Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Quarantined Messages(12).zip

Overview

General Information

Sample name:Quarantined Messages(12).zip
Analysis ID:1530701
MD5:b415ab3eb1b15a7df7f83c203cbdf0a1
SHA1:cd0f930a425647c10735ecde6c73f82eaa8f4148
SHA256:db06690123a57d43e83c54a576ca6689c7a0a9c2b9600adcc7f800a609af2e9e
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Creates a window with clipboard capturing capabilities
HTML body contains low number of good links
HTML title does not match URL
None HTTPS page querying sensitive user data (password, username or email)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Sigma detected: Office Macro File Download
Sigma detected: Outlook Security Settings Updated - Registry
Sigma detected: Suspicious Office Outbound Connections
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • rundll32.exe (PID: 5388 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • OUTLOOK.EXE (PID: 6476 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Temp\Temp1_Quarantined Messages(12).zip\f53ffd0b-396b-463d-993d-08dce86c57d3\55d4a84e-c7d4-087b-dd19-43da8bea99dd.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 3508 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "7F4EBBA9-8A21-4CE3-8297-26460B9C4859" "63C49320-D2EF-4817-872A-9D7FF5B5C1A7" "6476" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
    • chrome.exe (PID: 6672 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 364 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2140 --field-trial-handle=2076,i,254068900567008855,461859920414542457,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • Acrobat.exe (PID: 7152 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\SEXB8OWZ\Grillmeister BBQ.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
      • AcroCEF.exe (PID: 6528 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
        • AcroCEF.exe (PID: 400 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1372,i,5621814220395925370,2995762272540364628,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
  • Acrobat.exe (PID: 6136 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" /b /id 816_1290099431 /if pdfshell_prev702b6358-c673-42c6-9e23-88cbe0367c9c /CR MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
  • OUTLOOK.EXE (PID: 4128 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Temp\Temp1_Quarantined Messages(12).zip\f53ffd0b-396b-463d-993d-08dce86c57d3\55d4a84e-c7d4-087b-dd19-43da8bea99dd.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 2244 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "A3F6C9D3-DFDA-4878-BEDE-E9A80D507C5C" "96B9EAEB-D4F1-4F22-AF07-C3362B84342B" "4128" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
    • chrome.exe (PID: 4252 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 6712 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2004 --field-trial-handle=1760,i,15048366162093802740,9476151029119795841,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6476, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6476, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm
Source: Registry Key setAuthor: frack113: Data: Details: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\SEXB8OWZ\, EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6476, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Security\OutlookSecureTempFolder
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.16, DestinationIsIpv6: false, DestinationPort: 49730, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, Initiated: true, ProcessId: 4128, Protocol: tcp, SourceIp: 13.107.246.60, SourceIsIpv6: false, SourcePort: 443
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6476, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: http://caljv.jelasbanget.store/LLM: Score: 9 Reasons: The brand 'Fox News' is a well-known media company with a legitimate domain of 'foxnews.com'., The URL 'caljv.jelasbanget.store' does not match the legitimate domain of Fox News., The domain 'jelasbanget.store' is unusual and not associated with Fox News., The presence of an input field asking for an email on a non-legitimate domain is suspicious., The use of a '.store' domain extension is uncommon for a news media site like Fox News. DOM: 3.5.pages.csv
Source: http://caljv.jelasbanget.store/LLM: Score: 9 Reasons: The brand 'Fox News' is a well-known media company with a legitimate domain of 'foxnews.com'., The URL 'caljv.jelasbanget.store' does not match the legitimate domain of Fox News., The domain 'jelasbanget.store' is unrelated to Fox News and uses an unusual domain extension for a media company., The presence of an input field asking for an email on an unrelated domain is suspicious and indicative of phishing. DOM: 3.4.pages.csv
Source: http://caljv.jelasbanget.store/LLM: Score: 9 Reasons: The brand 'Fox News' is a well-known media company with a legitimate domain of 'foxnews.com'., The URL 'caljv.jelasbanget.store' does not match the legitimate domain of Fox News., The domain 'jelasbanget.store' is unrelated to Fox News and uses an unusual domain extension for a media company., The presence of an input field asking for an email on a suspicious domain increases the likelihood of phishing., The URL structure and domain name do not align with any known or legitimate Fox News web properties. DOM: 3.3.pages.csv
Source: http://caljv.jelasbanget.store/HTTP Parser: Number of links: 0
Source: http://caljv.jelasbanget.store/HTTP Parser: Title: Coming Soon - pnhr.zbharucha.com does not match URL
Source: http://caljv.jelasbanget.store/HTTP Parser: Has password / email / username input fields
Source: http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3HTTP Parser: No favicon
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="author".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="author".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="author".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="author".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="copyright".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="copyright".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="copyright".. found
Source: http://caljv.jelasbanget.store/HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 9MB later: 30MB
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13 HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13 HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /news?q=IP%20provider%20is%20blacklisted!%20LEVEL3 HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://caljv.jelasbanget.store/t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/styles.css HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://caljv.jelasbanget.store/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13 HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13 HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /news?q=IP%20provider%20is%20blacklisted!%20LEVEL3 HTTP/1.1Host: caljv.jelasbanget.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://caljv.jelasbanget.store/t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: caljv.jelasbanget.store
Source: global trafficDNS traffic detected: DNS query: feeds.foxnews.com
Source: global trafficDNS traffic detected: DNS query: moxie.foxnews.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.foxnews.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Address: gin_throttle_mw_360000000000_8.46.123.33X-Ratelimit-Limit: 10X-Ratelimit-Remaining: 8X-Ratelimit-Reset: 1728560603Date: Thu, 10 Oct 2024 10:43:23 GMTContent-Length: 0
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow created: window name: CLIPBRDWNDCLASS
Source: classification engineClassification label: mal48.phis.winZIP@45/1096@12/52
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241010T0643040058-6476.etl
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile read: C:\Users\desktop.ini
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Temp\Temp1_Quarantined Messages(12).zip\f53ffd0b-396b-463d-993d-08dce86c57d3\55d4a84e-c7d4-087b-dd19-43da8bea99dd.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "7F4EBBA9-8A21-4CE3-8297-26460B9C4859" "63C49320-D2EF-4817-872A-9D7FF5B5C1A7" "6476" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2140 --field-trial-handle=2076,i,254068900567008855,461859920414542457,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "7F4EBBA9-8A21-4CE3-8297-26460B9C4859" "63C49320-D2EF-4817-872A-9D7FF5B5C1A7" "6476" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2140 --field-trial-handle=2076,i,254068900567008855,461859920414542457,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\SEXB8OWZ\Grillmeister BBQ.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1372,i,5621814220395925370,2995762272540364628,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding ABB1D3B6274F7E1B7F461F7495A54ECC
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\SEXB8OWZ\Grillmeister BBQ.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknown
Source: unknownProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" /b /id 816_1290099431 /if pdfshell_prev702b6358-c673-42c6-9e23-88cbe0367c9c /CR
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Temp\Temp1_Quarantined Messages(12).zip\f53ffd0b-396b-463d-993d-08dce86c57d3\55d4a84e-c7d4-087b-dd19-43da8bea99dd.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "A3F6C9D3-DFDA-4878-BEDE-E9A80D507C5C" "96B9EAEB-D4F1-4F22-AF07-C3362B84342B" "4128" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2004 --field-trial-handle=1760,i,15048366162093802740,9476151029119795841,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2284 --field-trial-handle=1372,i,5621814220395925370,2995762272540364628,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "A3F6C9D3-DFDA-4878-BEDE-E9A80D507C5C" "96B9EAEB-D4F1-4F22-AF07-C3362B84342B" "4128" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{ED475410-B0D6-11D2-8C3B-00104B2A6676}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Clipboard Data
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media3
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Rundll32
Security Account Manager13
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Extra Window Memory Injection
1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture4
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Extra Window Memory Injection
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
feeds.foxnews.com0%VirustotalBrowse
moxie.foxnews.com0%VirustotalBrowse
www.google.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
caljv.jelasbanget.store
213.246.45.146
truetrue
    unknown
    www.google.com
    216.58.212.132
    truefalseunknown
    s-part-0032.t-0009.t-msedge.net
    13.107.246.60
    truefalse
      unknown
      moxie.foxnews.com
      unknown
      unknownfalseunknown
      www.foxnews.com
      unknown
      unknownfalse
        unknown
        feeds.foxnews.com
        unknown
        unknownfalseunknown
        NameMaliciousAntivirus DetectionReputation
        http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144true
          unknown
          http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13true
            unknown
            http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3true
              unknown
              http://caljv.jelasbanget.store/true
                unknown
                http://caljv.jelasbanget.store/favicon.icotrue
                  unknown
                  http://caljv.jelasbanget.store/t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13#gexwvvyoznxhpmwcbcx5ytq4jr8ihazp0k74z33kam61pcg144true
                    unknown
                    http://caljv.jelasbanget.store/assets/styles.csstrue
                      unknown
                      http://caljv.jelasbanget.store/t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13true
                        unknown
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        52.113.194.132
                        unknownUnited States
                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                        213.246.45.146
                        caljv.jelasbanget.storeFrance
                        21409IKOULAFRtrue
                        142.250.186.78
                        unknownUnited States
                        15169GOOGLEUSfalse
                        216.58.212.132
                        www.google.comUnited States
                        15169GOOGLEUSfalse
                        23.57.19.119
                        unknownUnited States
                        16625AKAMAI-ASUSfalse
                        52.109.89.119
                        unknownUnited States
                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                        54.227.187.23
                        unknownUnited States
                        14618AMAZON-AESUSfalse
                        20.42.65.85
                        unknownUnited States
                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                        13.107.246.60
                        s-part-0032.t-0009.t-msedge.netUnited States
                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                        64.233.166.84
                        unknownUnited States
                        15169GOOGLEUSfalse
                        239.255.255.250
                        unknownReserved
                        unknownunknownfalse
                        142.250.185.131
                        unknownUnited States
                        15169GOOGLEUSfalse
                        104.102.34.105
                        unknownUnited States
                        16625AKAMAI-ASUSfalse
                        52.109.32.97
                        unknownUnited States
                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                        151.101.2.132
                        unknownUnited States
                        54113FASTLYUSfalse
                        142.250.184.234
                        unknownUnited States
                        15169GOOGLEUSfalse
                        IP
                        192.168.2.16
                        Joe Sandbox version:41.0.0 Charoite
                        Analysis ID:1530701
                        Start date and time:2024-10-10 12:41:04 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:29
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • EGA enabled
                        Analysis Mode:stream
                        Analysis stop reason:Timeout
                        Sample name:Quarantined Messages(12).zip
                        Detection:MAL
                        Classification:mal48.phis.winZIP@45/1096@12/52
                        Cookbook Comments:
                        • Found application associated with file extension: .zip
                        • Exclude process from analysis (whitelisted): dllhost.exe
                        • Excluded IPs from analysis (whitelisted): 52.109.32.97, 52.113.194.132, 20.42.65.85
                        • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtCreateFile calls found.
                        • Report size getting too big, too many NtQueryAttributesFile calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                        • Report size getting too big, too many NtReadFile calls found.
                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                        • Report size getting too big, too many NtSetValueKey calls found.
                        • Timeout during stream target processing, analysis might miss dynamic analysis data
                        • VT rate limit hit for: s-part-0032.t-0009.t-msedge.net
                        InputOutput
                        URL: http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3 Model: jbxai
                        {
                        "brand":["Fox News World"],
                        "contains_trigger_text":false,
                        "trigger_text":"",
                        "prominent_button_name":"Back to the main page",
                        "text_input_field_labels":"unknown",
                        "pdf_icon_visible":false,
                        "has_visible_captcha":false,
                        "has_urgent_text":false,
                        "text":"Fox News World RSS Feed",
                        "has_visible_qrcode":false}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "brand":["Fox News"],
                        "contains_trigger_text":false,
                        "trigger_text":"",
                        "prominent_button_name":"Subscribe",
                        "text_input_field_labels":["Enter your email"],
                        "pdf_icon_visible":false,
                        "has_visible_captcha":false,
                        "has_urgent_text":false,
                        "text":"Our Website is Coming Soon! We are working hard to give you the best experience. Stay tuned! 446 Days 18 Hours 16 Minutes 22 Seconds Enter your email Subscribe Fox News Learn more about our email marketing agency Unsubscribe from our newsletter Privacy Policy",
                        "has_visible_qrcode":false}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "brand":["Fox News"],
                        "contains_trigger_text":false,
                        "trigger_text":"",
                        "prominent_button_name":"Subscribe",
                        "text_input_field_labels":["Enter your email"],
                        "pdf_icon_visible":false,
                        "has_visible_captcha":false,
                        "has_urgent_text":false,
                        "text":"Our Website is Coming Soon! We are working hard to give you the best experience. Stay tuned! 446 Days 18 Hours 16 Minutes 26 Seconds Enter your email Subscribe Fox News Learn more about our email marketing agency Unsubscribe from our newsletter Privacy Policy",
                        "has_visible_qrcode":false}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "brand":["Fox News"],
                        "contains_trigger_text":false,
                        "trigger_text":"",
                        "prominent_button_name":"Subscribe",
                        "text_input_field_labels":["Enter your email"],
                        "pdf_icon_visible":false,
                        "has_visible_captcha":false,
                        "has_urgent_text":false,
                        "text":"Our Website is Coming Soon! We are working hard to give you the best experience. Stay tuned! 446 Days 18 Hours 16 Minutes 31 Seconds Enter your email Subscribe Fox News Learn more about our email marketing agency Unsubscribe from our newsletter Privacy Policy",
                        "has_visible_qrcode":false}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "phishing_score":9,
                        "brands":"Fox News",
                        "legit_domain":"foxnews.com",
                        "classification":"wellknown",
                        "reasons":["The brand 'Fox News' is a well-known media company with a legitimate domain of 'foxnews.com'.",
                        "The URL 'caljv.jelasbanget.store' does not match the legitimate domain of Fox News.",
                        "The domain 'jelasbanget.store' is unusual and not associated with Fox News.",
                        "The presence of an input field asking for an email on a non-legitimate domain is suspicious.",
                        "The use of a '.store' domain extension is uncommon for a news media site like Fox News."],
                        "brand_matches":[false],
                        "url_match":false,
                        "brand_input":"Fox News",
                        "input_fields":"Enter your email"}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "phishing_score":9,
                        "brands":"Fox News",
                        "legit_domain":"foxnews.com",
                        "classification":"wellknown",
                        "reasons":["The brand 'Fox News' is a well-known media company with a legitimate domain of 'foxnews.com'.",
                        "The URL 'caljv.jelasbanget.store' does not match the legitimate domain of Fox News.",
                        "The domain 'jelasbanget.store' is unrelated to Fox News and uses an unusual domain extension for a media company.",
                        "The presence of an input field asking for an email on an unrelated domain is suspicious and indicative of phishing."],
                        "brand_matches":[false],
                        "url_match":false,
                        "brand_input":"Fox News",
                        "input_fields":"Enter your email"}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "phishing_score":9,
                        "brands":"Fox News",
                        "legit_domain":"foxnews.com",
                        "classification":"wellknown",
                        "reasons":["The brand 'Fox News' is a well-known media company with a legitimate domain of 'foxnews.com'.",
                        "The URL 'caljv.jelasbanget.store' does not match the legitimate domain of Fox News.",
                        "The domain 'jelasbanget.store' is unrelated to Fox News and uses an unusual domain extension for a media company.",
                        "The presence of an input field asking for an email on a suspicious domain increases the likelihood of phishing.",
                        "The URL structure and domain name do not align with any known or legitimate Fox News web properties."],
                        "brand_matches":[false],
                        "url_match":false,
                        "brand_input":"Fox News",
                        "input_fields":"Enter your email"}
                        URL: http://caljv.jelasbanget.store/ Model: jbxai
                        {
                        "brand":[],
                        "contains_trigger_text":false,
                        "trigger_text":"",
                        "prominent_button_name":"Subscribe",
                        "text_input_field_labels":["Enter your email"],
                        "pdf_icon_visible":false,
                        "has_visible_captcha":false,
                        "has_urgent_text":false,
                        "text":"Our Website is Coming Soon! We are working hard to give you the best experience. Stay tuned! 446 Days 18 Hours 16 Minutes 01 Seconds Enter your email Subscribe Fox News Learn more about our email marketing agency Unsubscribe from our newsletter Privacy Policy",
                        "has_visible_qrcode":false}
                        URL: http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3 Model: jbxai
                        {
                        "brand":["Fox News World"],
                        "contains_trigger_text":false,
                        "trigger_text":"",
                        "prominent_button_name":"unknown",
                        "text_input_field_labels":"unknown",
                        "pdf_icon_visible":false,
                        "has_visible_captcha":false,
                        "has_urgent_text":false,
                        "text":"Fox News World RSS Feed Back to the main page IP provider is blacklisted: LEVEL3 Canadian woman charged with killing 3 people in 3 days,
                         labeled a serial killer A Canadian woman allegedly killed three people in separate incidents over three days in and around Toronto,
                         authorities said last week. No content available. North Korea vows to block border with South Korea and build front-line defense structures To cope with 'confrontational hysteria' by U.S. and South Korean forces,
                         North Korea said it will block its border with South Korea permanently and will cut off railways and roads to the country. No content available. The history of the Hoxne Hoard,
                         the largest collection of Roman treasure found in Britain The Hoxne Hoard is one of the most significant archaeological finds out of Britain. The hoard is mostly made of gold and silver coins,
                         although other unique objects add to its value. No content available. Israel hit with multiple terrorist attacks as Hezbollah rocket kills 2 Israelis while walking dogs Israel was hit with another round of terrorist attacks as Hezbollah fired rockets into a northern border town,
                         killing two,
                         and knife-wielding",
                        "has_visible_qrcode":false}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):290
                        Entropy (8bit):5.203457544310412
                        Encrypted:false
                        SSDEEP:
                        MD5:A3CB27B76EFB34D114529DF9A1C72547
                        SHA1:8C8DE08B467F4278E83BCCB9C0024CA9D49CEC2A
                        SHA-256:571A8762DB6B283866DC558A7A8F8BDCB39D0C53766BB991FCA03F11B2A7514F
                        SHA-512:FE89C7495A3FC9484D0735224F1E5028132866874C64DDCB6343E2B352DC642864C3C4E95C4FAA220DCD2FA3C2F97611FF0C2A98FB79C2A5EFF98E34CCBC833E
                        Malicious:false
                        Reputation:unknown
                        Preview:2024/10/10-06:43:42.055 1748 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/10/10-06:43:42.058 1748 Recovering log #3.2024/10/10-06:43:42.058 1748 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:A3CB27B76EFB34D114529DF9A1C72547
                        SHA1:8C8DE08B467F4278E83BCCB9C0024CA9D49CEC2A
                        SHA-256:571A8762DB6B283866DC558A7A8F8BDCB39D0C53766BB991FCA03F11B2A7514F
                        SHA-512:FE89C7495A3FC9484D0735224F1E5028132866874C64DDCB6343E2B352DC642864C3C4E95C4FAA220DCD2FA3C2F97611FF0C2A98FB79C2A5EFF98E34CCBC833E
                        Malicious:false
                        Reputation:unknown
                        Preview:2024/10/10-06:43:42.055 1748 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/10/10-06:43:42.058 1748 Recovering log #3.2024/10/10-06:43:42.058 1748 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):331
                        Entropy (8bit):5.166207682594851
                        Encrypted:false
                        SSDEEP:
                        MD5:0BCE22B40C0740F456E18F1A5E5D269F
                        SHA1:8E2822DCCB142317D5D12CBC63D62CDBF0A2EDB5
                        SHA-256:9978ECF5B91935C0DFE4106018E9C81E974DE604D9EE8A1877616CA226F20B43
                        SHA-512:5086DD2A103C2665C52D1D46D3562CEA81591119C91CC1D6C28C34FA3AD4A601B99E1A021125416132CE2AEF279A9696630A230F44AD99AA0EBA0B746C1582AE
                        Malicious:false
                        Reputation:unknown
                        Preview:2024/10/10-06:43:41.962 d50 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/10/10-06:43:41.965 d50 Recovering log #3.2024/10/10-06:43:41.965 d50 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:0BCE22B40C0740F456E18F1A5E5D269F
                        SHA1:8E2822DCCB142317D5D12CBC63D62CDBF0A2EDB5
                        SHA-256:9978ECF5B91935C0DFE4106018E9C81E974DE604D9EE8A1877616CA226F20B43
                        SHA-512:5086DD2A103C2665C52D1D46D3562CEA81591119C91CC1D6C28C34FA3AD4A601B99E1A021125416132CE2AEF279A9696630A230F44AD99AA0EBA0B746C1582AE
                        Malicious:false
                        Reputation:unknown
                        Preview:2024/10/10-06:43:41.962 d50 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/10/10-06:43:41.965 d50 Recovering log #3.2024/10/10-06:43:41.965 d50 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:JSON data
                        Category:modified
                        Size (bytes):253
                        Entropy (8bit):4.931682077316122
                        Encrypted:false
                        SSDEEP:
                        MD5:F7734C5562A331E7E5AD650E528B9CCE
                        SHA1:1F2AC5AC6B7E30E317FD8F653B1C78339248DB12
                        SHA-256:C55A12976D4F8EC2298956E7A1024E79A8A0E8E2FB0A7F574E8CD01533B9B6C0
                        SHA-512:C985E18F984F1D8C5F0B5749E849E76FF4686415A33749977E10C28DC1D7B201B9F7E7C0F6556A35CB333A5CD7526F7D1A6D652BBCDDB50FB144869C74B70CFD
                        Malicious:false
                        Reputation:unknown
                        Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.16","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:F7734C5562A331E7E5AD650E528B9CCE
                        SHA1:1F2AC5AC6B7E30E317FD8F653B1C78339248DB12
                        SHA-256:C55A12976D4F8EC2298956E7A1024E79A8A0E8E2FB0A7F574E8CD01533B9B6C0
                        SHA-512:C985E18F984F1D8C5F0B5749E849E76FF4686415A33749977E10C28DC1D7B201B9F7E7C0F6556A35CB333A5CD7526F7D1A6D652BBCDDB50FB144869C74B70CFD
                        Malicious:false
                        Reputation:unknown
                        Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.16","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4509
                        Entropy (8bit):5.224614797670377
                        Encrypted:false
                        SSDEEP:
                        MD5:887B6FAB475439E6A93A5BBA1CD4D866
                        SHA1:EC19CF63F160E887A9EACD3C3B448ABA58EE903F
                        SHA-256:A8B3A1C6A868CE29B5DC2794A376EBE6F05F95C45B1FAA66DE645B9FDFACF883
                        SHA-512:52D4DEEC3F4C027439C98714900D013925B367C30C6080A5473B77E5823462E5E6C3D60795E3120E946EC36F8B1308FA9CBA93AB43D3AAC45FFB50D6EFCC3FBA
                        Malicious:false
                        Reputation:unknown
                        Preview:*...#................version.1..namespace-e...o................next-map-id.1.Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/.0y.S_r................next-map-id.2.Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/.16.X:r................next-map-id.3.Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/.2.P.@o................next-map-id.4.Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/.346.+^...............Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/....^...............Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/..?&a...............Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/_...a...............Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/...o................next-map-id.5.Pnamespace-07af9ee9_2076_4f12_94b5_
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):319
                        Entropy (8bit):5.17559474685622
                        Encrypted:false
                        SSDEEP:
                        MD5:3F7F9F130F92FC8DFDF6CF27EEC12A1F
                        SHA1:F42107EA947AC1EBB29037EA585D70C184191DD3
                        SHA-256:A3F1930AA89D4D2DD6448DFE3E474E86492E9EA0DD3CDD36607B36B0B8C5D6AA
                        SHA-512:5CE6110821517A592964B652FB4FCD90CC17FF9331AB5BAC541A1E4FA0F19B4C40877D02AE333ED3A0F65F07782F3D58650086ECE93521FE493DB628D9AD7E15
                        Malicious:false
                        Reputation:unknown
                        Preview:2024/10/10-06:43:42.087 d50 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/10/10-06:43:42.088 d50 Recovering log #3.2024/10/10-06:43:42.090 d50 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:3F7F9F130F92FC8DFDF6CF27EEC12A1F
                        SHA1:F42107EA947AC1EBB29037EA585D70C184191DD3
                        SHA-256:A3F1930AA89D4D2DD6448DFE3E474E86492E9EA0DD3CDD36607B36B0B8C5D6AA
                        SHA-512:5CE6110821517A592964B652FB4FCD90CC17FF9331AB5BAC541A1E4FA0F19B4C40877D02AE333ED3A0F65F07782F3D58650086ECE93521FE493DB628D9AD7E15
                        Malicious:false
                        Reputation:unknown
                        Preview:2024/10/10-06:43:42.087 d50 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/10/10-06:43:42.088 d50 Recovering log #3.2024/10/10-06:43:42.090 d50 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):185099
                        Entropy (8bit):5.182478651346149
                        Encrypted:false
                        SSDEEP:
                        MD5:94185C5850C26B3C6FC24ABC385CDA58
                        SHA1:42F042285037B0C35BC4226D387F88C770AB5CAA
                        SHA-256:1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808
                        SHA-512:652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344
                        Malicious:false
                        Reputation:unknown
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:WinTTHandler.FontType:TrueType.FontName:AgencyFB-Reg.FamilyName:Agency FB.StyleName:Regular.MenuName:Agency FB.StyleBits:0.WeightClass:400.WidthClass:3.AngleClass:0.FullName:Agency FB.WritingScript:Roman.hasSVG:no.hasCOLR:no.VariableFontType:NonVariableFont.WinName:Agency FB.FileLength:58920.NameArray:0,Win,1,Agency FB.NameArray:0,Mac,4,Agency FB.NameArray:0,Win,1,Agency FB.%EndFont..%BeginFont.Handler:WinTTHandler.FontType:TrueType.FontName:AgencyFB-Bold.FamilyName:Agency FB.StyleName:Bold.MenuName:Agency FB.StyleBits:2.WeightClass:700.WidthClass:3.AngleClass:0.FullName:Agency FB Bold.WritingScript:Roman.hasSVG:no.hasCOLR:no.VariableFontType:NonVariableFont.WinName:Agency FB Bold.FileLength:60656.NameArray:0,Win,1,Agency FB.NameArray:0,Mac,4,Agency FB Bold.NameArray:0,Win,1,Agency FB.%EndFont..%BeginFont.Handler:WinTTHandler.FontType:TrueType.FontName:Algerian.FamilyName:Algerian.StyleName:Regular.MenuName:Algerian.StyleBits:0.We
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:PostScript document text
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:94185C5850C26B3C6FC24ABC385CDA58
                        SHA1:42F042285037B0C35BC4226D387F88C770AB5CAA
                        SHA-256:1D9979A98F7C4B3073BC03EE9D974CCE9FE265A1E2F8E9EE26A4A5528419E808
                        SHA-512:652657C00DD6AED1A132E1DFD0B97B8DF233CDC257DA8F75AC9F2428F2F7715186EA8B3B24F8350D409CC3D49AFDD36E904B077E28B4AD3E4D08B4DBD5714344
                        Malicious:false
                        Reputation:unknown
                        Preview:%!Adobe-FontList 1.23.%Locale:0x809..%BeginFont.Handler:WinTTHandler.FontType:TrueType.FontName:AgencyFB-Reg.FamilyName:Agency FB.StyleName:Regular.MenuName:Agency FB.StyleBits:0.WeightClass:400.WidthClass:3.AngleClass:0.FullName:Agency FB.WritingScript:Roman.hasSVG:no.hasCOLR:no.VariableFontType:NonVariableFont.WinName:Agency FB.FileLength:58920.NameArray:0,Win,1,Agency FB.NameArray:0,Mac,4,Agency FB.NameArray:0,Win,1,Agency FB.%EndFont..%BeginFont.Handler:WinTTHandler.FontType:TrueType.FontName:AgencyFB-Bold.FamilyName:Agency FB.StyleName:Bold.MenuName:Agency FB.StyleBits:2.WeightClass:700.WidthClass:3.AngleClass:0.FullName:Agency FB Bold.WritingScript:Roman.hasSVG:no.hasCOLR:no.VariableFontType:NonVariableFont.WinName:Agency FB Bold.FileLength:60656.NameArray:0,Win,1,Agency FB.NameArray:0,Mac,4,Agency FB Bold.NameArray:0,Win,1,Agency FB.%EndFont..%BeginFont.Handler:WinTTHandler.FontType:TrueType.FontName:Algerian.FamilyName:Algerian.StyleName:Regular.MenuName:Algerian.StyleBits:0.We
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):227002
                        Entropy (8bit):3.392780893644728
                        Encrypted:false
                        SSDEEP:
                        MD5:265E3E1166312A864FB63291EA661C6A
                        SHA1:80DFF3187FF929596EB22E1DB9021BAD6F97178C
                        SHA-256:C13E08B1887A4E44DC39609D7234E8D732A6BC11313B55D6F4ECFB060CD87728
                        SHA-512:48776A2BFE8F25E5601DCC0137F7AB103D5684517334B806E3ACF61683DD9B283828475FC85CE0CBE4E8AF88E6F8B25EED0A77640E2CFFF2CC73708726519AFA
                        Malicious:false
                        Reputation:unknown
                        Preview:Adobe Acrobat Reader (64-bit) 23.6.20320....?A12_AV2_Search_18px.............................................................................................................KKK KKK.KKK.KKK.KKK.KKK.KKK@........................................KKK`KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.............................KKKPKKK.KKK.KKK.KKK.........KKKPKKK.KKK.KKK.........................KKK.KKK.KKK.KKK0....................KKK.KKK.KKK.KKK`....................KKK`KKK.KKK.............................KKK@KKK.KKK.....................KKK.KKK.KKK0................................KKK.KKK.....................KKK.KKK.....................................KKK.KKK.....................KKK.KKK.KKK0................................KKK.KKK.....................KKK`KKK.KKK.............................KKK@KKK.KKK.....................KKK.KKK.KKK.KKK@....................KKK.KKK.KKK.KKK`........................KKKPKKK.KKK.KKK.KKK.........KKKPKKK.KKK.KKK.KKK.............................KKK`KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK.KKK
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):295
                        Entropy (8bit):5.3752053086422285
                        Encrypted:false
                        SSDEEP:
                        MD5:F26F4DA1D218435A758720352F91177D
                        SHA1:BD26C87D1E2E73885889F5B847ADE983E1FB4B4E
                        SHA-256:A2A748C168154960D44B0F8227BD6FB38C5D7F1531A289A2CC13C261B7D7E83E
                        SHA-512:DE340E692FB4D787E053A27CAD8561967601C5186BC7963E7692CAE26B231B4DCE18506AAB090140029EF38DC0C96B5200AD37CCA4C0F0ECA9AD6E8F1DBC63AF
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"ACROBAT_READER_MASTER_SURFACEID","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):294
                        Entropy (8bit):5.32367382941867
                        Encrypted:false
                        SSDEEP:
                        MD5:70487603EBF0D42F40DAAA15BC3D434F
                        SHA1:17DBFF2E18F67DCA7A21728C33B519B3037F435B
                        SHA-256:AD74877241C316C1C3105EC75624203306B408E9B60468450A91B5E3301E5D76
                        SHA-512:04948319D4AA47D8E4B16A910D2A577DD83AAA12CA35BAAEE87CF17213AC0903AB5F569B877E6FCDA3FDC6108B078132089B365E66920E36E153691EFF4DAEBD
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_FirstMile_Home_View_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):294
                        Entropy (8bit):5.302222145944675
                        Encrypted:false
                        SSDEEP:
                        MD5:81BB19B92457FDA5560BE99AFB351BAB
                        SHA1:B937BE0D7BCD4D4741BD73D9E82CD889ED9019EC
                        SHA-256:32C83FB1818F0D01FE443D193CCABC44C2F98F87C307E6816CA05DFFF70D9F9E
                        SHA-512:9D94A43D8911BD8EBD02D866E0D700BD89F1F061CF3F0A19D98835FD7CC96B3BC845E3AE41DB6FB9F63F710E2DE1A6BC950EC5743DB3DBBB8CC8F0630A3D9273
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_FirstMile_Right_Sec_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):285
                        Entropy (8bit):5.364001003429716
                        Encrypted:false
                        SSDEEP:
                        MD5:44FE7335D8C580C16103555BEE0DC822
                        SHA1:4C841C2D8EF349F2AE91254FB308E9A8694572D2
                        SHA-256:41036FCC8FA5CBA9C83298A9D8D908F5F16F1DC0EA14F5E31247E391E7DAAD8F
                        SHA-512:C0C7F70E7F993390C0A413E7C7BDBFB001BFA5140A21B5C061C444C0B67C6AACCFC2A1C8AA59C5C08F9B5ACA1919A3C874BDB727D9D5F76C145185A00C7E3F35
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_READER_LAUNCH_CARD","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1083
                        Entropy (8bit):5.679406105561131
                        Encrypted:false
                        SSDEEP:
                        MD5:0AAA896AD549DF0BE5B5A44EF0364341
                        SHA1:EE49FED29F42FE5C6042A6CD81FC3E9AF45BA008
                        SHA-256:D0FDCD13F90785E12FAEDCDD19677849D2C49E2CC8B382EE90AA05D9C662FD04
                        SHA-512:700D8C62963A302D15F5205A3D6564A61BAD0081FF16CD8A5D060261E03A354F362B8440F33197077D146F55EB3ACFD705682B52E019E7B372FC49B0E6C7378D
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Convert_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Convert_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"89628_277808ActionBlock_2","campaignId":89628,"containerId":"1","controlGroupId":"","treatmentId":"22b145c0-22bc-4bba-811f-7234f288595b","variationId":"277808"},"containerId":1,"containerLabel":"JSON for DC_Reader_Convert_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkNvbnZlcnQgZmlsZXMgdG8gYW5kIGZyb20gUERGXG53aXRob3V0IGxpbWl0cy4ifSwidGNhdElkIjoiUkdTMDM1MS1FTlUtQ29udHJvbCJ9","dataType":"applicatio
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1050
                        Entropy (8bit):5.6531524022813215
                        Encrypted:false
                        SSDEEP:
                        MD5:A4C91C5299EFB2E44740417A4B057D76
                        SHA1:624F28714625021514C49D4E3DAECC8368F4548B
                        SHA-256:24E97B2F960F8596E18CB37CCC95A441CD66745898C2FEDA571D023F6CC4FF4F
                        SHA-512:B77148DF0F737776A21195B063D4E451519C408575E72E3CC24F6C0E2409E5851E942F967D4C12CF54739CCA7AE92BCF5AD054DE581C2FF33D83E2723F7B6968
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Disc_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"85534_264855ActionBlock_0","campaignId":85534,"containerId":"1","controlGroupId":"","treatmentId":"0924134e-3c59-4f53-b731-add558c56fec","variationId":"264855"},"containerId":1,"containerLabel":"JSON for DC_Reader_Disc_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkNvbnZlcnQsIGVkaXQgYW5kIGUtc2lnblxuZm9ybXMgJiBhZ3JlZW1lbnRzLiJ9LCJ0Y2F0SWQiOm51bGx9","dataType":"application\/json","encodingScheme":true},"
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):292
                        Entropy (8bit):5.3133621856531725
                        Encrypted:false
                        SSDEEP:
                        MD5:E354E184FAAEFF826D8D673A32E01042
                        SHA1:FEA3F4483E266CE87130D76D38230786405672F5
                        SHA-256:F646E00C5D3E67ED35959D4521A28DDDFFBE898C0C25EE9F4CC97569D5AFE187
                        SHA-512:30F147F235254D30E19224AD8455EE6BB40038C56CE7563AC24CFB7AE38A572EEA4C60C086FF2420C166745D25340D2D5A74D8893067D07BA3A37A744865D68F
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1062
                        Entropy (8bit):5.689027063670288
                        Encrypted:false
                        SSDEEP:
                        MD5:E5A90ED48EC0BF7CCAC0ED777B6BB2A3
                        SHA1:F862BA2EA50788C1EEFD8392DDFA5D1B145E0CBB
                        SHA-256:47BE637BAE65BE5A6CF6FECDB87ABF46C153714BE2815EF6520671F720C14BFE
                        SHA-512:482B3FAB6FAE03D5126976139DFAF6C549CF070E7B7858DF96ED5D52241CE2D8FE4887A13CF9BFA688FDA6A4ABBF90C3058369EB4A93BB5D7E5C98DAEAF65FD8
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Edit_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Edit_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"89628_277808ActionBlock_0","campaignId":89628,"containerId":"1","controlGroupId":"","treatmentId":"58886bd3-acd7-4f84-ae2e-6684bc127c41","variationId":"277808"},"containerId":1,"containerLabel":"JSON for DC_Reader_Edit_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkVkaXQgdGV4dCwgaW1hZ2VzLCBwYWdlcywgYW5kIG1vcmUuIn0sInRjYXRJZCI6IlJHUzAzNTEtRU5VLUNvbnRyb2wifQ==","dataType":"application\/json","encodingSch
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1164
                        Entropy (8bit):5.6972317180926995
                        Encrypted:false
                        SSDEEP:
                        MD5:855053C8800070BC91AAAC9E618C5EDF
                        SHA1:89FFBCC75E39CAB29E0F3B027C92EE44477BE9A9
                        SHA-256:ACC74F89ABEDF2B946C9D6748B4B41E2A08A62F62C399A0F268381B5E46A12AF
                        SHA-512:1B7A7ACCC4155D7B8142F1488A04BB7CCE29112B070B23B77F61258E15381FC983845131D9F30566AEDFADDA432A18B927E903D5DEA69EB746FC6FABEF7D5816
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Home_LHP_Trial_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Home_LHP_Trial_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"85531_264848ActionBlock_0","campaignId":85531,"containerId":"1","controlGroupId":"","treatmentId":"ee1a7497-76e7-43c2-bb63-9a0551e11d73","variationId":"264848"},"containerId":1,"containerLabel":"JSON for DC_Reader_Home_LHP_Trial_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IlRyeSBBY3JvYmF0IFBybyJ9LCJ1aSI6eyJ0aXRsZV9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjE1cHgiLCJmb250X3N0eWxlIjoiMCJ9LCJkZXNjcmlwdGlvbl9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjEzcHgiLCJmb250X3N0eWxlIjoiLTEifSwidGl0bGUiOiJGcmVlIHRyaWFsIiwiZGVzY3JpcHRpb24iOiJHZXQgdW5saW1pdGVkIGFjY2VzcyB0b1xucHJlbWl1bSBQREYgYW5kIGUtc2lnbmluZ1xudG9vbHMuIn0sImJhbm5lcl9zdHlsaW5nIjo
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):289
                        Entropy (8bit):5.3171117901646
                        Encrypted:false
                        SSDEEP:
                        MD5:739A14C00A9AA6097C046F1525DC60B9
                        SHA1:A77F71DC8CAADCB8EC20E24AC22771A2F0BE8FE1
                        SHA-256:A17724A1B23CBF9F2249E7EE8B5786A2DD2DDCB51765BCB3680409CD8E934171
                        SHA-512:FE4182874F75D05CB4C690F31543EB0D3EA4BE9A6451A3BE2A9FA464EBC8B2047B446BDE8459B4B4C618E28A3CAEF55C14B0BDC42BA08489375A33F8FAB49683
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_More_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1395
                        Entropy (8bit):5.76994845796074
                        Encrypted:false
                        SSDEEP:
                        MD5:28157E046213F379724364813989B68F
                        SHA1:9571CB863E29106F70BB45AAF82A14903FBE6CB1
                        SHA-256:7BC51D95469424F8140EECECC5172470BCFE5D65713F63ED3B6FCC535C24249A
                        SHA-512:E1E046F6E3DA9982510C58639FA5F0F3D51686526C30B48CFE3C11E60BB35E2D883BB051E9ACC05797E1B397DE49C07DD37FEE8283C65CBAFBD578D8D152580F
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_RHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_RHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"57802_176003ActionBlock_0","campaignId":57802,"containerId":"1","controlGroupId":"","treatmentId":"d0374f2d-08b2-49b9-9500-3392758c9e2e","variationId":"176003"},"containerId":1,"containerLabel":"JSON for Reader DC RHP Banner","content":{"data":"eyJjdGEiOnsidHlwZSI6ImJ1dHRvbiIsInRleHQiOiJGcmVlIDctRGF5IFRyaWFsIiwiZ29fdXJsIjoiaHR0cHM6Ly9hY3JvYmF0LmFkb2JlLmNvbS9wcm94eS9wcmljaW5nL3VzL2VuL3NpZ24tZnJlZS10cmlhbC5odG1sP3RyYWNraW5naWQ9UEMxUFFMUVQmbXY9aW4tcHJvZHVjdCZtdjI9cmVhZGVyIn0sInVpIjp7InRpdGxlX3N0eWxpbmciOnsiZm9udF9zaXplIjoiMTQiLCJmb250X3N0eWxlIjoiMyJ9LCJkZXNjcmlwdGlvbl9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjEyIiwiZm9udF9zdHlsZSI6IjMifSwidGl0
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):291
                        Entropy (8bit):5.300541281033208
                        Encrypted:false
                        SSDEEP:
                        MD5:7EDBF99B1A72F4CA5403CAF5517A3BCA
                        SHA1:BC714DEC68ED3805ED5ED780B6B9B9BC04D3FD8E
                        SHA-256:F4CAE3A0ED6AEDF5FE29224721427890041E578B7B2E805B5F7931D5D5985917
                        SHA-512:616D5EA589F2C0B20249CCADFEBD89FE2F6F37710A8A88092BAD1AAF0167F707A8B2D640F9B8DC6FECFB871E7BC7A29CAF8B22E1FC36820B156CF66AFD355873
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_RHP_Intent_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):287
                        Entropy (8bit):5.30415945407653
                        Encrypted:false
                        SSDEEP:
                        MD5:FCD2062CE1278175390784CD62819520
                        SHA1:E72828016F15FBA582BDE12509C7DD183762B362
                        SHA-256:0F4289843BBE5676F771E384C8077C97B9E545787D8BDBD468BEDED18D39F2DE
                        SHA-512:ACF7A3A5C6017D48ECD00FAAFBD3FD6EF6AD30CCE17ED545AD34AF84881DF1E1F691EB1063723C67E7E794176E4D0FCA1266920A816910FFE0D28E3549AAF02B
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_RHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1082
                        Entropy (8bit):5.685216405194105
                        Encrypted:false
                        SSDEEP:
                        MD5:90D1BA9B3B547B6E35E458E4F0A18389
                        SHA1:59EAF4E7E9DA99CDE62E5CA9D92A3D52315EAF40
                        SHA-256:3EA288F42D924FB5F1FC27E1CFFD99E1984945614DEE87AF2782A9905CD97D4B
                        SHA-512:537153E3DAC6E85146E1E5DFC557B05F9279820056FDF48AD12CB7A1879E98E2AAF28B74CA763D7E689909303038D3DAEA8F90F3D9117701AD7485650462F4B9
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Sign_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Sign_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"89628_277808ActionBlock_1","campaignId":89628,"containerId":"1","controlGroupId":"","treatmentId":"a8b11c37-7d39-4b12-9d33-a040ee4d296b","variationId":"277808"},"containerId":1,"containerLabel":"JSON for DC_Reader_Sign_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IlNlbmQgZG9jdW1lbnRzICYgZm9ybXNcbmZvciBmYXN0IGUtc2lnbmluZyBvbmxpbmUuIn0sInRjYXRJZCI6IlJHUzAzNTEtRU5VLUNvbnRyb2wifQ==","dataType":"application
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):286
                        Entropy (8bit):5.279856607412882
                        Encrypted:false
                        SSDEEP:
                        MD5:FCAEF9772BB4801D3215B4CF92567E6B
                        SHA1:03CF7C51BE95784890E706E113DD74BD0D819E11
                        SHA-256:753AE9BDFC3884B88A72C38A098156F7495EEFDA70B42920922F891314A8E5A3
                        SHA-512:BCC5E925118E1D574C52DF2D4A449F28CAE35953566E332B60517F130CF35312280BCA69272E26B77322BD5527FDC0DBE9954377DD2EE072CED9331EB5866DDF
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"DC_Reader_Upsell_Cards","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):782
                        Entropy (8bit):5.36131185501859
                        Encrypted:false
                        SSDEEP:
                        MD5:8CEC556F92EE7F37FE2DE4721A90E09F
                        SHA1:1BF815280CC3243053F86E3CBBB1323FF99B674D
                        SHA-256:EC8EB206734B08DA435B5C19C14F5093B9EF8F237ABBCED6C1B153BC72666BC0
                        SHA-512:6CF18D8D3038B857006450FE0A77B46C29A9AACE8D28C0D98439B2BB221FBE1408C46D8B1646D560A086779E97598AA1CCD893340CA7CD8BDFB935790F7D021D
                        Malicious:false
                        Reputation:unknown
                        Preview:{"analyticsData":{"responseGUID":"2e97780c-d2a7-43b5-a292-0555cf32e0d3","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1728734071995,"statusCode":200,"surfaceID":"Edit_InApp_Aug2020","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"Edit_InApp_Aug2020"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"20360_57769ActionBlock_0","campaignId":20360,"containerId":"1","controlGroupId":"","treatmentId":"3c07988a-9c54-409d-9d06-53885c9f21ec","variationId":"57769"},"containerId":1,"containerLabel":"JSON for switching in-app test","content":{"data":"eyJ1cHNlbGxleHBlcmltZW50Ijp7InRlc3RpZCI6IjEiLCJjb2hvcnQiOiJicm93c2VyIn19","dataType":"application\/json","encodingScheme":true},"endDTS":1735804679000,"startDTS":1728557027028}}}}
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):4
                        Entropy (8bit):0.8112781244591328
                        Encrypted:false
                        SSDEEP:
                        MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                        SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                        SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                        SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                        Malicious:false
                        Reputation:unknown
                        Preview:....
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):2818
                        Entropy (8bit):5.125111115025443
                        Encrypted:false
                        SSDEEP:
                        MD5:0AFAC8A68C1A34757C2E8D2D9DBEF5FE
                        SHA1:86CC637271B9F936C3E83DA5589AA887B9E4C0BF
                        SHA-256:B5347517CD27E966F542585F1E86F4B055B42F87A9CB9A01AF307F646A460D44
                        SHA-512:7C1A47EB0FCF699C4186501D78C6E7C5494AE65DC6AC6CC823ACC769061251C6CD8D0A30D5CE1C80CDBA7967B2BF96563EC794DEF96E7541E2B59B98B15D0182
                        Malicious:false
                        Reputation:unknown
                        Preview:{"all":[{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"99bba408c67e89a470c77886ab5d012b","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":1164,"ts":1728557026000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"21aea591ba9e0afcce09a5c7762339ad","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":1082,"ts":1728557025000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"63a068c1d66b38371f191beafebed193","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":1083,"ts":1728557025000},{"id":"DC_Reader_Edit_LHP_Banner","info":{"dg":"bffc7654fbbc37cdcb85bdebd7787540","sid":"DC_Reader_Edit_LHP_Banner"},"mimeType":"file","size":1062,"ts":1728557025000},{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"f88f590b06ac7365304e1acc941ce2f2","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":1050,"ts":1728557025000},{"id":"Edit_InApp_Aug2020","info":{"dg":"5cb188f84fbe587a11de28d0cdc3c860","sid":"Edit_InApp_Aug2020"},"mimeType":"file","size":782,"ts":17
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 19, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 19
                        Category:dropped
                        Size (bytes):12288
                        Entropy (8bit):0.9883758846341798
                        Encrypted:false
                        SSDEEP:
                        MD5:8E84C5CD4533DAC56355777591B4D909
                        SHA1:CA9DE20712EFFDBB3C5DE1CDD0F701EFD0CE6F70
                        SHA-256:6E93CC59F9F02066A59C98ED34DD010321601B826B43CBDD8E1F5F93F37A0AF9
                        SHA-512:BC30129202272414C352895D439DD460962393D10F2DE85B1C34DB9A9859ADF659A46A0FBE485D1C6F1E7F4BDA568BEAD62A8ABC089FA6B2BADEC8F84249F2EC
                        Malicious:false
                        Reputation:unknown
                        Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:SQLite Rollback Journal
                        Category:dropped
                        Size (bytes):8720
                        Entropy (8bit):1.3448025764130058
                        Encrypted:false
                        SSDEEP:
                        MD5:B4DAC1D77DCF108F29AAEB16279BD804
                        SHA1:AFBD6EAD6EEE79062D2FC3647BC7FA123B516BE3
                        SHA-256:5A085891B039938B78500560DBEBE649727668FCCC17EE46506BFBA4F4FFB263
                        SHA-512:BDFC63D81F029E49B09ED8201F8E753B1E749431D6B0C15D158B9E50BA7378532461279A29251FB036EF45A2F96BFA4793D223B979D7D138E94F467AC3296C96
                        Malicious:false
                        Reputation:unknown
                        Preview:.... .c.......e......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j...#..#.#.#.#.#.#.#.#.7.7........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):231348
                        Entropy (8bit):4.387475278042152
                        Encrypted:false
                        SSDEEP:
                        MD5:AB3BC8C6EEAA9129A2580EABA08CBAB1
                        SHA1:97DEBD9AB2F52A1C966D00324B6D6FE81C186B78
                        SHA-256:613E73601927A6D427B32075EEAE2D95CB050E7554D22A599C88E089DEAE4E92
                        SHA-512:D696DA94B2EF0C97410218F39188B11B7909471F7C766CB158A40C6874C289A4C74D6EDBD376233F02BB40E2DEE378F7B65453F914CA15E71CC8C231E9F3E6BC
                        Malicious:false
                        Reputation:unknown
                        Preview:TH02...... .............SM01X...,...................IPM.Activity...........h...............h............H..h|.......rF....h........`h..H..h\cal ...pDat...h(d..0.........h.B.............h........_`Uk...hFC..@...I.lw...h....H...8.Zk...0....T...............d.........2h...............k..............!h.............. h..)C........#h....8.........$h`h......8....."h8p.......t....'h..............1h.B..<.........0h....4....Zk../h....h.....ZkH..h....p...|.....-h .............+h.A......p................... ..............F7..............FIPM.Activity.st.Form.e..Standard.tanJournal Entry.pdIPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000.000Microsoft.ofThis form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with very long lines (1869), with no line terminators
                        Category:dropped
                        Size (bytes):1869
                        Entropy (8bit):5.0866318488087945
                        Encrypted:false
                        SSDEEP:
                        MD5:32BD518E8A55255BFABDA9DB66026913
                        SHA1:1836FD9155ED232D0730589B8E550873CA78D4FA
                        SHA-256:94422E86D23855E28F8FF5397BA265937CC5BCFBDA295B9B3FD6620C5C533736
                        SHA-512:CE94619491550DABB46D594199FD8712C773CD0FD19C6A612B24624AD84394890B6F2B8A5C6BF98567027C810E35C5EA27B432482A358E24989C48EDC72A5650
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?><root><version>1</version><Count>12</Count><Resource><Id>Aptos_26215680</Id><LAT>2024-10-10T10:43:54Z</LAT><key>29939506207.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos_45876480</Id><LAT>2024-10-10T10:43:54Z</LAT><key>27160079615.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_26215424</Id><LAT>2023-10-06T09:25:29Z</LAT><key>31558910439.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215680</Id><LAT>2023-10-06T09:25:29Z</LAT><key>23001069669.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_45876224</Id><LAT>2023-10-06T09:25:29Z</LAT><key>24153076628.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos Display_45876480</Id><LAT>2023-10-06T09:25:29Z</LAT><key>30264859306.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos_
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):1538
                        Entropy (8bit):5.170046666246265
                        Encrypted:false
                        SSDEEP:
                        MD5:F903C4A051E8AA36E9E085B08D1BC55E
                        SHA1:FF9AF9BBA28D4F3FF2238A64425CABE8123250AB
                        SHA-256:59D97433D58543D3CAE4BFDF9AC0DC6990A99BFB10D118B0D62D32DA15D30968
                        SHA-512:7B9A526C71B8DF94CF6556AB827C07E2265ACF6F81B4A12B3303ACCD6601C92735ECAA0F4AD5DC054FD1E7EA19B29FC220F41213822CD04E71DC27FDA8C9027B
                        Malicious:false
                        Reputation:unknown
                        Preview:{"CampaignStates":[{"CampaignId":"398f8b35-ef06-4a2b-a5dc-d85540d6fff3","LastNominationTimeUtc":"2023-10-06T09:25:18Z","LastNominationBuildNumber":"16.0.16827.20130","DeleteAfterSecondsWhenStale":31536000,"ForceCandidacy":false,"IsCandidate":true,"DidCandidateTriggerSurvey":false,"LastSurveyActivatedTimeUtc":"1601-01-01T00:00:00Z","LastSurveyId":"7e1f72bd-2c13-423b-93cf-2786588bccbb","LastSurveyStartTimeUtc":"2023-10-06T09:25:18Z","LastSurveyExpirationTimeUtc":"2024-10-05T09:25:18Z","LastCooldownEndTimeUtc":"1601-01-01T00:00:00Z"},{"CampaignId":"8a42827d-29d2-473e-998e-3217724c5b68","LastNominationTimeUtc":"2023-10-06T09:25:18Z","LastNominationBuildNumber":"16.0.16827.20130","DeleteAfterSecondsWhenStale":31536000,"ForceCandidacy":false,"IsCandidate":true,"DidCandidateTriggerSurvey":false,"LastSurveyActivatedTimeUtc":"1601-01-01T00:00:00Z","LastSurveyId":"0bb7f335-0b8a-4926-bb93-540e4e5b86c8","LastSurveyStartTimeUtc":"2023-10-06T09:25:18Z","LastSurveyExpirationTimeUtc":"2024-10-05T09:25
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):740
                        Entropy (8bit):4.578658879460996
                        Encrypted:false
                        SSDEEP:
                        MD5:439A34DE8DA5C04AF25AADB84A2120D4
                        SHA1:F12F9FF6E03A5762BD03061557029446680B1DAE
                        SHA-256:32B560C75C25C6F56C0439F67A3FA7D4F271F07B435EE41575A3D82C6C612880
                        SHA-512:BE704CD0DF8041945D16B8103135650B33D5E97D6F7C202E9C9499C3AE57E33855C2CC3A8F73B578DB482F47026C756F1FAA411A2CC58B5E53CE23CD24229834
                        Malicious:false
                        Reputation:unknown
                        Preview:{"ChannelStates":[{"ChannelType":0,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":1209600},{"ChannelType":1,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":0},{"ChannelType":2,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":0},{"ChannelType":3,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":3600},{"ChannelType":4,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":10800},{"ChannelType":5,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":7776000},{"ChannelType":6,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":1800},{"ChannelType":7,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":0},{"ChannelType":8,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":1209600}]}
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):87
                        Entropy (8bit):4.576828956814449
                        Encrypted:false
                        SSDEEP:
                        MD5:E4E83F8123E9740B8AA3C3DFA77C1C04
                        SHA1:5281EAE96EFDE7B0E16A1D977F005F0D3BD7AAD0
                        SHA-256:6034F27B0823B2A6A76FE296E851939FD05324D0AF9D55F249C79AF118B0EB31
                        SHA-512:BD6B33FD2BBCE4A46991BC0D877695D16F7E60B1959A0DEFC79B627E569E5C6CAC7B4AD4E3E1D8389A08584602A51CF84D44CF247F03BEB95F7D307FBBA12BB9
                        Malicious:false
                        Reputation:unknown
                        Preview:{"ShouldFloodgateTakePrecedenceOverRateAndReview":false,"AreRatingSurveysEnabled":true}
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:JSON data
                        Category:dropped
                        Size (bytes):14
                        Entropy (8bit):3.378783493486176
                        Encrypted:false
                        SSDEEP:
                        MD5:6CA4960355E4951C72AA5F6364E459D5
                        SHA1:2FD90B4EC32804DFF7A41B6E63C8B0A40B592113
                        SHA-256:88301F0B7E96132A2699A8BCE47D120855C7F0A37054540019E3204D6BCBABA3
                        SHA-512:8544CD778717788B7484FAF2001F463320A357DB63CB72715C1395EF19D32EEC4278BAB07F15DE3F4FED6AF7E4F96C41908A0C45BE94D5CDD8121877ECCF310D
                        Malicious:false
                        Reputation:unknown
                        Preview:{"Surveys":{}}
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:modified
                        Size (bytes):177810
                        Entropy (8bit):5.287196810087092
                        Encrypted:false
                        SSDEEP:
                        MD5:71C3833913DF3DEE17DA35A6E1735D0C
                        SHA1:D121071C752BA678EF45AC3D6B17582B86DE40BD
                        SHA-256:FF9AE47A866E713B317E2607D7DDBEB7395DF4EC45D077C5407AC5A4D9A967E6
                        SHA-512:F72C634AEDE4984A00B1FFF76D1F477E9E89B93515CB9A3D75D93E9595B5ACB489D27AF2DF96DA744C91C1AAC60BAADC838A79943FE10A81CA15084EC8AAFD00
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-10-10T10:43:06">.. Build: 16.0.18124.40132-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):489
                        Entropy (8bit):5.155248000155917
                        Encrypted:false
                        SSDEEP:
                        MD5:414277D4E3F104F55B935AB02A9BA9BF
                        SHA1:B01DF5CDB8EFCE39DA23495581D18C4AA4B1EF84
                        SHA-256:B8F1C0D81E44F9FEAB83DC2749B7807121F9BF8AB6AE82C01F8077FC05CA3FE1
                        SHA-512:40E2853C1EB0D9D627932232617C2D76EFA999DB788E20F5C7945C708B925E8A62788ED7D0F3518E72E00072AD7910BB199E67C82EE3119ABBEB3F3BB5E651C2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cm9y5" A="a24c8" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="OfficeTheme">.. <S T="1" F="OfficeTheme" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):517
                        Entropy (8bit):5.213185196410167
                        Encrypted:false
                        SSDEEP:
                        MD5:E03148FECDFEA3BFD90CA19AA52AC2C1
                        SHA1:BB0D4CE260F8E7C2F28A5A4FECD4AFA8B653BE2F
                        SHA-256:6BBCCD4AEA9494B1FD31DE86E19B2634F3AC6E6C72506BCBFD5A5C849C67829C
                        SHA-512:4B784F62D17524D89C194A534EAA1EF5FE69D21E907C97BEFBAB5321591256EE3D6348C48963A9DD9E156352218A6A8126DD9F2E5B934C0BE0B77D5ECCC6498C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100043" V="0" DC="SM" EN="Office.UX.Desktop.OfficeTheme.Changed.Through.UI" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a24db" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="OfficeTheme">.. <S T="1" F="OfficeTheme" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):457
                        Entropy (8bit):5.134868815976784
                        Encrypted:false
                        SSDEEP:
                        MD5:B9B2CA56A048BDBFE74315BAC8FEFAF0
                        SHA1:2061D5AA8AC1B3DC17C2839600F16C8975A58740
                        SHA-256:3C4A4929450C661680E8B674867368D76A71AA0A5FE6B1541E0CAB2EAECC2F2D
                        SHA-512:E6625F4A0B10DF7E3B966C40F5AD8FFB605592BC5AA0E250270DDDE78C539F376094CD95455DAC093B10B64FFBD2C3E4C17ED49AC39D8D5414731CBBC0F1B2EF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100068" V="2" DC="SM" EN="Office.UX.WhatsNewCantOpen" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqss" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="Reasons">.. <S T="1" F="Reasons" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):802
                        Entropy (8bit):4.792062686551037
                        Encrypted:false
                        SSDEEP:
                        MD5:8279DE7A54DC506ED68199AC880C2920
                        SHA1:C81A8D12C2CB577FC2A89242C8F9E22D4F37C6FC
                        SHA-256:40AD004C81F69364A2017FD3B758DC4C7834BC47A4A1340BED54594AF13F5B58
                        SHA-512:312A10EC95F62BCC2C924BEB9EDB7979E0EB3F8BDF5352874EB9337D2E8ABC02F2CC852E1B9813300FC1E40BB73422F075F4B42839180F6D0D15A49F211AFA3E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100069" V="1" DC="SM" EN="Office.UX.WhatsNewTimeOnScreen" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsl" />.. <UTS T="2" Id="bbqsm" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="I64" I="1" O="false" N="WhatsNewOnScreenTimeSec">.. <O T="DIV">.. <L>.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </L>.. <R>.. <V V="10000000" T="U64" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):410
                        Entropy (8bit):5.2896270378885895
                        Encrypted:false
                        SSDEEP:
                        MD5:D6DAF9F991EB87EB13BE13E79B869750
                        SHA1:D6611509E67BE22A205CBF308A08ACD150C99FAA
                        SHA-256:4CD12BB7EED5FE69ACC9E7A1EE29515CAEE4C453AB088F765ACB304DC882227C
                        SHA-512:686C1BCB148009D1D09EC6C1AE55EDB5CF454E46BBC39BE1536B45084CA09D4C7ADDD4C840E4AEC34500E2B4E92061D06863FDD35C6DB836B921557713E33682
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100070" V="0" DC="SM" EN="Office.UX.WhatsNewButtonClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsq" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):416
                        Entropy (8bit):5.295531666329221
                        Encrypted:false
                        SSDEEP:
                        MD5:3DF0BABC8132291994D448B40582DB90
                        SHA1:3C346E6C4A0779268FE62A4F7DF16307AF1F73C1
                        SHA-256:6FB9BDDDA6B632428391FAFE9CE78D58CD0986B6571D8BB4C9691496070F3F19
                        SHA-512:B982FC0ABC579C69F542C8BBBA3F78592E81BBE32DAEDA2D54E7A0427B0406DF62C53D483118A818A47162C766DAD68A29C83893401897D4994B993990D40288
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100071" V="0" DC="SM" EN="Office.UX.WhatsNewOnlineButtonClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsr" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):500
                        Entropy (8bit):5.241422570005702
                        Encrypted:false
                        SSDEEP:
                        MD5:B5F555AC798495BD8A6B4E254745EDA0
                        SHA1:C559E92D8618CA2F10E8734B77AFAFF25388F3FC
                        SHA-256:1C79426930C54765CB7B121361D58839DDDBCED8F37502FAB16903274414AB21
                        SHA-512:BF28AA7562613A4ADB9435701D58438AF3B2378D1BAF06394F4DE5805CC52628706A53D5AE3BCD4AAD12DCB6BE76EE7C533A9237113993450B2F2D8E62A5DE8A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100074" V="0" DC="SM" EN="Office.UX.WhatsNewItemHyperlinkClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsp" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="true" N="FeatureTag">.. <S T="1" F="FeatureTag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):586
                        Entropy (8bit):5.184710233838763
                        Encrypted:false
                        SSDEEP:
                        MD5:6E76DCB19FB44EA1E65014E0CE218AB0
                        SHA1:0313ABCCB6532B8749626F7BCB03ED0D730B8B6F
                        SHA-256:735879C44400699786304B87916667E37F35A3B26331C41B2366FEA88033B070
                        SHA-512:967A39E02654A0C6996C6DD9699C37E79007A8EFB7D315EBE23E77E5298A14B3AE80D8322C41FFFDE714CD0EA50F256A8C65A242450C163CAF5C70AF6E72C871
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100075" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutShown" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bfhe2" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="PreRegKeyVal">.. <S T="1" F="PreRegKeyVal" />.. </C>.. <C T="U32" I="2" O="false" N="PostRegKeyVal">.. <S T="1" F="PostRegKeyVal" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):729
                        Entropy (8bit):5.049181212012891
                        Encrypted:false
                        SSDEEP:
                        MD5:A1C32A2040850EEC0D8769D73B81F8B3
                        SHA1:6309C8B096063BA83039390BE9391E7FE6A91A29
                        SHA-256:8EBC17CB904B635F64A26B18D6C3BBB95BBA210C348D386F15A0C302B752A478
                        SHA-512:973A85A11BEC72BDC6A5E8FC50EABFA56CA04B6E659AA14854BD80ADF2DC98EB63BF1D4349979C44A32D81A42981327DD994C242EE4AEDDE96A68EDD0784D72B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100076" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutHidden" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnub" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <C T="B" I="4" O="false" N="CalloutAlwaysShow">.. <S T="1" F="CalloutAlwaysShow" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):586
                        Entropy (8bit):5.158726096353292
                        Encrypted:false
                        SSDEEP:
                        MD5:2BA258B06C54DF790012A5098D0DB9F0
                        SHA1:66AC50733B3D79D421AA3453C580B864830D8682
                        SHA-256:BB448A91F4A1AAEE49D517B15512555AE43508FE3471708EDC8B1549575E4A30
                        SHA-512:E31DD4A8FE41BD1431CAC663B0206F1517F84647DF0B0914E6EAD5CDC94367A6423C42B454F7FA11B4235ECE4C3F9A0796718916139C9EC332839486F7D4E11B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100077" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutButtonClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnua" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="ButtonType">.. <S T="1" F="ButtonType" />.. </C>.. <C T="U32" I="2" O="false" N="TotalButtons">.. <S T="1" F="TotalButtons" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):413
                        Entropy (8bit):5.287984558638439
                        Encrypted:false
                        SSDEEP:
                        MD5:F1CE09999B4B350E954C449DCD687080
                        SHA1:2DE21A2FFB189374B50FAFC28E524018874AE0B2
                        SHA-256:D708E23A5A1B7EEF562C29674913688C4C09F3BA6917988202F54A9B68EAD43E
                        SHA-512:9F17CD24C78E0FE9B5609B841DCE49EF7BB899859D1F1D26FF50E1601EA8A9AE74E933313132FEB229594570DAAF581A2557D87674BAC928D01F1000F5B9EE3B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100078" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutHyperlinkClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bfhe5" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):412
                        Entropy (8bit):5.267817827165894
                        Encrypted:false
                        SSDEEP:
                        MD5:3482F3A1659236D2232BA10912EF5CC6
                        SHA1:0C7CD5F8BBF3996C825E099148A6AC934D87C7F0
                        SHA-256:795F2F9F2683236ABE758C54944FCC1529B13DFA2F9CBC8FDFD5A6BE7B418922
                        SHA-512:4198CE6BEFBC9C2955A50B25C34F972E5FCB4F4E464FD4331E00E8B300670BD760F7E22091211BEAC280A0778BD4E77059B9F75BEA4C72BF931D4EE334A5790F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100079" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutTappedOutside" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnt8" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):681
                        Entropy (8bit):5.231377942579125
                        Encrypted:false
                        SSDEEP:
                        MD5:7B5BAC8525989E8899C3679731D98258
                        SHA1:C0803639CEFF57C7066B8ED1C67EB50B00349403
                        SHA-256:9A3292D9D11EE8CB27677F193ABE095831F9B7E4174D9E652F82803D328E5DE9
                        SHA-512:91D981040EA5E09BE70950240F8867229617D00092D1E66D537313AF74EA1DF765BDE195C2626B965B75E67BF8C454E2738ADE3E34FB44BA8D9B3068CBF78B13
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100083" V="2" DC="SM" EN="Office.UX.HighContrastAccessibilitySystemSettingsWin32" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhktg" A="bgkti" />.. </S>.. <C T="B" I="0" O="true" N="IsHighContrastFeatureAvailable">.. <S T="1" F="IsHighContrastFeatureAvailable" M="Ignore" />.. </C>.. <C T="B" I="1" O="true" N="IsHighContrastOn">.. <S T="1" F="IsHighContrastFeatureOn" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="HighContrastScheme">.. <S T="1" F="HighContrastScheme" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):403
                        Entropy (8bit):5.261641260441923
                        Encrypted:false
                        SSDEEP:
                        MD5:3671EA9C5CBDE113F64D8C3561349D0F
                        SHA1:34A9746232B7AD0A407774E6EC07ED97E3A295C2
                        SHA-256:7D7B07D4C42A86C7C69E9FDE8460DA77F21D6B82F7A65F183D859BBE9F76D674
                        SHA-512:7676A3F992C4A0FB1060D6EA5FDD2D352D74713B2EEDF42AF7D88BC96BD48EFA7DC56390F6952DB4C2ADE843F05B7051EFA2F9F37E52008EDA6CA85C49BCD22A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100084" V="1" DC="SM" EN="Office.UX.AnimationSystemSettings" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhkth" />.. </S>.. <C T="B" I="0" O="true" N="IsAnimationEnabled">.. <S T="1" F="IsAnimationEnabled" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):421
                        Entropy (8bit):5.2961268242072945
                        Encrypted:false
                        SSDEEP:
                        MD5:A6451ECAB2CD42E85B452E2BF1A1158C
                        SHA1:A04D2EA4080781702374E87591381B8F54051D4D
                        SHA-256:73FDDEB1B6C49CA452AE79D8975D99891A5CC1B2FA319F933081A7AD82E71955
                        SHA-512:D2631BFDBE43A130052E1436189445246C90AF7DEFC9C6E4031615B9F58F59D9519E11CDD3C6918D0770BD36F9C7958724D21255A5DAB75A5C6E2D4FAB95374A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100085" V="0" DC="SM" EN="Office.UX.AccChecker" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="be7sb" />.. </S>.. <C T="W" I="0" O="true" N="ShowingAccessibilityChecker">.. <S T="1" F="UxAccChecker" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):457
                        Entropy (8bit):5.193779288742389
                        Encrypted:false
                        SSDEEP:
                        MD5:0577879C523FD7CB65C2D80E7A663F27
                        SHA1:7A4863B6468521FC3AFF8331024A7537079A2035
                        SHA-256:7A9EAB976443BEB6F59CBD4F9B572BE0C7521771F3D871C0E4D6F53EB4DBAAC3
                        SHA-512:F4D4156DEF78C290FF6C0009C8DA02AB975B551C633FFC46156E0935D6E02D250F67DCDFFBC4A3DCBB7DEEF7722AD005CFB0BBA3540130CA5A97634D1DEC7564
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100094" V="0" DC="SM" EN="Office.UX.Dialogs.SDM.DoModal" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cnyur" />.. </S>.. <C T="I32" I="0" O="false" N="HelpId">.. <S T="1" F="DialogId_hid" />.. </C>.. <C T="U32" I="1" O="true" N="ReturnTmc">.. <S T="1" F="Return_tmc" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1594
                        Entropy (8bit):4.552983510334679
                        Encrypted:false
                        SSDEEP:
                        MD5:35A756BB6CA3F8BDDC97342284174200
                        SHA1:22F2158D40D9B17C665A965FE8721D45A352856A
                        SHA-256:8C638B3BF14BACA701C62344E8F41568D031BF006A440F0C92039D3685D13096
                        SHA-512:E31A85134F96F2AB82FA9B9B89BBFBA9EAF15035A397EDA4630D6F42A2859FBED98A112AE4560054D571F836C12C17024821926659AFDABD0C588557D99BEE50
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <Etw T="1" E="159" G="{02fd33df-f746-4a10-93a0-2bc6273bc8e4}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="Warning" />.. </L>.. <R>.. <V V="37" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="Warning" />.. </L>.. <R>.. <V V="29" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <TI T="3" I="10min" />.. <A T="4" E="TelemetrySuspend" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="2">.. <F N="RuleID" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):950
                        Entropy (8bit):5.13263189574204
                        Encrypted:false
                        SSDEEP:
                        MD5:11B08F2379BDB049177FAE40A8411612
                        SHA1:42689E356E86F48979F3A338F9ACA5C92CC5A911
                        SHA-256:70BF709198724DA28FC0AFD3B4DB93F514586ACDD769837B367563FAE256DB1E
                        SHA-512:A4584D522DF9196CE0401A593FA284DF21DC9C5D9D7765AF989838AAFB26EB5DCEE3FDA2D3A3AE535C2E7627B24EB6201CF4A78D8298F4E49CD6D33A81B42B21
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100104" V="2" DC="SM" EN="Office.UX.Desktop.SmartContextMenu" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ExperimentationCustomData" />.. </RIS>.. <S>.. <UTS T="1" Id="cplfq" />.. </S>.. <C T="G" I="0" O="false" N="ContextMenuSessionId">.. <S T="1" F="ContextMenuSessionId" />.. </C>.. <C T="U64" I="1" O="false" N="TimeTakenBySuggestionProvider">.. <S T="1" F="TimeTakenBySuggestionProvider" />.. </C>.. <C T="U64" I="2" O="true" N="ContextMenuTcid">.. <S T="1" F="ContextMenuTcid" />.. </C>.. <C T="W" I="3" O="true" N="Information">.. <S T="1" F="Information" />.. </C>.. <C T="U32" I="4" O="false" N="UserActionID">.. <V V="0" T="U32" />.. </C>.. <C T="W" I="5" O="false" N="UserActionName">.. <V V="SmartContextMenu_SessionInfo" T="W" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):841
                        Entropy (8bit):5.1130725494870894
                        Encrypted:false
                        SSDEEP:
                        MD5:9991F4C1B6E9408129E4545E3E0C5094
                        SHA1:D57948CEFBEDF08FBA780948F3D8BA208DB1AF76
                        SHA-256:BF1A2025122E71688D123BECAA5B58C35A36DA5FB321F3FECF4D58153975B399
                        SHA-512:502B5BF8FF233D15E8081ED99811AC1F5F3F6F63C8283E5D7FEF5C94571388B69979800F65EF2E0C90383B4D6A594D990EDF1CDEAB12393FEBCBC8FE90E00A20
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100105" V="0" DC="SM" EN="Office.UX.Desktop.SmartContextMenuItem" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ExperimentationCustomData" />.. </RIS>.. <S>.. <UTS T="1" Id="ctgzk" />.. </S>.. <C T="G" I="0" O="false" N="ContextMenuSessionId">.. <S T="1" F="ContextMenuSessionId" />.. </C>.. <C T="I32" I="1" O="false" N="SuggestedTcid">.. <S T="1" F="Tcid" />.. </C>.. <C T="I32" I="2" O="false" N="CommandPosition">.. <S T="1" F="Position of suggested tcid" />.. </C>.. <C T="U32" I="3" O="false" N="UserActionID">.. <V V="0" T="U32" />.. </C>.. <C T="W" I="4" O="false" N="UserActionName">.. <V V="SmartContextMenu_MenuItemInfo" T="W" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1045
                        Entropy (8bit):5.1005145953903295
                        Encrypted:false
                        SSDEEP:
                        MD5:F06A86C81121B490ECBCD2104D19C599
                        SHA1:F18D7727120EBA5FCFE8536E3FE34E68A2620D61
                        SHA-256:7D72509EBFEFA8422109C6EED61991763C6D9A2E3BC2BDBDA2D8D2FC741A5094
                        SHA-512:32B47E5796409DBCC70360311D0752B562F4D8DB657464E6FB39DD134CD31B326F9B2378476077E997EF53B0C707A86A365AA1945A24B097F0BBCB182F865026
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100106" V="0" DC="SM" EN="Office.UX.Desktop.ContextMenuItemClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ExperimentationCustomData" />.. </RIS>.. <S>.. <UTS T="1" Id="ctgys" />.. </S>.. <C T="G" I="0" O="false" N="ContextMenuSessionId">.. <S T="1" F="ContextMenuSessionId" />.. </C>.. <C T="I32" I="1" O="false" N="CommandPosition">.. <S T="1" F="CommandPosition" />.. </C>.. <C T="I32" I="2" O="false" N="CommandType">.. <S T="1" F="Command Type" />.. </C>.. <C T="I32" I="3" O="false" N="ResultBindingTcid">.. <S T="1" F="ResultBindingTcid" />.. </C>.. <C T="I32" I="4" O="false" N="ExecutedControlTcid">.. <S T="1" F="ExecutedControlTcid" />.. </C>.. <C T="U32" I="5" O="false" N="UserActionID">.. <V V="0" T="U32" />.. </C>.. <C T="W" I="6" O="false" N="UserActionName">.. <V V="SmartContextMenu_MenuItemClickInfo" T="W" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):545
                        Entropy (8bit):5.118071593489877
                        Encrypted:false
                        SSDEEP:
                        MD5:9AA744D5B6B17CD62043AF4E53E7B38F
                        SHA1:D8DBC753961C8404F8D873278E7AB53238C683A7
                        SHA-256:2586C46FF798CBCAC590A3506190AA94DE2A483B31EA20BADABFBED1CFE74AC0
                        SHA-512:D5CD6D35E45B8C3F826762D3AD183E17FFEBDF1E88CE9541D668B14A466184F0E127F67EEF548D821B690675872EF31E67A7203CE38FE77B72790C6EA88E6718
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100109" V="1" DC="SM" EN="Office.UX.HostedSurveyShowed" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cmgze" />.. </S>.. <C T="W" I="0" O="true" N="SurveyId">.. <S T="1" F="SurveyId" />.. </C>.. <C T="U32" I="1" O="true" N="SurveyType">.. <S T="1" F="SurveyType" />.. </C>.. <C T="W" I="2" O="true" N="ManifestSubType">.. <S T="1" F="ManifestSubType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):460
                        Entropy (8bit):5.1674364373796875
                        Encrypted:false
                        SSDEEP:
                        MD5:BE4F266143658422F4649C9A2CCF6B60
                        SHA1:FDBC871B6F3403285D9CB928AA42694C645792A3
                        SHA-256:777A02FD054568BBA52B024BC36BB0F9428F5912D1A77F3C0A1AE9BB38305613
                        SHA-512:787D7A32BC01B4081BECB4E2EFAFFCD7DE4F6123620D9707FCCADB7E058ABD40FC15792AAB5EF65BECC8BEF43CBF9469DA22313AFB39656464B44B6BFB3F26E1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100110" V="1" DC="SM" EN="Office.UX.UpgradeOfficeButtonClicked" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c7xsl" />.. </S>.. <C T="W" I="0" O="true" N="SurveyId">.. <S T="1" F="SurveyId" />.. </C>.. <C T="U32" I="1" O="true" N="SurveyType">.. <S T="1" F="SurveyType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):409
                        Entropy (8bit):5.271528662709587
                        Encrypted:false
                        SSDEEP:
                        MD5:02042A13C2C5CD1B3EDC95A6B15E4FC7
                        SHA1:F08188D7215D13A767C4D4FC517BFA881D985712
                        SHA-256:034C44375BF10EF9DF06C6D354EF65C6739D8E467A2F17F2F169C92001EC038F
                        SHA-512:DCC10C3B5065BC5CC7C86834DCEEB9948CA30CF76FCC88F68F6A4BC9048D65D3705BE1380C5F0AC28B738DC38DDBAB122C6A248E460F61D497C294FE8AF3007F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100124" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutSuppressed" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnt4" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):509
                        Entropy (8bit):5.2429290585512724
                        Encrypted:false
                        SSDEEP:
                        MD5:03AED7AA46EBBB9175F30A2BF8F7F530
                        SHA1:F0FA4FAC253E9DE69F814A464BEA53DCDB6D6D7C
                        SHA-256:71BE055A91F15DAAF9F37FA90A0A65D6EBC7C20CEF1D41445854500576F7F068
                        SHA-512:468F848A7DA60EFCDE910031D3AED6E1A9E84016DCA7540B9C4AD3A00492056D3D57E5C596756665B18CA6F661280B22C84594F004110E6E7BBF761B8E206128
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100125" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToCreateWICFactory" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisgt" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="APIHResult">.. <S T="1" F="APIHResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):515
                        Entropy (8bit):5.259684957183188
                        Encrypted:false
                        SSDEEP:
                        MD5:170633F0EAB1976D69AF72CD49C6766E
                        SHA1:426EB2461DF891C78C7228EA87262E643D721CBC
                        SHA-256:A1CECD578E1263D01D03633FF36054F5299E6F1F6AB39B1C46D75FBC6005655A
                        SHA-512:F50B9A8422EF1DE054081299EF156C6B436D945A1D6F214CD613BDA1A0CC3B14DD393DB54DB760264B81789900B5DC514D858A5EA111961B04335979B701C130
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100126" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToGetDecoderFromFilename" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisgv" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="APIHResult">.. <S T="1" F="APIHResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):501
                        Entropy (8bit):5.234524039048711
                        Encrypted:false
                        SSDEEP:
                        MD5:85C60DF6C18137A60BF1A03F35F2EEB5
                        SHA1:F6A5401EC2E7AAF2B706A0FBB694BB84CE41F2D3
                        SHA-256:A31B06DD5540239D68D5F75CF8FC416C1FD5C24A8237EEC8DDD07CE3DFBD92E3
                        SHA-512:AA0766C418EDAC12F5CABA90807FB800E40EB6A6D4A4EDB167755126869F05B295BD3D35B033C06FF7CD1856B77C0A0011C5A095420D8223A0F10ADA3EC80087
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100127" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToGetFrame" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisgx" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="APIHResult">.. <S T="1" F="APIHResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):5.254995423773981
                        Encrypted:false
                        SSDEEP:
                        MD5:05F479C943851C6FF70E8762CFCAF94A
                        SHA1:98E7C7D2BC7B278F491C7F00F44A42BD8D935E57
                        SHA-256:F19EDD0DEC9F58B711ACD45E52409321BFF693853557690E9CEDB0BD0E71A942
                        SHA-512:23322F5E4CB27432114C91EED94D6FF6E654B63EFA6D28B364CCF01E83306699BAE5869F27B2D295B67070CCB4EC3991DF32B2973D50A23BB1D3D3E6779A7CC4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100128" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToCreateVideo" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl7ep" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):5.258730267850173
                        Encrypted:false
                        SSDEEP:
                        MD5:3BE6320F54CACC68FF5332D7F19017AF
                        SHA1:34321424619ABF9C69E03109C6AC9633C09A0490
                        SHA-256:B10674D4BB061FB003BACC6AFBE070A7183D2D1A287099936FFFB931E3D5F5EE
                        SHA-512:252A8498605D19C3DAF5ED983C40541A6E77B1BAA6AF9BBDC63228C2A81C79076AC3EB405393BB902C79F70E644D7AA103EA8D7FF0D8614C2E432F9143A6FEDE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100129" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToCreateImage" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bep2n" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):485
                        Entropy (8bit):5.202017526192053
                        Encrypted:false
                        SSDEEP:
                        MD5:765304F24D02DEB0E55BE018E9FEFB99
                        SHA1:9B3D0B42621BCF5A5EE53B01E1D841EF21776DE9
                        SHA-256:7962562BFB89190AD2B7C932D1EAC211A8533B7A6D8842736FDB2424EABA22AB
                        SHA-512:CC1E376C53E372A762B4916BDA601EB0D67B337EBCD7E8FD85D3CBD5E0FC1E04E0EEAEAD489D86E354B8B1265DEE491AC594B52A77858F4D7EBB0B3A93779098
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100130" V="0" DC="SM" EN="Office.UX.TeachingCallout.AnchorInvalidCallback" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmzya" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):639
                        Entropy (8bit):5.057028798011694
                        Encrypted:false
                        SSDEEP:
                        MD5:FE6EFF7CC51E8C64DAFE15F2F5B08F0A
                        SHA1:3619F72BC2A5656EDA6B3098629BC1D43F567143
                        SHA-256:DCA842112B5A586E2B07AC91EE140B305C57F4004D40CAF8E8AFC09D4FFE2089
                        SHA-512:00E577AEFF86E2F062336BA1C634F087B62C824F0D7EADC92B8971A6A3D6532853458E1F2CB7AFF4C11141681CAE3EC77068EEEC0CA9CB01F3A21A5168D7EC96
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100131" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarkShown" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnuf" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):656
                        Entropy (8bit):5.097491847536972
                        Encrypted:false
                        SSDEEP:
                        MD5:109B2CA6601FAFC1E0C81848FE7B35FF
                        SHA1:012627B761E319EB73B51190DC3D884FE84D7D8D
                        SHA-256:1E6A4E86CEF8C6EB85D2297E959D418BEA102DAD9133177462800CB4AF3E8533
                        SHA-512:D97E22E0E603B06C1EFCFFAFFA413BF2AE4231545D717063D01E6D7445985F7E6CA65D89FE961F2C7BDC65A28AA93C88224C007715CA2A6B171D97DB7D27DA18
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100132" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarkHiddenWithoutExpanding" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnue" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):643
                        Entropy (8bit):5.0658952579474645
                        Encrypted:false
                        SSDEEP:
                        MD5:3711CCBD08320FAE2AEE12194EA45A68
                        SHA1:970D1B229C11C851E0964A7C0F333377734F1D10
                        SHA-256:78AFCBBCFDE75A7DEB70B8AE80213D76D06D824D5F494719081F507E791E889D
                        SHA-512:5300894FDDB0A075E7DA7FE828000B64EDB7795E47219EAB2BD7504E7C1D058381CB213D59D587185F92A40AB6F029E4AEB29E4DA83984983C409B9864B68ACD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100133" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarksTUIShown" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnud" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):742
                        Entropy (8bit):5.0659835404992695
                        Encrypted:false
                        SSDEEP:
                        MD5:570EE9E464A3F9CF12C8FB0F50B48E06
                        SHA1:AC394C063E80F880195FE859048B90BB2E42891F
                        SHA-256:B881023859406F131865B38F176EA00D08C3D9A0BEDBF9BB189BF051D99504D5
                        SHA-512:97EB77C67DF5604B3A6ADFB0911446492C9B83C87D1FB8A47B9D84AA16162489FEAAFCE1112C6A720B2DC02579FF9F55E64BFD5AAAC998461DDDE6FA4A967B8E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100134" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarksTUIHidden" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnuc" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <C T="B" I="4" O="false" N="CalloutAlwaysShow">.. <S T="1" F="CalloutAlwaysShow" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):409
                        Entropy (8bit):5.284731259430513
                        Encrypted:false
                        SSDEEP:
                        MD5:1EA191226A363A271C15C2F470CA5A27
                        SHA1:88C8FFA286C023D049F764164C905993F326AF75
                        SHA-256:5AB9DBD686E3724114A39F1F5B743186C3E54BDA7651C7116484CBFE2472EA20
                        SHA-512:BA80F037204D9050EBC138C88657810F7D26552608D942678853B05F3E7A90B9960BA92C5E460F37C6927614FBE6474AAC271BDD935C667D1108A68A731267E3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100201" V="0" DC="SM" EN="Office.UX.HyperlinkDialogControlTriggered" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bg4y8" />.. </S>.. <C T="U32" I="0" O="false" N="Surface">.. <S T="1" F="Surface" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):595
                        Entropy (8bit):5.183023140804415
                        Encrypted:false
                        SSDEEP:
                        MD5:0DF2BC07A6BBFDF8FA8DAFF18DE89752
                        SHA1:95BFD0A56DF9F1B8CBB157C102EFCD17E7D13813
                        SHA-256:7C039ED8E77E4B44A8A4EDC8DDD3F020893B8EE3588E52A31505774EF53A882C
                        SHA-512:17DDC165955D9C28519AB0FF4B82F80F3757A7063289C12D25A8146558380FBC311B56C9C8CC633831466430A14A3ED233DD0454217F172A2ADA487CADE2F094
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100202" V="0" DC="SM" EN="Office.UX.HyperlinkDialogInsert" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhdvx" />.. </S>.. <C T="U32" I="0" O="false" N="ActivePane">.. <S T="1" F="ActivePane" />.. </C>.. <C T="B" I="1" O="false" N="HasScreenTip">.. <S T="1" F="HasScreenTip" />.. </C>.. <C T="B" I="2" O="false" N="HasDistinctFriendly">.. <S T="1" F="HasDistinctFriendly" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3146
                        Entropy (8bit):4.508946786981067
                        Encrypted:false
                        SSDEEP:
                        MD5:6FF3467268BD237803A45014883BB526
                        SHA1:F5DDFEEAAE8B71F3AC671F309822D45BB42033E0
                        SHA-256:2AC1F2E48418DA10E57310FD901C76F19F8764ADE0E6570EF1E2ACF3D199845D
                        SHA-512:690531C90F83679ED68B8F4694A28C0CEBD84675DF19248939797DCF3CFE9D04859EFEDE7954F0FB16A56D8688784C0E27D2B350EA31678C20DB9DD7B30A6235
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10100" V="4" DC="SM" EN="Office.Outlook.Desktop.ImapSessionStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="104" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="2" E="107" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="3" E="110" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="4" E="111" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="5" E="114" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="6" E="136" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="7" E="137" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="8" E="135" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <F T="9">.. <O T="EQ">.. <L>.. <S T="2" F="Cookie" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="10">.. <O T="OR">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):727
                        Entropy (8bit):5.108505754989354
                        Encrypted:false
                        SSDEEP:
                        MD5:2B9151DFC36BEA465EE7FBBDB954C535
                        SHA1:5AEB74704975487E194AD391CD5C85A3221E64F4
                        SHA-256:F6F01D681A446C0770D08489DD51189DA4CDD2EB8C5E6890FF036FA399E39A34
                        SHA-512:D75FA40A4E3181B123B04C16A8CDB4DEEA74B7149E4F640CC891D8592BB7E89D31DE2986C5238D74BFCC3626608667701D2FF4B0747864850E9D73A728043F09
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10101" V="1" DC="SM" EN="Office.Outlook.Desktop.ImapRedownloadedMessagesDetail" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="135" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. </S>.. <C T="FT" I="0" O="false" N="EventTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="FolderUid">.. <S T="1" F="FolderUid" />.. </C>.. <C T="U32" I="2" O="true" N="MessageUid">.. <S T="1" F="MessageUid" />.. </C>.. <C T="U32" I="3" O="false" N="Reason">.. <S T="1" F="Reason" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3581
                        Entropy (8bit):4.319953654572439
                        Encrypted:false
                        SSDEEP:
                        MD5:FFB8D60DF34E2B842ADBE605BA68D3BB
                        SHA1:56034F7C1A9302916BCBB5C26B5395A1C027F663
                        SHA-256:863AA2C79B6B94241211F41954762B70F073C06491AE2CDC04694393F6F55DD3
                        SHA-512:9387BC2E91C898CA7C2D84793FA2FAC98E783588AEA6622742679B8068A99EAA63617047A2C55065BDB7B22F9F12E193A1E6F27FF329CD5526510FE2A878B52B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10111" V="3" DC="ESM" T="Subrule" xmlns="">.. <S>.. <TI T="1" I="1min" />.. <Etw T="2" E="4086" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="270" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="4" E="4106" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="5" E="566" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="6" E="675" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="7" E="676" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="8" E="277" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <R T="9" R="10408" />.. <R T="10" R="10111" />.. </S>.. <G>.. <S T="2">.. <F N="ConnID" />.. </S>.. <S T="3">.. <F N="ConnID" />.. </S>.. <S T="4">.. <F N="ConnID" />.. </S>.. <S T="5">.. <F N="ConnID" />.. </S>.. <S T="6">.. <F N="ConnID" />.. </S>.. <S T="7">.. <F N="ConnID" />.. </S>.. <S T="10">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2575
                        Entropy (8bit):4.943690754092889
                        Encrypted:false
                        SSDEEP:
                        MD5:51C90B69B876269DC33BD8D8FEA793E3
                        SHA1:7AD16FA0855410498763EBCC126C164C262993E4
                        SHA-256:68863C7CF677C677A6349F09BCAC56136B1FC2676BFA5BBE4D1FBC8CD7D02654
                        SHA-512:9427D8441953C82D70BD215313D2DC9A95D55C5575E057BA5DA13A67C3B4A81C2D4B09F75898803305D73002A978C7E58D8E146B804210E1924B4898B327F057
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10119" V="5" DC="SM" EN="Office.Outlook.Desktop.OutlookLayout" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8100" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="AwesomeBarExpanded">.. <S T="1" F="AwesomeBarExpanded" />.. </C>.. <C T="B" I="2" O="false" N="TouchModeOn">.. <S T="1" F="TouchModeOn" />.. </C>.. <C T="B" I="3" O="false" N="PortraitModeOn">.. <S T="1" F="PortraitModeOn" />.. </C>.. <C T="U32" I="4" O="false" N="DPI">.. <S T="1" F="DPI" />.. </C>.. <C T="U32" I="5" O="false" N="ScreenResolutionX">.. <S T="1" F="ScreenResolutionX" />.. </C>.. <C T="U32" I="6" O="false" N="ScreenResolutionY">.. <S T="1" F="ScreenResolutionY" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):852
                        Entropy (8bit):5.106585100855806
                        Encrypted:false
                        SSDEEP:
                        MD5:AB10F26BADEC1D42F0080AC8A2EC289A
                        SHA1:7780651F9B12BEBC502FC0D6A73F8BB397270CF4
                        SHA-256:EB84D268F96520E655D4D409569B5100DE0D36110E7985C2309F3CDAF40A3601
                        SHA-512:6A221BBB0803016BEFD49C195F5BC3515C84BA4B81C76C0CAB8C904257D4AB884786356EA3FFD4A07D65A473E15D058358E2FB403FDD1455DE47FA42E1CD7289
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10145" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentsFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4110" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4112" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <TR T="5" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="5" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="GalleryClosedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="GalleryBrowseButtonClickCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3877
                        Entropy (8bit):3.925777788823839
                        Encrypted:false
                        SSDEEP:
                        MD5:49F5C886CD66DFFE23CABB589481F00C
                        SHA1:B1135101F93767957D9B29212B78C80BFA3A0851
                        SHA-256:D627E61866107DB48D77661FD746744F6A9EEEEA0193077EFAD152E1A6BF3970
                        SHA-512:48AE868716DBF64EDC8B3F8F2DB9E6578808F3B68011503794973880774F23A0B5F511A6786AB2E8C7A36A2FB99A1A06A3EFA6EE5D0693A269B68CD1DCC9C5FC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10146" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSuccess" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4111" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):760
                        Entropy (8bit):5.190312368254792
                        Encrypted:false
                        SSDEEP:
                        MD5:272EB1EC59F9D51625FA2D7446C8DADE
                        SHA1:6CC60666ABB895525230A71284CA7661606D26E6
                        SHA-256:B749DE176193BB7EE0F1B220D20A4FAE1CD8F91AD49FAC187189F089DB4387C8
                        SHA-512:2B27990B8A1A0C80FAB8757B1D5AE938BD7C15869FA2EFE3030D0FA9D607917A015D9D1CD21C8CA17956A1030C4B0FDA542002E029ED74D63FFB448BADC39D4D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10148" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchSessionQueries" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <SQ T="4" R="([2]|[3])" />.. </S>.. <C T="FT" I="0" O="false" N="EventTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SearchSessionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalDistinctQueries">.. <A T="SUM">.. <S T="1" F="FollowUpQueries" />.. </A>.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):579
                        Entropy (8bit):4.8007189542904944
                        Encrypted:false
                        SSDEEP:
                        MD5:0DEFB7361DF6139054B2DD12853092E0
                        SHA1:74F3DCC66C980937F6E134F9A71206ADD50D247F
                        SHA-256:75628F173F32E77C6EC3115D6733346B2BE6A032D6199EDAF34440A27B40A67F
                        SHA-512:3B6D2227BAB188BFFAB098EB9E9EAA8F2B427609AA43FE849AAD1AD1EC863DF57FAF37CDAB3356CF9D68C0009EB5672F3BB726A3015B36495A07C756932C4C80
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10155" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4104" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4105" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):579
                        Entropy (8bit):4.7993548413267595
                        Encrypted:false
                        SSDEEP:
                        MD5:2DF47221FCD5ACFE77DB18C83E99AB2D
                        SHA1:8209F1E0F885E2906685964E529E1DA018F9345B
                        SHA-256:826DEB2CDEAB0229866D098A86A8F5E1BA6F9DBEE212D801D5B4DCB42CB94CEC
                        SHA-512:34B53783DD5EB157529326A43F89829E59A9B651737CCE0EDC720E0F549106A7C40CA7AE79487BD642D55D17A1E22EC8288B12416DACABC2110196AC2875C10C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10156" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4106" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4107" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):579
                        Entropy (8bit):4.798169602663376
                        Encrypted:false
                        SSDEEP:
                        MD5:62E54506D475F39D5D6ADDA2D649C90B
                        SHA1:FAA204C07798F56D4ACAA03DD3E0DCBF2CA63A04
                        SHA-256:7A9AAFCCC77ABEC5724396BC8C0F3610A32B61BFD45A189ECB5FDE04ED2D0A67
                        SHA-512:1C884BFAA4BAE6E9806196B7D454BD200481F2AFC565EAB3B5658C1120EDC3DB65B2332466B620D52B8392517D9D3E6FEC4290EA353A85D458A9B585DCBA8D4C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10157" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4115" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4116" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):579
                        Entropy (8bit):4.7968257638721274
                        Encrypted:false
                        SSDEEP:
                        MD5:655AA6B7E0D318C3CC36CBF6119D9848
                        SHA1:2C581E12C2E0487D239FB580BACF839C0B17D9FA
                        SHA-256:218C268719118758D6A61A1970BE9478C7E42A16CEE3654289BE9A41C270204F
                        SHA-512:BD5D5F80C41ADDE63B1B8DFD9DD4247E30F413B4DCEC395FCFA1D2342F929BAA2694CA9A6D71AEAFAC28906014084C9226FFECAACB94AA44589753930A3355A1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10158" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4100" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8281
                        Entropy (8bit):3.9192806348703595
                        Encrypted:false
                        SSDEEP:
                        MD5:B66A367E476ACC8C56C788850E5F5C2C
                        SHA1:186B0D405F4E2A6C011D15C7189E392E03FA4EF5
                        SHA-256:E66C552809AFF9B7A5E5A903271C1EA12C1A561F6E4C740402A04ED88FFB0CB1
                        SHA-512:7BD68CA560C7F13BA85D94C60B62A4C72066AA25E34D787E73A0C230CF10E6DA412FE59B92A4E2F65FE1FBC09EE40F363139D4738F25329B0C84D67A01B357A7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10166" V="1" DC="SM" EN="Office.Outlook.Desktop.MailAttachmentSizeNumber" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="10000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Hourly" />.. <SQ T="3" R="[1][2]" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4486
                        Entropy (8bit):3.7678228223786885
                        Encrypted:false
                        SSDEEP:
                        MD5:505E8F9CEDDF4C1450117FA672F9611B
                        SHA1:07A92E09D9DB152370193D0A6E167F1A3BDB7D16
                        SHA-256:1E5406A0FA73FD7180D1C3D03C286869E0ADADCE287589C40786BCC179C69570
                        SHA-512:89394D35E8DDB4DCBC490884EE62B0828072BA6BBAF276079B384D1F16819F5F83CC79DC75C23C0D692D88B3AFA9456FFB6DCCA2ED5909DBC6856913B258F56B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10177" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentLocalMruRefreshUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10155" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="301" T="U32"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4470
                        Entropy (8bit):3.80724102352738
                        Encrypted:false
                        SSDEEP:
                        MD5:C884F342BEFE8025A359FA3D1A931DFC
                        SHA1:42A007E8CD713233AD35E6F05A3C85FC9D15E9FE
                        SHA-256:60A7902E22F25A698C1DE4C52F1FE854686CF263433F85B9566A6F3676D3D48B
                        SHA-512:F9C1E9B9E9A5A4BB60C97FF450D70A3B0166EB0F4E14297A99757FA1D5AAA20747E9BE3FFA24CAA29AB038AD0BFBFB1CA53D6B7C302E092A7112BB45152CC104
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10178" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentRoamingMruRefreshUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10156" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <SQ T="4" R="[1]([3]|[2])" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2369
                        Entropy (8bit):4.152848078919524
                        Encrypted:false
                        SSDEEP:
                        MD5:9A28F393C3C78BD48A446BC179F95C5F
                        SHA1:C9D56BF09053471D3CDB2B0C7C326E9891FD4DE0
                        SHA-256:0143CD233C0975EB010D5CD4E3B3436113A08990845CD6DC06D7ACC7EC079B4F
                        SHA-512:F214F60C6143FF492A4D2B0DCA28C1AF2623FA430C7D7DD32103338CB356458FF6061400832536E83EF7E0CA2C160B01E786238870B86B44CBBDA2C2CEBA69E9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10179" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentMasterMruMergeUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10157" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <SQ T="4" R="[1]([3]|[2])" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3586
                        Entropy (8bit):3.905238509406438
                        Encrypted:false
                        SSDEEP:
                        MD5:CEBD6F38A643CCCC409E61F2FF7CAA69
                        SHA1:19C493EAD92B7F3FB66582E567A6A816C0F933D1
                        SHA-256:70F2CC759F96BD6F86BD8E691F2A9424BC40301F2DB608C997176528FE127166
                        SHA-512:A85517AE0EA0C23FA5E6E417E22AA7EE8086C5FEFA424B63864268E985CF37B850A5F2D2233B76170B389D44A58BBD3CB6671DFFDA1C1CD82CFF366D345F091C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10180" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentGalleryPopulateUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10158" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="7">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):494
                        Entropy (8bit):5.29821635346088
                        Encrypted:false
                        SSDEEP:
                        MD5:D4A849BE3E71FED884E424B7159FBF55
                        SHA1:C702FAF3B512E3FAB4E22FED589C6D20FEB77FA2
                        SHA-256:3DC9BF1AA4CE04479493C9BA0C8DBEB35F246B424756CD9E91C8AF8E03B8B415
                        SHA-512:33E7032AE25F5E1108EF13B8C208980019C2A5696DA5B19E3905DBFCB265D2401A83839A0269B1414CDEF44437D114F7DC16E7B63EAD377EF3E6CCE30C6EFC25
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10202" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchHealthState.CEIP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6500" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ErrorState">.. <S T="1" F="State" />.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):495
                        Entropy (8bit):5.339202817505073
                        Encrypted:false
                        SSDEEP:
                        MD5:BC17C2C7ECBED3A0F78EBFDE28859285
                        SHA1:F01F249EEF7C20DBF964F3CE4776CD49C84EB738
                        SHA-256:900A61A99BF493AF06E100AFD56D9BA092E4B43E44A1F2E3B761D6B0DB094AC2
                        SHA-512:DF0C79D077677AD2FB4C3298346D1DFF63748753716C0AA9DA47A27A7AE73D5062D456B7C4F8D8B37C085DD4A54A0A013BDDF4EF369EE22295105B0F96BBD7AF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10203" V="0" DC="SM" EN="Office.Outlook.Desktop.RepushToIndexer.CEIP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="552" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="RepushReason">.. <S T="1" F="pwzReason" />.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):765
                        Entropy (8bit):5.2033766222867275
                        Encrypted:false
                        SSDEEP:
                        MD5:4D83B5D170E9F9ABEEEEFF0EC67EFEA7
                        SHA1:71FC24F35566B456A296FAF7F1060AF724AE82D9
                        SHA-256:72DECE77E6DF06472192D9CF5C2B872974239E494719E35F51307734DDDFE085
                        SHA-512:1198718952E6E25BBA118CD4BEB38EF9D61A26D9A1DA22AF7F6632E1567BDC42137561F59D8C13CC962FCA33F8F40D662F02BA032C2BDECEBB70F057FC763C61
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10204" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchSessionQueries.CEIP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <SQ T="4" R="([2]|[3])" />.. </S>.. <C T="FT" I="0" O="false" N="EventTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SearchSessionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalDistinctQueries">.. <A T="SUM">.. <S T="1" F="FollowUpQueries" />.. </A>.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1728
                        Entropy (8bit):4.6960452034160864
                        Encrypted:false
                        SSDEEP:
                        MD5:4C5F246DE21CDBD172E0C0480CA8BA1B
                        SHA1:29FC484692F3BB5BE7A126A9ED40BC646D96060D
                        SHA-256:69219BEC3B67F362E27382527694CFED0906B188DE29326B31CA55B21ACE8F57
                        SHA-512:193EAEA9E8DCE03DF32B021C5E92BABE13167BE7C1962E74670FECB8E6FD4FF14738EE01BADF34D2FE9FD5F3C7048F504C0B95DBBB29EF1B533230953CDBA080
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10207" V="4" DC="SM" EN="Office.Outlook.Desktop.ForegroundRPCPerHour" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="561" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="558" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="FForbidden" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="FForbidden" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="2" F="BlockingBugId" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <TI T="6" I="Hourly" />.. <A T="7" E="TelemetryShutdown" />.. <TR T="8" />.. <R T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):564
                        Entropy (8bit):5.236745811461481
                        Encrypted:false
                        SSDEEP:
                        MD5:AB3919EDCA75CC637FD94123D56C0699
                        SHA1:08E25031E465F0FCA798A19F16B9EC14B0D11CAA
                        SHA-256:6E7F60AE0F2BF5B851128FC19856E2D71EF25E7F210C310B08FDE57795F79F58
                        SHA-512:8B84BFE2D565F6AE22E73C0A7D94C87D105D24DA71B32BF474701EEAFE00503266E3CEFE64AB5310B42CD52896151CC5C8F247AF988F3D0B8BF44DE71EB6377C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10208" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookTheme" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="CurrentTheme">.. <S T="1" F="CurrentTheme" />.. </C>.. <C T="U32" I="2" O="false" N="Timing">.. <S T="1" F="Timing" />.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):509
                        Entropy (8bit):5.204853110720731
                        Encrypted:false
                        SSDEEP:
                        MD5:23BBCFCC28C498CE4C6E35225534300D
                        SHA1:21AAE8C55AC91901A869A1719BCDD8CA3BBF93CE
                        SHA-256:EF387F995F932BFDC068743C204906B7A7A8909B14749C17BB47EB251ACAD1CC
                        SHA-512:A615E5F1FCF81A933EEDB7DCF0C77E45AC157E5D3D03028550D5D4315A419A704C622418C00C9C65FD770636D95212B5426FF14AC1C125AD4B49D409E4EECB2E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10217" V="0" DC="SM" EN="Office.Outlook.Desktop.DefaultFont" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1508" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="Font">.. <S T="1" F="FontName" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):511
                        Entropy (8bit):5.2224101127064895
                        Encrypted:false
                        SSDEEP:
                        MD5:F8B68775E57C14130F182027350D750B
                        SHA1:1992BECCF8BDE4572B6F8589E0063ADEECBC964E
                        SHA-256:79CDDCB1937F19D6E2AC43DDC8D1872121F1B71874B959007E80EDE8BAFAB2F7
                        SHA-512:FFF4A818717E742852D6F0F8F53FFCC624D60C6C0CC6FF001DC4F1168DBDB5EA1B0FBDC455E476EE811A62588B9FB7C20B6DC2D3F9625F9B43C6AF1CBFC2A2A6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10218" V="0" DC="SM" EN="Office.Outlook.Desktop.AppliedFont" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1507" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="Event">.. <S T="1" F="FontName" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):5.1129913733810595
                        Encrypted:false
                        SSDEEP:
                        MD5:4FBDE5AAE43D6174395019D841AF2475
                        SHA1:CAEDA33ED7919BEFF86EC8DDA98BD8A999305A9E
                        SHA-256:803912A1B19C8A701002507D9AB2F24AD42A6A17E033E1BAB41E6D200C2AA2CD
                        SHA-512:4B4FF455789287AC419C132DA4F7FA30741A0FCDF2BC7BA443E75DD56BCB742154B37A3BA44C02095A812E9DEFFD972109E7B3389A1355269BF627CF2BB95CCA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10244" V="1" DC="SM" EN="Office.Outlook.Desktop.ImapCapability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="115" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <SR T="2" R="CAPABILITY">.. <S T="1" F="ResponseBuffer" />.. </SR>.. </S>.. <G>.. <S T="1">.. <F N="ResponseBuffer" />.. </S>.. <S T="2">.. <F N="Input" />.. </S>.. </G>.. <C T="FT" I="0" O="falseNoError" N="CollectionTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ConnectionId">.. <S T="1" F="ConnectionID" />.. </C>.. <C T="W" I="2" O="falseNoError" N="Capability">.. <S T="2" F="Input" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):742
                        Entropy (8bit):4.973626752240643
                        Encrypted:false
                        SSDEEP:
                        MD5:BE2A7B5FC3E03C7C85FAEB2AE375FA47
                        SHA1:76B6F3457B038812AB1F009465950FB2ED57A44E
                        SHA-256:2BAABE84A76F275857F2E25D941B97ADD23844A3FC8C4AAD725CC950F229BAEA
                        SHA-512:BABEFA4917A30ACCB10572231CD76FFF28F6ACF74CD8CDFD1C8F26175F0941F0ADCADE84CE7262116ACB3C142F2D387CD6C10F8EF567FAAF320382D42EF9C785
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10300" V="1" DC="ESM" EN="Office.Outlook.Desktop.ExchangePuidAndTenantCorrelation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DL="A" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="15min" />.. <R T="3" R="12076" />.. </S>.. <G>.. <S T="3">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="PUID">.. <S T="3" F="0" />.. </C>.. <C T="W" I="1" O="false" N="OMSTenantId">.. <S T="3" F="1" />.. </C>.. <C T="U32" I="2" O="false" N="ConnectionCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2720
                        Entropy (8bit):4.257158845522902
                        Encrypted:false
                        SSDEEP:
                        MD5:0CADA144D1AC00A1D81627CC77E793EF
                        SHA1:90D1A01EDA853ACF2B824240603EBD4892953812
                        SHA-256:2C648334328C5EF9789BA826686264131C369A407D676CFC8C2642F6AA3A969F
                        SHA-512:8884B07441339FF57919E778CE4D9E76D9593E1A04B75A8515D7DB36966A7CF32C72351EFA4214E29503BE58B1C6D3B4732E252579F6FC88C8025872A59CB7F2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10306" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsLinkFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4144" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4145" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <TR T="5" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="FileLocation" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="FileLocation" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="FileLocation" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1951
                        Entropy (8bit):4.0166006108695935
                        Encrypted:false
                        SSDEEP:
                        MD5:568B295502044CAB216A0140F4671F0B
                        SHA1:2B2ABDFD4A1C31E12A05583F8053CB2AD3654630
                        SHA-256:0166C7714E15E9DCAE500657EECE340B55C0A0A2F7F09C3B723FAAE105C43ED3
                        SHA-512:A400B5E4BEF941263EFBE36F777A425F162B33AC0B9BAEE71C8A8881326827634E4CB4C633A1D22C6C57CD99D713B4618EC6AD10A78B788E6147EB151968E23E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10307" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <Etw T="1" E="4146" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4147" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="4148" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="2" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="3" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="NE">.. <L>.. <S T="4" F="ResponseCo
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1692
                        Entropy (8bit):4.410837786064996
                        Encrypted:false
                        SSDEEP:
                        MD5:B426227189D12E78E9BC8688C73CA417
                        SHA1:4029C9D4F16EE6008BF6EC79CFE5ABB01D3ED4CB
                        SHA-256:C81F0F8AE2C92338B3200002709377CFA2A028B458ADB9FB0793C8FEEF44FC7C
                        SHA-512:21844AA8E8D00B5D6D2AE46D2FBA9C82A6AE2CFE5F7BC0311C469D579C0BDCA0C661DE43787C56685F5B4A4BEFE29D160B48CAFFB02451213D82A8F3A28D8230
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10308" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentsError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10307" />.. <Etw T="2" E="4132" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="3" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1057
                        Entropy (8bit):4.776770703320076
                        Encrypted:false
                        SSDEEP:
                        MD5:E6ECDEF4B9AA10D5E6239FF91096ED58
                        SHA1:468D38112BF42E731C5050593514AB1117487763
                        SHA-256:09C0B070310E178C60D9442FE06BF4D34D27DCED8D8ECDA809F6AAC0CD3F30D8
                        SHA-512:832D6BF937F3940793FC111185E0F63CE783AF7BEC362ED469615E5AEDF5BD85AD92A2F1F11E06C7BEA9BC7F3990CA8DCAEBA0E48C6D3124D71DC759CB0157F2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10310" V="1" DC="SM" EN="Office.Outlook.Desktop.CalendarEnagagedUser" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="132" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="SameAsPrimaryTZ" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsEqualStartEndTZ" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_usertems_NonPrimaryTZ">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_usertems_DifferentStartEndTZ">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1020
                        Entropy (8bit):4.835904842706168
                        Encrypted:false
                        SSDEEP:
                        MD5:ECAFFC6CA0D5620D25639F12BD5D2523
                        SHA1:9F4B6FD72F5CD99F692472161623E3F97C1BB20A
                        SHA-256:003D362AEB26174E022A3A30E176AB2E0CFFFADA74679B8E2D76323ECAB8D995
                        SHA-512:4DA3AF3E9D518CB6B0E5395FF8E172C835E8E43F11B847573E1BC1C585C1D054E1A06D21EEF78B72821626853598AA8A240914B95F045FEB7A8BAD3ADC8A25F2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10317" V="2" DC="SM ESM" EN="Office.Outlook.Desktop.OAB.DownloadResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10111" />.. <R T="2" R="10338" />.. </S>.. <G>.. <S T="1">.. <F N="12" />.. </S>.. <S T="2">.. <F N="3" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="FullOABResult">.. <S T="2" F="1" />.. </C>.. <C T="U32" I="2" O="falseNoError" N="DiffOABResult">.. <S T="2" F="2" />.. </C>.. <C T="G" I="3" O="false" N="AccountGUID">.. <S T="2" F="3" />.. </C>.. <C T="W" I="4" O="true" N="ServerName">.. <S T="1" F="2" />.. </C>.. <C T="W" I="5" O="true" N="Puid">.. <S T="1" F="10" />.. </C>.. <C T="W" I="6" O="true" N="OMSTenantId">.. <S T="1" F="11" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="2"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):846
                        Entropy (8bit):5.058297363259834
                        Encrypted:false
                        SSDEEP:
                        MD5:80B9712FCDF940C3B17367A00FB380D2
                        SHA1:60F386A103ACE51771A555F569EEF73F6A1B0126
                        SHA-256:DF5C04ED948522B8AEAFACA5D861AA7C1CF67E08D38B034553E66DDA07BAA56E
                        SHA-512:152A80E899CE8F1D7B70F98D296FA50F6B2BCDAF2BAB893EAA050A8298CBD21DCEC30C95E77A9DD98EC17D95853FBD04B254CE113A8A2552245BA8D88D549E8D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10319" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsGalleryFileSourceAndType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4111" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. </S>.. <G>.. <S T="1">.. <F N="FileLocation" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="FileLocation">.. <S T="1" F="FileLocation" />.. </C>.. <C T="U16" I="2" O="false" N="FileLocationCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1612
                        Entropy (8bit):4.790072563931327
                        Encrypted:false
                        SSDEEP:
                        MD5:19A228C0B216C18FCE94777A4C0155AC
                        SHA1:1832F292767B908E28B9BC1E547F5D7FE61E8CE0
                        SHA-256:3F536CCA6FBAB50FF68ACDE0A44CD8D0138C115D415B7FFC57900E736D5E2A14
                        SHA-512:5C2051B6E30EA1E99AC05F3F73BCECB2DBE2D1EC96E57A23AA7417FE99F96A3A9A52277032B828EA35397DE5FC369F84DD4E266A035E251D8A92F194982E8A70
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10320" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentsGalleryAttachmentCountAndCloudAttachmentType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4143" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4186" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="4163" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4308" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="5" I="Daily" />.. <A T="6" E="TelemetryShutdown" />.. <TR T="7" />.. <F T="8">.. <O T="EQ">.. <L>.. <S T="2" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="3" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):965
                        Entropy (8bit):4.596710489364331
                        Encrypted:false
                        SSDEEP:
                        MD5:119F7019DE57AC52FD4EF078AF76B981
                        SHA1:80F0B3FCC4F47726ECAB778645EC8B1AC46AE85D
                        SHA-256:EB816A6DC9E86FA6CF2511E59261F60E56D30DB06C86400D5BEE377EB1D7F393
                        SHA-512:22BED7A6726631D9EA0E832A1645A79C3F6746B771FB5B93C1E3DA246AC74DDE4131C8BC5D4083D179B35C3E66EC149093F0796754BC136C974A14CA64C8F43B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10338" V="2" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="26113" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="1101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="FunctionName" />.. </L>.. <R>.. <V V="DownloadFullOAB" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FunctionName" />.. </L>.. <R>.. <V V="DownloadDiffOAB" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true">.. <S T="3" F="Result" />.. </C>.. <C T="U32" I="2" O="falseNoError">.. <S T="4" F="Result" />.. </C>.. <C T="G" I="3" O="false">.. <S T="2" F="Exchange Id" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1007
                        Entropy (8bit):4.751915504162806
                        Encrypted:false
                        SSDEEP:
                        MD5:63C3312C3BB712E4F132585D26AD6AFB
                        SHA1:CC9899D603EC7D2534DA31F06A20A8518CF1D12F
                        SHA-256:F691DBE61E8B01A9A2BA12EC741412A880E0B229B89DEA5E4138592A8F010D2A
                        SHA-512:4E12923CA6A2362C4836FA6DE891E1A1960BCD4CBDEB390877BFF1B69D07F54EBF5CD91608242433FEB3038CFACB4671390DA6B8970413ABF2B7408F9B7FA4C9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10343" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentsCloudOfflineView" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4160" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ViewMethod" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ViewMethod" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="OfflineAccessOpenAttempts">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="OfflineAccessPreviewAttempts">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2001
                        Entropy (8bit):5.040434132189173
                        Encrypted:false
                        SSDEEP:
                        MD5:051C39D1DBF4E1C18E963DFD39EA91C6
                        SHA1:43CBFAA77DBE2C232C8248FADAB2AA275FA76333
                        SHA-256:F97BE884E2C633C67676C1B42BF88D8335D1C19E01EFCBDE34D30B5048F4245D
                        SHA-512:4BAFA16933A6B610E55477A0D229E27A1593A4C7E12E3BAEF3BDF8E63D2BE5BB8D7FFBDA33A48F310A74AD217A23C9BE9BAB49F7117368315A4B7FAA8AE21D24
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10352" V="3" DC="SM" EN="Office.Outlook.Desktop.Groups.ExchangeGroupsTableCountsRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="3522" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="F" I="0" O="false" N="AVG_NumberOfGroupRows">.. <A T="AVG">.. <S T="3" F="NumberOfGroupRows" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="MAX_NumberOfGroupRows">.. <A T="MAX">.. <S T="3" F="NumberOfGroupRows" />.. </A>.. </C>.. <C T="F" I="2" O="false" N="AVG_NumberOfMailGroups">.. <A T="AVG">.. <S T="3" F="NumberOfMailGroups" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="MAX_NumberOfMailGroups">.. <A T="MAX">.. <S T="3" F="NumberOfMailGroups" />.. </A>.. </C>.. <C T="F" I="4" O="false" N="AVG_NumberOfPinnedMailGroups">.. <A T="AVG">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2636
                        Entropy (8bit):4.740554163112672
                        Encrypted:false
                        SSDEEP:
                        MD5:354AA6C0869013B60B8FC284B9E2FAC5
                        SHA1:732E14FA7A931EDB1E626AC5E63A339AC9E3B78A
                        SHA-256:CB79E32FE0BF855FA5787ADB8C36CCA6BD9E2BA993204C53DCE4E6B4D51151B9
                        SHA-512:914F49CC4880BF188102262B9CD1E7340049C136B61FEAAE1C9955332504F73F27259E18C48F1F1027832024821187C78BC2728554D8B4697FBD0093DEDB986B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10363" V="4" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupNavigationCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="3500" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="3522" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="Folder" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="Folder" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="Folder" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):954
                        Entropy (8bit):5.2182894470657
                        Encrypted:false
                        SSDEEP:
                        MD5:E537BFF05B9F0D86A0AE808DD3811C0C
                        SHA1:86562CBB8C02656F3BCB67E5D741CA6365FABB70
                        SHA-256:669BA9FFB8E4EC3E0F470D69370EB2F3369BFFD9C5714A00012581601D4DCFF4
                        SHA-512:88BC4CF078F18035C10AC53C9AAEF9B2DF52C479562FBF67ABA2F4A8D5A23AB33CECFCD17E2DAD22D03D337BDE4360DC5812FF4D5D51B6D97A11CFC48F3D3E7B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10364" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MeSpaceHeaderUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="FT" I="0" O="false" N="RuleTriggerTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="Count_MeSpaceHeaderDisplays">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_GoToGroupClicks">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="Count_MultipleGroupsDropdownClicks">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3869
                        Entropy (8bit):4.5287237329748296
                        Encrypted:false
                        SSDEEP:
                        MD5:E1C8037CB1E444B13E827AD922E5B584
                        SHA1:E4E861B9E6EEA073F39B3D80806E79F996E5DFE7
                        SHA-256:80C409B75717887D61DC1F9D05D8EF52B4F9B8D90A6075BBDEFF4511BE5C7BA6
                        SHA-512:A1AA6272BF8D47567590C53625502383481F27BB576E84CEA396648CDAD8C579D9BFB7FDBA6578BC3B6D1C62D46B51ADDD3FDFB7741AF0BAF7337282DC00DFBD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10365" V="3" DC="SM" EN="Office.Outlook.Desktop.Groups.WeSpaceHeaderUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="18007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Daily" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="EntryPoint" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="7" F="MembershipChangeAction" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):10371
                        Entropy (8bit):3.920664955688752
                        Encrypted:false
                        SSDEEP:
                        MD5:0347AB70CEB86B906FF331114D6F79C3
                        SHA1:56BC43FBD5095C53300B10FA217D562AC15E22BB
                        SHA-256:8A5D4DF964693243A093F91F551F5B7158170AF3F5410F6FB6A6D372E90783C0
                        SHA-512:B1864445196E6609F1D73610EEC97D72D0F4C16C5CF85AE4B240443E64E30110B9CD5F8435608F5D4DE3EDB4040B8CB8901B076DF9CCF92A4C5248C3274641B5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10368" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupCard" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <TR T="3" />.. <Etw T="4" E="89" G="{8736922d-e8b2-47eb-8564-23e77e728cf3}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="dwActionType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="dwActionType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="dwActionType" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="4" F="dwActionType" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1704
                        Entropy (8bit):4.850564138240475
                        Encrypted:false
                        SSDEEP:
                        MD5:3549DFAC2FD409B626AA95205A6C2A5B
                        SHA1:509612DB2C802B3376EA607A25F555A4654AC8B9
                        SHA-256:1657C8FD2490B852EE8D544FD903F899E9C15DC6EF2C5B1319813A9EEC0B9636
                        SHA-512:FD6EA9122F4F450E697C050A385256301CECD3FE9B086F862EDCD9579433D2DCED17FA467285EB9156F20E596E8D9BF60786A6E9F0CBD06D41292BBBE0B555A9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10369" V="1" DC="SM ESM" EN="Office.Outlook.Desktop.MapiHttpSlowServerReqRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4119" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <R T="2" R="10111" />.. <TO T="3" I="5min">.. <S T="1" />.. </TO>.. </S>.. <G>.. <S T="1">.. <F N="ConnID" />.. </S>.. <S T="2">.. <F N="1" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="EventDateTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ConnID">.. <S T="1" F="ConnID" />.. </C>.. <C T="U32" I="2" O="false" N="RequestID">.. <S T="1" F="RequestID" />.. </C>.. <C T="W" I="3" O="false" N="BEServer">.. <S T="1" F="BEServer" />.. </C>.. <C T="W" I="4" O="false" N="FEServer">.. <S T="1" F="FEServer" />.. </C>.. <C T="U32" I="5" O="false" N="RequestMethod">.. <S T="1" F="RequestMe
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):866
                        Entropy (8bit):5.111528189017966
                        Encrypted:false
                        SSDEEP:
                        MD5:B356B7B999903B9F0DB25DC5513A1149
                        SHA1:1E345ECE6FF09AB8D9C2F6A8F0F9FCC95E3D31B2
                        SHA-256:7A68D2A7BA51A702B890F8969E3A5B98CD8B8B282131C64A90BF6AB0E5BE6C8A
                        SHA-512:96CF80E2018FAB92D8F308538E7614D8C6CC82B71605205494F05AD1E375B0B00C8F9718FF92263C87BCEA7CEBD65E199BD6E42C800400AAEBC4F8F26684910F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10370" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EWSBrokerNotificationsRecieved" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="306" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. </S>.. <G>.. <S T="1">.. <F N="ChannelEventsType" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="RuleTriggerTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="NotificationType">.. <S T="1" F="ChannelEventsType" />.. </C>.. <C T="U32" I="2" O="false" N="NotificationTypeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1698
                        Entropy (8bit):4.281086973374979
                        Encrypted:false
                        SSDEEP:
                        MD5:82B2DBE1DDC035DDB56220073CA83414
                        SHA1:6A2E313BDEB3A9E5BDB491CB8CD9DAA28A99EABE
                        SHA-256:6E998197E5B3DABBCDB7A79B497982EA5BB2FED53A020BCBBD4CEA40ECFF023F
                        SHA-512:914CB4F61074B8437730BFB13BCBC45CB0C178BEECC86E6B2CB87FEC3EA41D13FC80F2008F43450ECC7CD357734AD51DA953091D2BCF95B476F450E7EA8BB39B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10373" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsWebRefMessgeRate" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4151" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Unread" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="5" F="WebRefAttached" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="PhysicalAttached" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="4"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):772
                        Entropy (8bit):5.1329924350057565
                        Encrypted:false
                        SSDEEP:
                        MD5:6A00E5D9BF6B77093A0CFC5FD001C087
                        SHA1:20193D802D37574455355AAC0C85049341237AC9
                        SHA-256:C9B7D8ED5DE8A2EF4868D2C37852169E7DC020269A39CCC7191A82B9561187E9
                        SHA-512:F53D26794C4F77D51EF0B66580A3EC79645490BDA2741DAA5ED34B92A7BB61062AC0DFC4E4A9CFCE778B299A908C9E2916216EF2BE2FD3E4629069CB260D0A4E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10385" V="1" DC="SM" EN="Office.Outlook.Desktop.FASTSearchError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7049" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="G" I="1" O="false" N="RIPCorrelationGUID">.. <S T="1" F="RIP Correlation GUID" />.. </C>.. <C T="W" I="2" O="false" N="Event">.. <S T="1" F="FastEvent" />.. </C>.. <C T="U32" I="3" O="false" N="Error">.. <S T="1" F="ErrorType" />.. </C>.. <C T="W" I="4" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1529
                        Entropy (8bit):5.107006439307173
                        Encrypted:false
                        SSDEEP:
                        MD5:8B18849FE0AA897BD471692A2482124D
                        SHA1:0E777924A52A4316592190CB7D13C30B7A9949FC
                        SHA-256:65442C55F1619BF670F4F97DFC447630A0DA602998538F9D1EF425CAD142A93A
                        SHA-512:79090CDFDCA17B7F3297C9A69ABE8388E3B297E56F48F1A9F431BD598FD5AC8209E42A60FF77E6D099FBA40F9710F185CD9BA6D32CD1044A349509F6426D01D0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10388" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupsRibbonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="19002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="19003" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="19004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="6" I="Daily" />.. <A T="7" E="TelemetryShutdown" />.. <TR T="8" />.. </S>.. <C T="FT" I="0" O="false" N="RuleTriggerTime">.. <S T="8" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="Count_GroupRibbonNewGroupConversationClicked">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_GroupRibbonGroupInboxClicked">.. <C>.. <S T="2" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2587
                        Entropy (8bit):4.3333666742679595
                        Encrypted:false
                        SSDEEP:
                        MD5:7D773F13CA109AAF627A1108B08F9C41
                        SHA1:B90AFB0EE8D36F50C9B852DD93FBE6753678E8E6
                        SHA-256:29A671874FC7F6E713D447D12574E73CDC733739FC61E798BA0DF6533A97BA04
                        SHA-512:465E0B8D9417052FB8DCD9DE599A1A3FC02C7F39BA19EB272CBA1B295FE63AD048A70CA84F72707069CCF595860AF08ADFB7869ADDD2D944DC91C2F19F10DE52
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10389" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupDeepSyncPerSession" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="250" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <Etw T="2" E="184" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <Etw T="3" E="247" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <Etw T="4" E="238" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <Etw T="5" E="239" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="4" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1572
                        Entropy (8bit):4.927166304300959
                        Encrypted:false
                        SSDEEP:
                        MD5:680AB635B01C72997CA075EA63044379
                        SHA1:FC1B3281258D30E658D56D5AB7F1D108C3C977C3
                        SHA-256:30FF74EA4D63A8610FF1FECCA5E20F7D6ECB26B348889075CDBD9A6C09B72328
                        SHA-512:7E332EB1FE5016F972200D5567E21AFAB8DA2B9345FE1A1BEB348E6E005BB24192B3C816CD3722BCAB0D6E223B76D3100E19714AC78A6B4C3DAC31A06654B785
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10392" V="0" DC="SM" EN="Office.Outlook.Desktop.MailEngagedUser" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="19007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="19008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="19009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="19010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="7" E="TelemetryShutdown" />.. <TI T="8" I="Daily" />.. <TR T="9" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="9" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SendMail">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="ReadMail">.. <C>.. <S T="2" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1917
                        Entropy (8bit):4.84278517503294
                        Encrypted:false
                        SSDEEP:
                        MD5:1DD2FFF6ACED93C6D24145AD026B3888
                        SHA1:54F565AE00F4D4D2D94433D2546BF471492F3C58
                        SHA-256:16B502D4233772464995E53C79B8A03DD094C3EC4457C7F98DB9AEC2853CE670
                        SHA-512:2C737B1FA157890329302BAFF86FAA7485C32E4DA21AF33CF4F4375A2CD8DB0B4CF775E2ADCCDF991CEC84DE2E33AB9C3C1FCEEE8DCA920DDF32031C8B05C2FB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10395" V="3" DC="SM" EN="Office.Outlook.Desktop.MCRP.CountOfConversationMessageResponse" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Hourly" />.. <TR T="3" />.. <Etw T="4" E="20000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20003" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="20012" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="9">.. <O T="EQ">.. <L>.. <S T="4" F="ResponseType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="10">.. <O T="EQ">.. <L>.. <S T="4" F="ResponseType" />.. </L>.. <R>.. <V V=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1719
                        Entropy (8bit):4.838099064213476
                        Encrypted:false
                        SSDEEP:
                        MD5:7FBF62B2A8E65D32628604384B984BC1
                        SHA1:39721095776FF67A39D4215374FF8F47FEF029A8
                        SHA-256:370EB2F6995B15689757291945D8FFC6825C27BB5B2A1904C2ED6139930ABD46
                        SHA-512:76DDA9EA7AF939BC896F7D2B10B308FF5DEEC470F57ACE8558A6D0C9E8AE2CFAF96725AD27A6BA6764C734C642C76F8FFBD5ACFD2ABF6A50E0A1F605AAFD1ED6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10396" V="0" DC="SM" EN="Office.Outlook.Desktop.AverageWindowlessHitTestingPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="308" G="{bb00e856-a12f-4ab7-b2c8-4e80caea5b07}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="LE">.. <L>.. <S T="1" F="MsForHitTesting" />.. </L>.. <R>.. <V V="2000" T="U16" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GT">.. <L>.. <S T="1" F="MsForHitTesting" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U16" I="1" O="false" N="CountOfTimesPerfEventTriggered">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="F" I="2" O="fal
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):828
                        Entropy (8bit):4.702566865434047
                        Encrypted:false
                        SSDEEP:
                        MD5:3049188BA876B1D41520D29378AF77D1
                        SHA1:0CFD51219B413B1169BB82B4AAD1E3542A8A14FC
                        SHA-256:3DA46F3B6AD17015C43169A549ED1E4246FDC89DBF39589D844D2C288A2EADB7
                        SHA-512:26FF3002754994A268A9744087789C4A66D34509DF6E104A805B76D57C7727648F219BC60C9881F787FB6FE134E49FD6F31C5A13E57ACEE943814D2BD00A1422
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10397" V="2" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="20004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="ConversationIdW" />.. <F N="ThreadIdW" />.. </S>.. <S T="2">.. <F N="ConversationIdW" />.. <F N="ThreadIdW" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="B" I="1" O="false">.. <S T="2" F="GroupsStore" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.719717933369507
                        Encrypted:false
                        SSDEEP:
                        MD5:07568689EC71D880AAF6CDE74BC3DD1F
                        SHA1:461B4D29352B6724161A46D537694B001591C43D
                        SHA-256:80ADBB837402D27A137C459E0D114B5D3AFEF2DF9224B046D5BCDB14310D7C1B
                        SHA-512:3317B2349922981FE49E8BD9FAC2DBB3F81E9E45CDD2FD93C97418654CDC8DC7C200A6763F84C0EC22CE34ED371DC72354407DE833BB0342C9BB4ED529E7E26E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10398" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="20010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20011" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.724509232403731
                        Encrypted:false
                        SSDEEP:
                        MD5:74263D48A24224CCD4A5D93C02C54600
                        SHA1:988C57D6B11784356F83C5417F5AC8845D709BD1
                        SHA-256:F86B04258CC6BCBD80C388C92C42CA093B7E82626E7065C5955D9644BE369B5C
                        SHA-512:5787554EB002EF4EE23F828295FC6FFD42B11384B4C4899371497B727EBF5EB2A9457F2B7C674B1E55FFD0E396030CFCC8901AD0EB2A1AE86A38551626AE8AA4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10399" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="20008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.7156529279413135
                        Encrypted:false
                        SSDEEP:
                        MD5:6658A0E4C489B90A96A5AFA430C61B84
                        SHA1:40381EB7BC69466E670F1948251B3D0FFD8EEBB7
                        SHA-256:553C67CA3371AD3D405F70081DA93EB039DF04FE1EE978759C57682873CCEE84
                        SHA-512:32B530E2D20AA484094E624CC25CED13CF5D92D87B869836C72028FAB7981E2D5B9707B0CA304DE6CB1A1AD5E42A2C46B71BB700CFF3B9538DD6E256D8F09C41
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10400" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="20006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5424
                        Entropy (8bit):4.454131699966936
                        Encrypted:false
                        SSDEEP:
                        MD5:32A4B18F60ED325E7E289B9D281CBE7F
                        SHA1:01B659A715F578815DAFABD18D6860AF956AEB06
                        SHA-256:DBC85A517AA9AE5DFEE45490012ED5E58639511AA036C2F0E2F77BE603D7A372
                        SHA-512:9931F6BF46BC03531FD4444E98468513A3A4E4F73F5F73F7E919A42018653537F6EA91BC2C1E483972AABAA49493D904CAA84184510492D5F248A5C8ACF91680
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10401" V="5" DC="SM" EN="Office.Outlook.Desktop.AvgPerfTimeToFullyLoadModernReadingPaneConversation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10397" />.. <R T="2" R="10398" />.. <R T="3" R="10399" />.. <R T="4" R="10400" />.. <R T="5" R="10737" />.. <Etw T="6" E="20015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="20017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="9" I="Hourly" />.. <A T="10" E="TelemetryShutdown" />.. <TR T="11" />.. <F T="12">.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </F>.. <F T="13">.. <O T="EQ">.. <L>.. <S T="12" F="1" />.. </L>.. <R>.. <V V="false" T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1106
                        Entropy (8bit):4.589847035817531
                        Encrypted:false
                        SSDEEP:
                        MD5:0AC4EA91FB53502B382EB118A5D264B1
                        SHA1:567A91EE4C7FD45B4903E9550634461D347371BB
                        SHA-256:12A5D98930BDA8E77C341BCE796CAD843E647FD1DEBE3917FF165A8F719546B1
                        SHA-512:12087F5B53BE822ED33A53E28C3EA8D5EB708AC0E7B538E6FB4AC01840719747212F1DA5CF3EDAF97BCC5FB0BE6542BAA1EB2C6E956577F2CE15CA45E01959A1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10408" V="1" DC="SM OII" T="Subrule" DCa="SS" xmlns="">.. <S>.. <Etw T="1" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7045" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <R T="3" R="10713" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="CallerKeyword" />.. </L>.. <R>.. <V V="MapiHttp" T="W" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="ClientRequestId" />.. </S>.. <S T="2">.. <F N="ClientRequestId" />.. </S>.. <S T="3">.. <F N="2" />.. </S>.. </G>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="4" F="ConnID" />.. </C>.. <C T="W" I="2" O="false">.. <S T="2" F="X-FEServer" />.. </C>.. <C T="W" I="3" O="false">.. <S T="2" F="X-BEServer" />.. </C>.. <C T="W" I="4" O="false">.. <S T="2" F="ClientRequestId" />.. </C>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5523
                        Entropy (8bit):4.572278986318944
                        Encrypted:false
                        SSDEEP:
                        MD5:A2D535213E1F15192487A9B1A1268331
                        SHA1:7713BB5C03457E59C4F2DE1967B663B017C1518A
                        SHA-256:383A3C28E541759E9AB921FCD292BB00326FBDAB49DA3B1E1ABA89A55159C757
                        SHA-512:780F43CEBBED650FED84BC59A91012F5B07EC18830442BB271978FEF52D91898F9BDEB15D8225FFB456E1208F507503C21296A418D760FD19A7685A456488B7C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10421" V="6" DC="SM" EN="Office.Outlook.Desktop.FASTSearchEnd2End" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7110" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7023" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7029" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="4" E="7043" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="5" E="7045" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="6" E="7126" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="7" E="7057" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="8" E="7112" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="9" E="7044" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="10" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="11">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):802
                        Entropy (8bit):5.084311398512499
                        Encrypted:false
                        SSDEEP:
                        MD5:7EE502334135E6C50B16503A4CC1779C
                        SHA1:B678F680AAA3540BF4EC87DC14B89AD356ED668B
                        SHA-256:09643AAFAD7D620AFFE305E336399152BFE1F722F8EAAA2D412BEBFF9A9F90F2
                        SHA-512:FFED226FB2EC9849F0955394DBC8A5951A459B67786E00EA0A1B87CC0D05722070F9401629A169A58832B12284C6EEAFA2F1B0F959C77B649B57ACDB5DF62237
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10435" V="1" DC="SM" EN="Office.Outlook.Desktop.AddToMyCalendarCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="500" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ItemType" />.. <F N="OperationType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountOfAddToMyCalendar">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ItemType">.. <S T="1" F="ItemType" />.. </C>.. <C T="U32" I="2" O="false" N="ATMCEntryPoint">.. <S T="1" F="OperationType" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1176
                        Entropy (8bit):4.802613324723994
                        Encrypted:false
                        SSDEEP:
                        MD5:A514D7DA125CC94A1F68967B3FF9CC36
                        SHA1:D5DB4735C4D590475BDBC03679FC2FBA91CEB841
                        SHA-256:37FB14509B9E3952FF4A635822038A14881DE0E8531CDAA9D68A4F57E1B49271
                        SHA-512:98698BC8356C6F4312012DD9D9DD2E79B3D2CEB7ADE68D529525B51A1FD6D76A47455AA92E321E2EC9BD83D60D960F6AD983248E85D4B2C5464E7284EB9A9DB4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10438" V="1" DC="SM" EN="Office.Outlook.Desktop.Rule10438.Olk.WebExt.GetMoreApps.Button.Usage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="8204" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="Location" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="Location" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="MOEBarLocationClicks_Count">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):679
                        Entropy (8bit):5.155622855129688
                        Encrypted:false
                        SSDEEP:
                        MD5:2786A544815A2DCE69BA7A19356658C0
                        SHA1:EE75B6416DCB05D3C15AAE5EFF5C98AFAB4C2ED8
                        SHA-256:739F8A0B46E97B614B2866A6418DA0A53439962210527BFA00AE0CEB1524BFB7
                        SHA-512:032B63F53CA9E08CD8D554AE8B39F2F4465047F8361C260ABBD33A16BDE22A4754A37F1F5DE395C781EE29E9D24566BA443416E7F3C96A639D5E7C45B0D7084E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10447" V="2" DC="SM" EN="Office.Outlook.Desktop.ExchangeTracerouteCollection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="2000" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="132" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. </S>.. <C T="U32" I="0" O="false" N="RunID">.. <S T="1" F="RunID" />.. </C>.. <C T="W" I="1" O="false" N="Endpoint">.. <S T="1" F="EndpointUsed" />.. </C>.. <C T="W" I="2" O="false" N="HopsInfo">.. <S T="1" F="HopsInfo" />.. </C>.. <C T="W" I="3" O="false" N="TenantID">.. <S T="1" F="TenantID" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):5.154405423977513
                        Encrypted:false
                        SSDEEP:
                        MD5:3A5816D4D882C7A612FEEB9020957FED
                        SHA1:ECC8970108BDD6F1954D4A4914343FCCA7B93A28
                        SHA-256:8F81FADCA603956112CEC0AF0C4E4812E15B8AAFA41D961DD33E432297B163B3
                        SHA-512:8423080F71C1979FCE74DADE837788E95A51003EB77BFBFAAD8D6CC3C631E317662C262A025480139FDF4C7BD75BB3A82F9CD1ED0CCCA81A5CF1990AA87C3D40
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10448" V="0" DC="SM" EN="Office.Outlook.Desktop.ExchangeTracerouteErrorInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="120" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ThreadId">.. <S T="1" F="ThreadId" />.. </C>.. <C T="U32" I="2" O="false" N="RunID">.. <S T="1" F="RunID" />.. </C>.. <C T="U32" I="3" O="false" N="ErrorCode">.. <S T="1" F="ErrorCode" />.. </C>.. <C T="W" I="4" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):680
                        Entropy (8bit):5.219244730672968
                        Encrypted:false
                        SSDEEP:
                        MD5:15458526173C4F4E9422F2FAF412083F
                        SHA1:25A963F1278E7DC45DEAA8D46979237A963C927F
                        SHA-256:74E71DD4BC379E86C4F978D722D4FD36D80603D1DCB90FEF4250E75A4A82CB78
                        SHA-512:3C8D38A6632F021F749FF1BA3EF42F789FC5195216A92562877BEE1CAD7939F6C48B521052B3EE7E0DCA3BD0334DCFE1C7E6096CAD8477BE41EBDEEED1FFB28D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10449" V="0" DC="SM" EN="Office.Outlook.Desktop.ExchangeTracerouteServiceEndpointCopyError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="121" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ThreadId">.. <S T="1" F="ThreadId" />.. </C>.. <C T="I32" I="2" O="false" N="ErrorCode">.. <S T="1" F="ErrorCode" />.. </C>.. <C T="W" I="3" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1053
                        Entropy (8bit):5.065099138149148
                        Encrypted:false
                        SSDEEP:
                        MD5:B0C15D905CF6BB86A791D25D695D5034
                        SHA1:5A8CD74F5879E46F852047535998230A6DD9C77F
                        SHA-256:30D89B15725CEF2D6CFF1C1DE721F454C5485EC3600EE6E9E0A6CD52D940F143
                        SHA-512:B62EBE2F4879268985B56D6CEC6DDACC9159E89A5B1783A199B6E9BFFFF7F80C0F2C11936DA79B7BBD898B08ACF7598D735EF12957D6C2FA0F9AEF0A30F6C09F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10450" V="3" DC="SM" EN="Office.Outlook.Desktop.NDBCorruptStoreRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="319" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="U32" I="2" O="false" N="NdbType">.. <S T="1" F="NdbType" />.. </C>.. <C T="U32" I="3" O="false" N="Version">.. <S T="1" F="Version" />.. </C>.. <C T="W" I="4" O="false" N="ProcessName">.. <S T="1" F="ProcessName" />.. </C>.. <C T="W" I="5" O="false" N="PstVersion">.. <S T="1" F="PstVersion" />.. </C>.. <C T="W" I="6" O="false" N="Details">.. <S T="1" F="Details" />.. </C>.. <C T="U32" I="7" O="true" N="CreatedWithVersion">.. <S T="1" F="CreatedWithVersion" M="Ignor
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):733
                        Entropy (8bit):5.182276486360153
                        Encrypted:false
                        SSDEEP:
                        MD5:505CE0D0BA4F54EFA6B858DEACD5B9E4
                        SHA1:A502DB5D5378133CEC1C3C1C345664DE1774D741
                        SHA-256:747BB1B075E15C184B604921966413FA32E36673AA6460495A6CC741911A9D59
                        SHA-512:0C9DC603F9BF64F6462D492C1D310F3A33DAD56AF7B106BF406437EE91528628AE0EA1643F36EA52633117DF340D4771F12A5C947C786248586CBB4F32AE4CB6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10461" V="0" DC="SM" EN="Office.Outlook.Desktop.EAS.XO1.UpdateFolderServerID" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="141" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="2" E="161" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. </S>.. <C T="FT" I="0" O="false" N="StartTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="OldServerID">.. <S T="2" F="OldFolderServerID" />.. </C>.. <C T="W" I="2" O="false" N="NewServerID">.. <S T="2" F="NewFolderServerID" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3496
                        Entropy (8bit):5.135570537564772
                        Encrypted:false
                        SSDEEP:
                        MD5:B118ED7ECA4AF7FD25E50DD172C5E199
                        SHA1:601B4421DDF61814316EC90AF2E6FD994D96ABF3
                        SHA-256:3C8569990611B6992DE138773DD8D474AC1D3ECB99AF4439B2B096CDF0C7F40C
                        SHA-512:FBCC482293E28A7EDF70A3C23E5A1C03FD546CADE319A2EDF0268415B3AA7B59877AE52BB94A03B09E5BB2C58A2A7B5E1D78D58D69300FE6FACAEB75FED12641
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10462" V="0" DC="SM" EN="Office.Outlook.Desktop.EAS.XO1.SyncZero.ExtraDataTypes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="141" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="2" E="143" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="3" E="142" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="4" E="144" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="5" E="146" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="6" E="148" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="7" E="149" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="8" E="154" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="9" E="155" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="10" E="160" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="11" E="167" G="{265f23e0-615d-4082-8e17-ddc
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4246
                        Entropy (8bit):4.9805073251829555
                        Encrypted:false
                        SSDEEP:
                        MD5:C5AD3DF8A2E8519121EA19F713461B85
                        SHA1:EC25450FF9278F996FC3E81DF44315C518899955
                        SHA-256:7F83FEAC2C0D93B4446D2CA5ACCE380580EC0064F75C4A6D788EB13581F0931D
                        SHA-512:4DA7F276C951B7B3327166337DBAB5200B2E3E580A342CA9A9ADCC0FCFDB1C81A3C5CEDC8CAD67521262284D922B5FC863DD52F9FA7AF2980962DC5013C11B85
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10463" V="0" DC="SM" EN="Office.Outlook.Desktop.EAS.SyncZero.X01" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="141" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="2" E="142" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="3" E="143" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="4" E="145" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="5" E="147" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="6" E="148" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="7" E="149" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="8" E="150" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="9" E="151" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="10" E="152" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="11" E="153" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2346
                        Entropy (8bit):4.373305629217386
                        Encrypted:false
                        SSDEEP:
                        MD5:A2BB0B06EF07CF7152500CB92D52FAA2
                        SHA1:D9CD4520349784DA744B6A8299514AE2D5A03F4B
                        SHA-256:93CC5982BAFA88A0D8CD7873BD1548E676E76CB76DEC1C4382E66B7D89625B70
                        SHA-512:46424F0D637F3377D20FFC82D32FDC35B0E89D49F9615E1AF5BE643A6E5525B1457D433C8B5367CD26FB9D54E2CED2791A13133CC7BDD5FF2A199FEBE3023DD2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10464" V="0" DC="SM" EN="Office.Outlook.Desktop.RopsBeforeGetBuffer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="283" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="78" T="U8" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="67" T="U8" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="68" T="U8" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="86" T="U8" />.. </R>.. </O>.. </F>.. <Etw
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1184
                        Entropy (8bit):4.8293089783105225
                        Encrypted:false
                        SSDEEP:
                        MD5:251278741B508681E537B8D7E4068BA4
                        SHA1:9DD04C3EB89E66E1EC3BB5EF7625ECF8F308BE00
                        SHA-256:63BB9B410498C5C232BBBEED111E8EC99FB4270475BDEA887DE469CE0426F4BB
                        SHA-512:62BAFF24E52CD3B5762812EF2905DE8B37F99D4DCB1E54B93AA8E1AAFD40D3C0525C04C21DC1C543E26A003CFF11757D3914C430C5D291A6B1EA15C0791B890A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10467" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7068" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7063" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <G>.. <S T="1">.. <F N="RIP Correlation GUID" />.. </S>.. <S T="2">.. <F N="RIP Correlation GUID" />.. </S>.. <S T="3">.. <F N="RIP Correlation GUID" />.. </S>.. </G>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="G" I="1" O="false">.. <S T="2" F="SearchSessionId" />.. </C>.. <C T="I32" I="2" O="false">.. <S T="2" F="ClientId" />.. </C>.. <C T="W" I="3" O="false">.. <S T="2" F="ClientVersion" />.. </C>.. <C T="G" I="4" O="true">.. <S T="2" F="MailboxId" />.. </C>.. <C T="W" I="5" O="false">.. <S T="2" F="ClientCulture" />.. </C>.. <C T="G" I="6" O="true">.. <S T="3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1548
                        Entropy (8bit):4.521025293937798
                        Encrypted:false
                        SSDEEP:
                        MD5:1C0A58F9E28F2A994FC07156B86C384F
                        SHA1:1D764C5342BD31C94860D244500D813D053EB82F
                        SHA-256:685107F285557A7214D7C87294AAEB45BB02D4C444DAF4959F2701A41F5E8677
                        SHA-512:D0BD0EC7A9776375D5A46BBC18B8B4595EB86C4C057A3DA3F5DCAF5381B5C94D384ED6E9C220D91C31862BCD06F64FB2AC712F8D55DFCA03273D55591CDFD7C8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10468" V="1" DC="SM" EN="Office.Outlook.Desktop.ServerSearchSessionStart" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10467" />.. <R T="2" R="10111" />.. <R T="3" R="10468" />.. </S>.. <G>.. <S T="1">.. <F N="7" />.. </S>.. <S T="2">.. <F N="12" />.. </S>.. <S T="3">.. <F N="8" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="0" />.. </C>.. <C T="G" I="1" O="true" N="SearchSessionId">.. <S T="1" F="1" />.. </C>.. <C T="I32" I="2" O="false" N="ClientId">.. <S T="1" F="2" />.. </C>.. <C T="W" I="3" O="false" N="Version">.. <S T="1" F="3" />.. </C>.. <C T="G" I="4" O="true" N="MailboxId">.. <S T="1" F="4" />.. </C>.. <C T="W" I="5" O="false" N="Culture">.. <S T="1" F="5" />.. </C>.. <C T="W" I="6" O="falseNoError" N="Puid">.. <O T="COALESCE">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1184
                        Entropy (8bit):4.830833085358591
                        Encrypted:false
                        SSDEEP:
                        MD5:5ED5C63B7DCD4B705EF7CD7A9F306B33
                        SHA1:B8743192929B64C4C1C5C998598656955F2DC484
                        SHA-256:3DCF03BA7D4F466435FF18345CDDAEC03DAE622B74C1358918F7FC291D1C7408
                        SHA-512:FB3F690129EE90D0881485AAFB70783FCEF39D54C9DF88AA58898525E9E66C065A13D074A80AEF3C527EA18A60295393B6B2CB06708B7027C851D72E25ACFC03
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10469" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7069" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7064" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <G>.. <S T="1">.. <F N="RIP Correlation GUID" />.. </S>.. <S T="2">.. <F N="RIP Correlation GUID" />.. </S>.. <S T="3">.. <F N="RIP Correlation GUID" />.. </S>.. </G>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="G" I="1" O="false">.. <S T="2" F="SearchSessionId" />.. </C>.. <C T="I32" I="2" O="false">.. <S T="2" F="ClientId" />.. </C>.. <C T="W" I="3" O="false">.. <S T="2" F="ClientVersion" />.. </C>.. <C T="G" I="4" O="true">.. <S T="2" F="MailboxId" />.. </C>.. <C T="W" I="5" O="false">.. <S T="2" F="ClientCulture" />.. </C>.. <C T="G" I="6" O="true">.. <S T="3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1546
                        Entropy (8bit):4.52065037497559
                        Encrypted:false
                        SSDEEP:
                        MD5:D354EFEA3ECB4B207BF737CC1796332D
                        SHA1:BE0708908B8B4B03A2A6999273176F7633655DCC
                        SHA-256:FA6440413A287EA8984DD703A59B296F178E33CAB8987F4B385278DA80213D99
                        SHA-512:0E9CBB70B102EA8D30F8A85E0F2AD5D83FDD6DBCB3DBD29CB805A09732365FA3BC0DE532940043DF2082BC9CD24BB9D1734A27B4A0124C04A34AE3418F41BC9A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10470" V="1" DC="SM" EN="Office.Outlook.Desktop.ServerSearchSessionEnd" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10469" />.. <R T="2" R="10111" />.. <R T="3" R="10470" />.. </S>.. <G>.. <S T="1">.. <F N="7" />.. </S>.. <S T="2">.. <F N="12" />.. </S>.. <S T="3">.. <F N="8" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="0" />.. </C>.. <C T="G" I="1" O="true" N="SearchSessionId">.. <S T="1" F="1" />.. </C>.. <C T="I32" I="2" O="false" N="ClientId">.. <S T="1" F="2" />.. </C>.. <C T="W" I="3" O="false" N="Version">.. <S T="1" F="3" />.. </C>.. <C T="G" I="4" O="true" N="MailboxId">.. <S T="1" F="4" />.. </C>.. <C T="W" I="5" O="false" N="Culture">.. <S T="1" F="5" />.. </C>.. <C T="W" I="6" O="falseNoError" N="Puid">.. <O T="COALESCE">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1021
                        Entropy (8bit):4.945103748344296
                        Encrypted:false
                        SSDEEP:
                        MD5:F79C1FD29DFF21D60AABB5956EEC720E
                        SHA1:9E8CFE23575F8404B24C2CF5F8CCA7F52BD469A9
                        SHA-256:4B21BD470965A8A2153DC6D52BDE55C314251E8D33CC52DB2179C125850FA389
                        SHA-512:D388317F69C36483CDAB2C6A5C527D7658655305B5DA8798F9717296CA4ABEF012C499354EA684E41A2E1FA373EE908F032991B0B3329A5B8911E73E14AF787B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10478" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageSubmissionTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="5002" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="5003" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="MessageID" />.. </S>.. <S T="2">.. <F N="MessageID" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="MessageSizeInBytes">.. <S T="2" F="MessageSize" />.. </C>.. <C T="U32" I="2" O="false" N="TotalSubmissionTime">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1028
                        Entropy (8bit):5.1285144008320325
                        Encrypted:false
                        SSDEEP:
                        MD5:374437007257BE9E0588FF094D0267D7
                        SHA1:66B736F7546012CCCE7443AB3D251B8A91E05248
                        SHA-256:293EE625C8E78718BB6B30DD3FFF14E20B9D0FE708836BEBD1EFDB4D7A27F2CF
                        SHA-512:C46C3E748BFF1BFEBAE62AABA41177B45C1B22217ED9F5BC5F2122CCC3C3CBE6208008597ECABF9E7B8463673FD633F32254C094B3504E9BA417AF932C263CE5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10484" V="0" DC="SM" EN="Office.Outlook.Desktop.MailRuleCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20400" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="TotalCount">.. <S T="1" F="TotalCount" />.. </C>.. <C T="U32" I="1" O="false" N="EnabledClientArriveCount">.. <S T="1" F="EnabledClientArriveCount" />.. </C>.. <C T="U32" I="2" O="false" N="DisabledClientArriveCount">.. <S T="1" F="DisabledClientArriveCount" />.. </C>.. <C T="U32" I="3" O="false" N="EnabledSendCount">.. <S T="1" F="EnabledSendCount" />.. </C>.. <C T="U32" I="4" O="false" N="DisabledSendCount">.. <S T="1" F="DisabledSendCount" />.. </C>.. <C T="U32" I="5" O="false" N="EnabledOtherCount">.. <S T="1" F="EnabledOtherCount" />.. </C>.. <C T="U32" I="6" O="false" N="DisabledOtherCount">.. <S T="1" F="DisabledOt
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1386
                        Entropy (8bit):4.864259596705089
                        Encrypted:false
                        SSDEEP:
                        MD5:469D8AAE5D15C6B256274B4DD59A503D
                        SHA1:2A2F65E83269500E5F2DD323702411139AA66DFF
                        SHA-256:A4573230226FD513CDDADCF06E273F5A126C0B13F1CA851F51BE0AF5DE67D7FA
                        SHA-512:DF2675C1532D9EA0ABA9B2AB3692F5D6513D800E4A6245C4899F47A6F75AC229F39ED5D9D4348B00C58B635C6A1FCC05840205888E63763C91599DC52EA19C16
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10488" V="1" DC="SM" EN="Office.Outlook.Desktop.ReceivedAttachmentBreakdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4151" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="Unread" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="WebRefAttached">.. <A T="SUM">.. <S T="4" F="WebRefAttached" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="ClassicAttached">.. <A T="SUM">.. <S T="4" F="PhysicalAttached" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="ClassicPreviewed">.. <A T="SUM">.. <S T="4" F="PhysicalPreviewed" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="ClassicOpened">.. <A T="SUM">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):828
                        Entropy (8bit):5.098743301870036
                        Encrypted:false
                        SSDEEP:
                        MD5:35176C49D6E0D78D2A3BD73B9BC5E5C9
                        SHA1:3BA9B4295D97B919276B12C9DF000288AC031656
                        SHA-256:8DC1F0EBFC80F53BB7A0123982A7ECA141E741357F31314A76F4225DA23E9706
                        SHA-512:6BB29663A7C43F8493320F6E26C636A3FC8BA7BB77F90B89CD2E638EDBDE2E74589A7BD7EB3D33CAF8E7D0C8D66A6E9899E45FC3A738B74912DA6B89175234D5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10489" V="0" DC="SM" EN="Office.Outlook.Desktop.SentAttachmentBreakdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TR T="1" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <Etw T="4" E="4197" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ODBAttached">.. <A T="SUM">.. <S T="4" F="ODBAttachmentCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="ODCAttached">.. <A T="SUM">.. <S T="4" F="ODCAttachmentCount" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="ClassicAttached">.. <A T="SUM">.. <S T="4" F="ClassicAttachmentCount" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):703
                        Entropy (8bit):4.9756302067851035
                        Encrypted:false
                        SSDEEP:
                        MD5:B625698D93F69E11988A047788A0BDE5
                        SHA1:5BD6805E2ECDDD7FEE1F08FE9B420D73B042D384
                        SHA-256:0D147F5458BE1DA76E9D1AE90E650F25D41DA6ED46ED9E70294B5519818E0D49
                        SHA-512:36AFE645E3722CEB06B93B5A2A068FE40CEACBC1FA8A054AE4448AC666C995861BF7EE6576213E2409A0739594D645F34D1DF2697331126DA73E5BD133D7CA85
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10497" V="2" DC="SM" EN="Office.Outlook.Desktop.ExchangeVersionBlock" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="163" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="2147746064" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ConnID">.. <S T="2" F="ConnID" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1832
                        Entropy (8bit):5.043837281948011
                        Encrypted:false
                        SSDEEP:
                        MD5:0D5F1CFF7759A2946BA10F9EB2D68702
                        SHA1:034AF42F0551BDADC3C6CA318EA03F6BA071068F
                        SHA-256:451FA1B29923C37763CF28C2035D24FDE3310A2F7863D18DD98053E57C97CE3C
                        SHA-512:2A744478B2332A06D7D572296CD20442EDA3169FD0E4B265B6B0D8D0822FB086E637E3B3E18E2A481A19375D50616D95ECEC07D916B59F3B15503A84DAC13239
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10499" V="0" DC="SM" EN="Office.Outlook.Desktop.RulesWizardServerRuleUpdate" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <TR T="1" />.. <Etw T="2" E="20401" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="20402" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20403" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20404" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20405" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20406" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="20407" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="20408" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="10" E="558" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1123
                        Entropy (8bit):4.61048772335179
                        Encrypted:false
                        SSDEEP:
                        MD5:8376FC6DB043015C8879295CEF7F3DC6
                        SHA1:16E087CA3931A04E197F85BCA4B23BF6F1160177
                        SHA-256:B29D9A0E6210063ECC17771B422CA06748E0941FC41368E264B32FB450F17B6C
                        SHA-512:4539EF79219D5068320BEE58C906FCE7CBF749A2EE325F197A7835BC30A87C62145B5CED85913FA62EDDD99D4AEC3448475529801C9F0B299E58852DA4A29F95
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10507" V="2" DC="SM" EN="Office.Outlook.Desktop.BlockOlkRecoveryRaceCondition" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="462" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="triggerPointMessage" />.. </L>.. <R>.. <V V="0" T="U8" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="triggerPointMessage" />.. </L>.. <R>.. <V V="3" T="U8" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="U8" I="0" O="false" N="TRIGGER_POINT_Enum">.. <S T="2" F="triggerPointMessage" />.. </C>.. <C T="U64" I="1" O="false" N="DBRF_Flags">.. <S T="2" F="dbrfFlags" />.. </C>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):535
                        Entropy (8bit):4.796161750023944
                        Encrypted:false
                        SSDEEP:
                        MD5:E0B62F75FE0A177528688138298B37F7
                        SHA1:1A81C3B3A3550420D6823E6BDA5556B2EC3DEF45
                        SHA-256:C7B51398B4844E124553FA212FD2CEC18AB3E1CEA948FF292996166AC1AA3276
                        SHA-512:32B06CF3893314F20A3A9EA1CE70519B3065340F50F3D355349D497714DAD34904EA406B7116BAA78F07D2F7FF8FE684BA0946F7DBB872425D67D2A31C822404
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10514" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20700" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TO T="2" I="5min">.. <S T="1" />.. </TO>.. </S>.. <G>.. <S T="1">.. <F N="SearchSessionID" />.. <F N="SearchCriteria" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="1" F="SearchSessionID" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="SearchCriteria" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1386
                        Entropy (8bit):4.776493982422101
                        Encrypted:false
                        SSDEEP:
                        MD5:08361C469F26BE38E370AA1D4B86FDC8
                        SHA1:12037039A3037BF47AA456993B54D5280D772D0C
                        SHA-256:E86AB3843DDF2534EEB442AC7C38114C00BDA962D965C1E10AEF0F98F253560F
                        SHA-512:327F8C22FA914B876D82900FFD1A272BA4483519209A21D7BF151D536F977ADB2AA2E6BB4DBEDC55D67F489A3FDB03EF200FD1349833BC31370718C2DB9456E2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10515" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchCriteriaUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10514" />.. <Etw T="2" E="20701" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="20702" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="1" />.. </S>.. <S T="2">.. <F N="SearchCriteria" />.. </S>.. <S T="3">.. <F N="SearchCriteria" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="SearchCriteria">.. <O T="COALESCE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="2" F="SearchCriteria" />.. </L>.. <R>.. <S T="3" F="SearchCriteria" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):942
                        Entropy (8bit):4.910351081972186
                        Encrypted:false
                        SSDEEP:
                        MD5:ACDD3AC0D5B3421A80E539B092A1B29B
                        SHA1:4239886E6C19C3AC60D98514DFE1B2399D489210
                        SHA-256:683AEFEE39E2E68F0697E1CC0EC43BB0F25E3A10DE01897CE085AAB08B2FA7D4
                        SHA-512:2A25541BC1C924692713DA4F6EA4317A4132D36E9B009866F4B9E9916C1ADBF002133F5B1FBE8B0916C80A522754C193484CC333B4EC4CD3708EFD03BFDE5059
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10517" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentMultiSelect" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4205" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4206" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="MultiAttachSelected" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="MultiSelectUsageCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SelectAllUsageCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. <S T="4" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):976
                        Entropy (8bit):5.241690327638327
                        Encrypted:false
                        SSDEEP:
                        MD5:E70EB7FBE470AA3B6C7CEA973C2F34B5
                        SHA1:5A8C746311A904F4762E0829D701D00D7A8653DA
                        SHA-256:CFDBA44E59C4D4144608869FB4D977A9B35446EB3865EE7534FCD1D7191C84B2
                        SHA-512:4600465C08CC3C1D7DFE55F5A6F661DDDB97067895C532C745E47102B29568334F28F2C75DE1BE80C133A1952359EE4D725EB7042E2F7272B4FEB8D01A1E043F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10522" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookSearchPagingInfoDiagonostics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7072" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="SearchSessionID">.. <S T="1" F="SearchSessionID" />.. </C>.. <C T="B" I="1" O="false" N="CapSearchResults">.. <S T="1" F="CapSearchResults" />.. </C>.. <C T="U64" I="2" O="false" N="NumberOfPagesFetched">.. <S T="1" F="NumberOfPagesFetched" />.. </C>.. <C T="U64" I="3" O="false" N="NumberOfItemsAdded">.. <S T="1" F="NumberOfItemsAdded" />.. </C>.. <C T="B" I="4" O="false" N="MoreResultsAvailableOnServer">.. <S T="1" F="MoreResultsAvailableOnServer" />.. </C>.. <C T="B" I="5" O="false" N="StopRequestingMore">.. <S T="1" F="StopRequestingMore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.725786668523051
                        Encrypted:false
                        SSDEEP:
                        MD5:46208DBF4A68FD32353438B793DA7451
                        SHA1:8EECF9402F9BA3BFE028F8E5AE20BA012C7AF851
                        SHA-256:0903FAFCD1529BC0E28A3BA28865687EF026440417650E096360AFC01A447745
                        SHA-512:C7FB87C4C76CD3DC93D2F30A0A52CCF224BB8E89C9905F3718DC2AC57958B3BF6C0D8545315129051ED5A1DA3C135137E46C7F70A8079A51C6EE4FDFBE6C2A9D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10533" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="19015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1158
                        Entropy (8bit):5.046432484061533
                        Encrypted:false
                        SSDEEP:
                        MD5:9542A2B8023773945987721AA43E7517
                        SHA1:9C6BE0CED65B2CE8570BD0EB263A0BA5EB56E83C
                        SHA-256:E02EE28063552FEFE0850A4B09C0EE443FD7D297998879B924D2780D394EB804
                        SHA-512:D6728D199DB929ADC36123C8D2FFD97D2E3D6E8105F963254E509E8469C6ADB93223814BA91EEF0AF00EC7E85AFCC9D8050EB85CA30596300973AB243D000BA6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10534" V="3" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsPerfRule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10533" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <Etw T="4" E="19014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="3533" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="F" I="0" O="true" N="BrowseGroupsLoadTime_Avg">.. <A T="AVG">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="1" O="true" N="BrowseGroupsLoadTime_Min">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="2" O="true" N="BrowseGroupsLoadTime_Max">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="NoOfRibbonBtnClicks">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="false" N="NoOfCtxUIClicks">.. <C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):837
                        Entropy (8bit):4.76220970509313
                        Encrypted:false
                        SSDEEP:
                        MD5:1AE4E28C8D2BFCA2DF54EA5DB0FBE2C2
                        SHA1:78BE4F0CA0314EE06C7097915E8072E5B5697E1D
                        SHA-256:7167C18989B02D7E5273D6175308C62CF8622FE3DFD2CD08FCDBC1B6A087E7B3
                        SHA-512:77E4D30460CC3D336723A8BDF49D12177080CA66D90348E1046F4D83C0F0D8936CD7A2238F43D63A329174DFF1521C2793690E39F94E6E2E4BE5C0756906BCC2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10535" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsPerf.LoadFail.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):838
                        Entropy (8bit):4.7668848217854105
                        Encrypted:false
                        SSDEEP:
                        MD5:1A2781EAA1E71A422803EFB458943BA6
                        SHA1:BB8C0FEAE7527B3CAC8DE21E824D3E8E33B4EFD3
                        SHA-256:E89C4780AE0B3222E59C1E7AD1E6D6905A249285DE8FBECE2FC51FCDA7D1BB42
                        SHA-512:B1412775BDFD8343C728ADE96F79F192D9C1B4727C43926BC57B8101DED8AFA9E1CAEBB17E9E4BF1E6579F6AF0E5B9F4A6DE3E41CB0A98247720EABEF44815C8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10536" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsPerf.ClickFail.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3826
                        Entropy (8bit):5.070342439110033
                        Encrypted:false
                        SSDEEP:
                        MD5:02374E6E64C4662B1DF6F7A62C264631
                        SHA1:86F49FEE55F240E1C3361DE09A034738CA5D9309
                        SHA-256:D16F7E4672D08968B668CA55273CF1388513474EB032CF5F9DB7EA776FE017F2
                        SHA-512:BA44D515322B502FC68D4F614D5BF98443513BA63EB2E1276C86BC6BFF1293412FCAF019B5D5C612BF86AF273186F3B16DF9D1909D09E0A7315EFB0ADFD49248
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10537" V="0" DC="SM" EN="Office.Outlook.Desktop.ArchiveUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20300" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20301" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="20302" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20303" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20304" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20305" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20306" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="20307" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="20308" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="10" E="20309" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="11" E="20310" G="{691e1c12-2693-4d4a-852c-7478657
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2272
                        Entropy (8bit):4.54885520239409
                        Encrypted:false
                        SSDEEP:
                        MD5:4DF1573ED1192DEC7B3CEB1DD26138B0
                        SHA1:25BBAD1B9475B8533D8EE2A2EB336825EBC9A3B1
                        SHA-256:A3D8C27FBC3D9019235DCE2B746739A3329F60ED401CA58479E6FABDA9558746
                        SHA-512:7D8B6045A0D30147487740FC3A08734152D730F6E791138C9038B8B5BEA99433C5001BEFE08250E88D73250BCD9FB6D61B34EFBFAFECB384F22A538B4FA53B95
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10539" V="0" DC="ESM" EN="Office.Outlook.Desktop.FrequentReconnect" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10111" />.. <Etw T="2" E="4202" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="3">.. <O T="LE">.. <L>.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="2" F="LastConnectTime" />.. </R>.. </O>.. </U>.. </L>.. <R>.. <V V="300000" T="U64" />.. </R>.. </O>.. </F>.. <TH T="4">.. <O T="GE">.. <L>.. <C>.. <S T="3" />.. </C>.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </TH>.. <TO T="5" I="Hour">.. <S T="3" />.. </TO>.. <SQ T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1392
                        Entropy (8bit):5.101550234496587
                        Encrypted:false
                        SSDEEP:
                        MD5:3A0B7E81FDD22975EA54AD58416F3DBB
                        SHA1:2CDC322602C92A93AAB4BB7F0EA85F8A83767E0C
                        SHA-256:563FDD942372FE13A4D7B25B7D88757023AA8DCEE337ED00B7213F31378EFB57
                        SHA-512:805D071EA08AA92494DEB93CF11DF0FFCE7742C6C532FCB6D7F4F615090B6D3A56E14BD1A5F5F62EC1859CCD22CC2F5DC2D6B399EED845F9EAB589D0EA2C66D7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10540" V="0" DC="SM" EN="Office.Outlook.Desktop.MCRP.ThreadHistoryInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="20013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20018" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ThreadHistory_HeaderGenerated_Count">.. <C>.. <S T="7" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ThreadHistory_HeaderFailed_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="BodyOffsets_LoadFail_Count">.. <C>.. <S T="4" />.. </C>.. </C>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1121
                        Entropy (8bit):5.046897338447445
                        Encrypted:false
                        SSDEEP:
                        MD5:63A2B8A82E897CEC1B0DA20C92E10FBC
                        SHA1:663F69EC6AB93005B768232BECD33413A6177ABF
                        SHA-256:4DEA23A5C3CCC056E8561BC063FE4E26DCE9CA6EEFFB6CF49F7C97ED28CFD19A
                        SHA-512:E273A1B540BB1D92F2CFCCDD3138EB70498A5D31778E61EB98AD705064D834451EB1A682DE42F6BBBF55607FF0A2C5739566527031ED65504EACBCB8FEB13264
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10548" V="1" DC="SM" EN="Office.Outlook.Desktop.AccessibilityApps.And.HighContrast" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryStartup" />.. <TO T="2" I="5min">.. <S T="1" />.. </TO>.. <SS T="3" G="{d793ead1-6b23-494c-aa6d-c109f00f3eb1}" />.. </S>.. <C T="B" I="0" O="true" N="Narrator">.. <S T="3" F="narrator.exe" M="Ignore" />.. </C>.. <C T="B" I="1" O="true" N="Jaws">.. <S T="3" F="jfw.exe" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="WindowEyes">.. <S T="3" F="wineyes.exe" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="Nvda">.. <S T="3" F="nvda.exe" M="Ignore" />.. </C>.. <C T="B" I="4" O="true" N="ZoomText">.. <S T="3" F="zt.exe" M="Ignore" />.. </C>.. <C T="B" I="5" O="true" N="Magnifier">.. <S T="3" F="magnify.exe" M="Ignore" />.. </C>.. <C T="B" I="6" O="true" N="HighContrast">.. <S T="3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):4.974719529285956
                        Encrypted:false
                        SSDEEP:
                        MD5:8CFFD055B6FFCC462CCB01FCB3BA1868
                        SHA1:8A3E86BE1FF5E34446160B8239E4747FFE51A561
                        SHA-256:7304BDF5F038829FE9831E52B1104EA9E85CE76D03DD138885E00EA3BF0A2E5B
                        SHA-512:9A0B1E26EF0318BC8A4E86A76E4643BAEA64F720AA13981FAD80867A90A073B349300F8B9C268B49A480BD449CB98047A8D240C40A514E3E086E29A188137776
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10549" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentsUploadToCloud" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4161" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4208" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="4209" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4216" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4218" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4219" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="4251" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="8" I="Daily" />.. <A T="9" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="UploadToCloudClicked">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="UploadToCurrentGroupClicked">.. <C>.. <S T="2" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1187
                        Entropy (8bit):5.115067902508748
                        Encrypted:false
                        SSDEEP:
                        MD5:BE8F200FC06A306B98B586C9069BECD9
                        SHA1:1D602BFE60D03FA531F414C313DCCC2BFC1B522F
                        SHA-256:0B748EB06215FC99825129F2BEDB4E270B905B14EFCCB89BBB5BC35222598A52
                        SHA-512:A866B60E08528A4980BDDE6568662468A4DB30F096A4562C59E3233AC312543BCDF5B0E2FC69E8E941A5FD0972367E64BE5436E536FF131C4703D5893DE78B83
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10551" V="2" DC="SM" EN="Office.Outlook.Desktop.FeedbackSupportOutspaceUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20703" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20704" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="20705" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20706" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="5" I="Daily" />.. <A T="6" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_UsageOpenHelpAssistant">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_UsageOpenOutlookBlog">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_UsageOpenOutlookFeedback">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="Count_UsageClickOutlookMobileHyperlink">.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):874
                        Entropy (8bit):5.203529635404143
                        Encrypted:false
                        SSDEEP:
                        MD5:4664838C21527CA3EE903FFAC963FAB3
                        SHA1:B1D3548C5A79B876E9586889FBE8AE5F3A4024C0
                        SHA-256:77D5466B176C3C47D7B466BE854BD7C260EC7F2D67FE4B9FA6FE816969CCCCED
                        SHA-512:46C4A5421E2FF37B19CD80A3D4E66EA68D7FDB6A366164E4D60F0EF26160BA097A6276D76C9FBD45500834269FEE8546A3139DA8CA46E7DDD2F65D869D22CA01
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10553" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlook.AttemptedKeyboardPaneChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20800" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="InKeyboardNavChangesFlight" />.. <F N="PaneChangeMethod" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsKeyboardNavChangesFlight">.. <S T="1" F="InKeyboardNavChangesFlight" />.. </C>.. <C T="U32" I="1" O="false" N="PaneChangeKeystroke">.. <S T="1" F="PaneChangeMethod" />.. </C>.. <C T="U32" I="2" O="false" N="KeystrokeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):982
                        Entropy (8bit):5.199788397426366
                        Encrypted:false
                        SSDEEP:
                        MD5:B0B23843653655A9A97191B573CE9E20
                        SHA1:AD8360337EB15D642994BDDDC3A984A033394B8B
                        SHA-256:926D214E4A06BEF3FF57242267C7EA28D9ECA7E069C502FC0DEE3AE15AFD1D96
                        SHA-512:F5C95C7419931E4374E30167F8506B371C1AD75E7C35F6C17473546EABDC6C79B6380CA27D869D14A82970DB300B581451937F0DE734DFC93B7D77121FD40913
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10554" V="1" DC="SM" EN="Office.Outlook.Desktop.CredControlEnterNeedPasswordState.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="691" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="U32" I="0" O="false" N="CredControlID">.. <S T="1" F="CredControlID" />.. </C>.. <C T="G" I="1" O="false" N="AccountInstance">.. <S T="1" F="AccountInstance" />.. </C>.. <C T="U32" I="2" O="false" N="Reason">.. <S T="1" F="Reason" />.. </C>.. <C T="B" I="3" O="false" N="IsMsoStack">.. <S T="1" F="fIsMsoStack" />.. </C>.. <C T="B" I="4" O="true" N="IsAuthRefactorFlightedOn">.. <S T="1" F="IsAuthRefactorFlightedOn" M="Ignore" />.. </C>.. <C T="B" I="5" O="true" N="IsAuthRefactorPromptStateFlightedOn">.. <S T="1" F="IsAuthRefactorPromptStateFlightedOn" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1935
                        Entropy (8bit):4.7497497501400225
                        Encrypted:false
                        SSDEEP:
                        MD5:98A481A1D799A43936E551337623AE20
                        SHA1:4AA8449795E6D1F294B73A5A4F2B7F6DB2CDCBE5
                        SHA-256:19401B2A477C61D902ABF27B2D18D8EA978A3358A3861DFBF54A0108E1044732
                        SHA-512:C751D93AA5A340369EDD8249E50D82C3D988F212128AA104CD37261D27B181EE9D54EF112A9D30F646C6F04BDA0F9DF1835DFC87E63E158106106CABAFCBE262
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10556" V="1" DC="SM" EN="Office.Outlook.Desktop.CredPromptShownForMsoStack.Count" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="728" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="729" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="730" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <R T="4" R="10678" />.. <US T="5">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. <A T="6" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="5">.. <F N="AccountGUID" />.. <F N="AuthScheme" />.. </S>.. <S T="1">.. <F N="AccountGUID" />.. <F N="AuthScheme" />.. </S>.. <S T="2">.. <F N="AccountGUID" />.. <F N="AuthScheme" />.. </S>.. <S T="3">.. <F N="AccountGUID" />.. <F N="AuthScheme" />.. </S>.. <S T="4">.. <F N="0" />.. <F N="1" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3129
                        Entropy (8bit):3.8480757607116693
                        Encrypted:false
                        SSDEEP:
                        MD5:9E75DEACD8D53699D7A157C6E65F9174
                        SHA1:D51C1BD9F1C96F2BD5556EAA6F7B32F59396FB4B
                        SHA-256:CC994EA32C46C2EB19CB2DF627561C489AAF2DEFFD27ACB6B3C826DDBF321453
                        SHA-512:20CFE8FBBA09FABD735E29FFBD248786DAB98A9EFA249F8D6AF2531A5A16555462A19066094044EC07CAFA33163CF15577210E47284424CD68A177507CC48380
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10562" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.ShowContactCardCalled" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8213" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <TR T="4" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Type" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="Success" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Type" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="E
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):739
                        Entropy (8bit):5.171006641165599
                        Encrypted:false
                        SSDEEP:
                        MD5:CD0161E39D1DBD8C7C27F7BADB5123D3
                        SHA1:29EE014F8F6D6A6BE6E9984AD95AC3C131AC1FEE
                        SHA-256:14ED809507B07389CB32CCBC147ACACC3B75DF461943293B5E0E7D9E429EBA5B
                        SHA-512:19B1262539D4B205395451F23EC0F291FA771EC24F958008EC0A086F924C4121E4D9754203F1BACB69DD8812B9C990F4B6CE73AB79784EC24090971EC4D93DDC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10566" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.StoreJumpingHitsAndErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="205" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="GroupsStoreJumpingResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="GroupsStoreJumpingCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):914
                        Entropy (8bit):5.093507270795182
                        Encrypted:false
                        SSDEEP:
                        MD5:9EAE0455BEAB29AECEA158DEDFD2418B
                        SHA1:4DBD34DDFFA033D8DC3AEF8A6AAC2A7F579030A0
                        SHA-256:31CF6FC7DB1E33CD2B78049E60B8E10198EA4D7F94DBF18292C4A420DFBB50F2
                        SHA-512:7413B945C6005FBFB2B3C94D925EDC0FCC35D8869E1C78186DC826E75A667E61600D1531A5E646F5F6CB5F55309226DEB1DE7262B6D3BF1A3D5B13509599293E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10567" V="0" DC="SM" EN="Office.Outlook.Desktop.MCRP.HideForwardedContent" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="389" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20022" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="20023" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="EntryIdW" />.. </S>.. <S T="2">.. <F N="EntryIdW" />.. </S>.. <S T="3">.. <F N="EntryIdW" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="HideForwardedContent_Count">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ShowHiddenContent_Clicked_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. </T>.. <ST>.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5890
                        Entropy (8bit):4.46273551307581
                        Encrypted:false
                        SSDEEP:
                        MD5:06E0623B68D3BB5290F620C111A0FA78
                        SHA1:E77D0BAF7F8D95E8D5C567CC1459645B12ECD313
                        SHA-256:E5E460C409527595D4E9DD5905F12D9679359930C43DDDF3ECA0ECC9B77C79C0
                        SHA-512:E58A0D9D1E9E237B55EA907D9ED8A8EB647C67359BB5B87490AFAD0DC96A9482AEC25A7FEF48D6005D5CAA584E0DACAD50B53354B9DE3FD050426EAD09252BFB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10570" V="4" DC="SM" EN="Office.Outlook.Desktop.MessageSubmission.NDR.Stats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="5001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="5016" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="5017" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="25321" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <TI T="5" I="Daily" />.. <A T="6" E="TelemetryShutdown" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="FDiagnosticsLoggerAvailable" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="7" F="FDiagnosticsLogAdded" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="GT"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):695
                        Entropy (8bit):5.124593110667686
                        Encrypted:false
                        SSDEEP:
                        MD5:8C49D002467F9530F915B20E0783B165
                        SHA1:F7BFECD91FFACF90A069A96DFEEBD23CB085F8BA
                        SHA-256:7132982CE93A3CDE8A612E79FA2920E26C1FC100014B961E6B4C349B13E02EF9
                        SHA-512:73977C946F97CD2774330285B9660F1A9D0E51B937448D0A532A3E162C5C977E19716500579872AEFFBF067279931C204107096C686B7150F2078D9D1C939FC8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10573" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDetailsSavedServerCall" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3112" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FullDetails" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsFullDetails">.. <S T="1" F="FullDetails" />.. </C>.. <C T="U32" I="1" O="false" N="CountSavedServerCalls">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1019
                        Entropy (8bit):5.023104382326757
                        Encrypted:false
                        SSDEEP:
                        MD5:A5B4A5FC8105ABE3BF196EC890E2470F
                        SHA1:980622C3ECC72C793D40B9BD1F84F3643BF06B4B
                        SHA-256:9F70C560E44ED0B75AA38380BC781CA3DD4D6A62E20FD33771EFD42CE755050A
                        SHA-512:E47A7D67DE732E2DBF155C61EE146FA6C68DAA7B5264DEEB0E28598B819BBEA62127B7EC5B68CBC75C741414390821F9E204AEF7EB91086FEB342C5F0317223E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10575" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupsDetailsErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3110" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountDetailsErrors">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):694
                        Entropy (8bit):5.154438666645573
                        Encrypted:false
                        SSDEEP:
                        MD5:1D377405694C0368ED5C62649D36EF0F
                        SHA1:78FFAD3AA7B45D430309FDBC894D6047295B06F3
                        SHA-256:BDF0F73CFFEACFE3FD4636CA2BB88A00D7CEF63988F69750D550AE756BF2C1DA
                        SHA-512:243DBC9FDC4DA8317AEC298FA4B18CA63524443717B049CD7E4DEDB5F1F45F65422AAD5406348E9A3CF55060C896EF2A792CF248D1D86B3B99D12177FC288871
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10576" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDetailsRequested" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3111" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FFlightEnabled" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FlightEnabled">.. <S T="1" F="FFlightEnabled" />.. </C>.. <C T="U32" I="1" O="false" N="CountDetailsRequests">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.723453209377742
                        Encrypted:false
                        SSDEEP:
                        MD5:2A401EB416DAC211C16B311F559B384F
                        SHA1:E30A16AE51F134DC71EFE44F1B5B55C6482A1A19
                        SHA-256:0BDF212EAAEF92D739DD9407565E65E9587CE1307569E962721F75695A904B71
                        SHA-512:05C3E5F1C1911F48147AED1737824022B381FCA7434047D0E2C8F40FC21CA5B78408670B2F0162D68EBD1FD0A2AB4164EE650304AA6A625868E529C95613FFF9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10591" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="18022" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18023" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.7248058276021325
                        Encrypted:false
                        SSDEEP:
                        MD5:06E888E879E0C7DADA8DF110DDB45F59
                        SHA1:A82A89B4654D27B25374AD963F8E35213660F1E0
                        SHA-256:FA404CEFFBF2206DE9DE11ED1F2D883DC415EE8605CE87E908A9831B97A51DA3
                        SHA-512:BB3D7F5BE9660EC266252FB5701886AA35A320403A8F556AA03B5B55D10FFDAF05E5635FDAC110DE8709E7D1E7D5DA6937FFD3483381F9E5A099A557C2F46B6A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10592" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="18024" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18025" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.726920772359991
                        Encrypted:false
                        SSDEEP:
                        MD5:4C6B8DC2F95118DDADA0C46C907285C7
                        SHA1:5D8C015D22FADF1A5973085A8AC6120BF288E11A
                        SHA-256:F460442B0C3FA0C06192B69B6D37FFDDD3AEFB69520591A25661B087A4446558
                        SHA-512:CA86FA19F294EC28A7BC533F58649363330414B1BF7F3AD532196F8CA8E7048F35C16BF84ED45962D468D1396CC040210971183895827ABAD651E178DB9DC127
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10593" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="18026" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18027" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.726093176261092
                        Encrypted:false
                        SSDEEP:
                        MD5:7EA9D120E4EE04F0936EB4D13F6940CB
                        SHA1:906AF427DEB9EF2845A433CED285380EA7B62FC6
                        SHA-256:13CA3C1C3DB78CBE605AB0E924A0AF7BA9722B852006939CF8D58955A4475122
                        SHA-512:9A42F19DE2E334836A222BCFC4F848240E1F988F1FFCA23839B27C557EF7DA507F60AFA85C3ED53715A560E311B41DFD535290B0BF007AB3A432360E7DA90464
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10594" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="18028" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18029" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3127
                        Entropy (8bit):5.006710952578469
                        Encrypted:false
                        SSDEEP:
                        MD5:16247BD78513CB5428ABCC5F6E30D8C8
                        SHA1:9AE44BEFE30A2F665BAA45188C7445984B87A9AF
                        SHA-256:10DDDC90A043F3BEC95462EDD8C90BD44A64F3C4D0A2E5D06842FB3833BF000E
                        SHA-512:E1F45E29CF2CAD78210988EA43EF19B71B0DB4547CB5CC6F26AE4B7878A7264083D0C9DD8C845EB82D3A93B3322EFDC4EC7A3B90DEA0752A8F22D52E69E86B0B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10595" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIPerfRule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10591" />.. <R T="2" R="10592" />.. <R T="3" R="10593" />.. <R T="4" R="10594" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Daily" />.. <Etw T="7" E="18016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="18017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="18018" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="10" E="18019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="11" E="18020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="12" E="18021" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="F" I="0" O="true" N="BrowseGroupsLoadTime_All_Avg">.. <A T="AVG">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="1"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):847
                        Entropy (8bit):4.770531347718884
                        Encrypted:false
                        SSDEEP:
                        MD5:076140BD641F5CA503AB5C4BB8247B7F
                        SHA1:8EFF1CFFB1B65C81ACE973D7344AF79CEDAF1D26
                        SHA-256:F4A05906738F76EACB349CBDB6E6EEC866384029560274555FE084AEFD140528
                        SHA-512:1091E0ED103E166C641020B53BC2789CD89F523B74C9830113B293FD805360987EF026CC112B430ADDCCB76612D046C8B97D2CCEFDF2B80221F373A84A090380
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10596" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsPerf.LoadFailAll.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18023" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):851
                        Entropy (8bit):4.781788666074573
                        Encrypted:false
                        SSDEEP:
                        MD5:21D0E5BFAF68460559F327504D73F57B
                        SHA1:82A24EF84A03761F55CBF87558974C921D98C614
                        SHA-256:566AD65BF4DC2F93D7115DA7F04248673A707DE8236D0E4536E94B93EFD37A79
                        SHA-512:79995943920EDF8A9F170D870CB785858632E691F95170DEA1DCD35A6B882DF4F44881466EA955EF2F4BDC6BAC8EB7D44836E2E7B1DC8FA0C12F581CBBADD79A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10597" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsPerf.LoadFailSuggest.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18025" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1087
                        Entropy (8bit):4.830524735734257
                        Encrypted:false
                        SSDEEP:
                        MD5:91EE21C9C5926C8247CB199B1A07D215
                        SHA1:A18D48443D88931812CDE2C51E5E7C5DC15D0872
                        SHA-256:C5C1343AC3A69C532DE045D5B35CD2174F6A1F702C487C0577C2E07D864EDED9
                        SHA-512:6193D2A92296D3A230BB59C96A8E75AF28258A91CB3BC82809118F95F367CB06232DA3ACFA6E0E65B6218501F1F13246E534BB7A5AB56F228A9DFF7F9AE77CA6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10598" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsPerf.LoadJoin.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="18027" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="fJoinSucceeded" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="fJoinSucceeded" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountOfFailedBrowseGroupsDlgJoinLoad">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountOfSuccessBrowseGroupsDlgJoinLoad">.. <C>.. <S T="5" />.. </C>.. </C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):757
                        Entropy (8bit):4.951299533486742
                        Encrypted:false
                        SSDEEP:
                        MD5:35DE60EF72E98A3B43494CF91E9DC12F
                        SHA1:309F6A7AB884317A5CAD0CBCC70344BC87BF862B
                        SHA-256:3145FE42FD4F90E9FA113AB1564BD8656393E46D154BF0C4D636A6F687515DBC
                        SHA-512:F47E91996874B78D977D0E5D4E477790BC3044DD8D94FF5CF18DDBE77F1E755C4545841E259ABF3EA5A804BDC14E2C3BE2DEF1B81F21C30590C3A69858B16B7F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10599" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookPerf.JoinSuccess.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="3258" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="ToggleValue" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountOfSuccessfulJoins">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2164
                        Entropy (8bit):4.931561287823141
                        Encrypted:false
                        SSDEEP:
                        MD5:081294868C6476828D4B983A4D4BB0DB
                        SHA1:440F9A2011292C5BEB545C921DD3CA1A0E5652FC
                        SHA-256:81FB37F86FB5037992ECB8F14D85C7DF0276EC155FE8C0D31C22AEDAD682B2BC
                        SHA-512:EA36DD603EAF9695FD8A4929A1EB31CF3AACDF5BDE1FEBBA8B7EBA36C730B9CDCCA88ADF758CF191476E38C68AB56E857EB09CD7EE846497504F9C3EBCD5B928
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10600" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageSendMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="25301" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <Etw T="2" E="25304" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <Etw T="3" E="25315" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <Etw T="4" E="25317" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <Etw T="5" E="25337" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <Etw T="6" E="25354" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <Etw T="7" E="25355" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <TR T="8" />.. <A T="9" E="TelemetryShutdown" />.. <TI T="10" I="Hourly" />.. <F T="11">.. <O T="EQ">.. <L>.. <S T="6" F="HRESULT" />.. </L>.. <R>.. <V V="2147747329" T="U32" />.. </R>.. </O>.. </F>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):722
                        Entropy (8bit):5.219229441759465
                        Encrypted:false
                        SSDEEP:
                        MD5:8FD8B85D0E6D514530497F5C738D4220
                        SHA1:8B81A8EE558416B0359A4286767950AB330E8910
                        SHA-256:787B905F57A4D3179FED47B36C7805461CC9C306FDAE962704EC46B875DF6306
                        SHA-512:05564A846427BFCBE043DE15990B98F99E69BA56C91B0CA41FD5B89588340BBA89CA9DD428EED174D2C759E7CE8A962381E942ACB7884A73B56B8138F999A8FB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10601" V="0" DC="SM" EN="Office.Outlook.Desktop.AbortedSubmissionDueToAddIn" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="25355" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="true" N="AddInProgID">.. <S T="1" F="AddInProgID" />.. </C>.. <C T="W" I="2" O="true" N="AddInFriendlyName">.. <S T="1" F="AddInFriendlyName" />.. </C>.. <C T="U32" I="3" O="true" N="ConnectFlags">.. <S T="1" F="ConnectFlags" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2303
                        Entropy (8bit):4.404420972268341
                        Encrypted:false
                        SSDEEP:
                        MD5:0259A54DD1D66E59384C29BA9301587A
                        SHA1:E457BD8BC14C9A8AB2881745E4EEFFB38FEB0E2D
                        SHA-256:3074FC4B7DAC402F7CF8A968969DEB15140F2ED9DD6476AB0B74286BB8840BC5
                        SHA-512:E23247A76860E6E3F4A4B3199C1E4BA105BA9E9C474539E41E8D006DBC9A5874A318B5234264E8D6E47EE8D61CA454B9B27B90CAF27AF976FCD1E59BBE1D0424
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10603" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.DisplayNewMessageForm" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8214" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="To" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Cc" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Bcc" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="Subject" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):698
                        Entropy (8bit):5.138640938787166
                        Encrypted:false
                        SSDEEP:
                        MD5:E6A0ACAC0CD9BAA8EC95DDF53CD94372
                        SHA1:7B9AA5DB5431EBA4FB383C79C087B3F90D257929
                        SHA-256:BCD28C1C3D9D8BBEFAADC976564763DB7BBCE669B389721ED0E217CEF392F8C6
                        SHA-512:ACD1194F75492ED000A4C1250CE4E71258C11BD6D4181BD7DC0292B005716CD8249FC190EB2855B83020BC72ACEEA129C369A00C54CA5DEC0F54D6DDFE18F3C9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10606" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlook.AtMentionRecipientColChanges" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6108" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Result" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="RecipColModificationResult">.. <S T="1" F="Result" />.. </C>.. <C T="U32" I="1" O="false" N="ResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2033
                        Entropy (8bit):4.5378175775693865
                        Encrypted:false
                        SSDEEP:
                        MD5:58A9A9607C55746F91269B21229FE394
                        SHA1:61864D93FAE7267E2074CAF215D2EB85040A9E65
                        SHA-256:34341DD778F9459A193F2E334F9C6CF5B329FAC423ABC00375D3FC461E183B73
                        SHA-512:992137262F1A1696621D16E8FB63B96CD691187A1F74C2ADA14DBC3925A2D161D9C42A9D992BDA9CB53A0C93A35E99CA0DBA343B6D557716D940B851C8770D38
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10607" V="0" DC="SM" EN="Office.Outlook.Desktop.ArchiveErrorDistributions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20313" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20314" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="20316" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1587
                        Entropy (8bit):5.056831335187698
                        Encrypted:false
                        SSDEEP:
                        MD5:AD663867D101FEE036C87FCF085D7091
                        SHA1:F264F6158F9D75AB581D339B8717BD815A863B69
                        SHA-256:76FEB975BAF179DDA4D6024E1ED6975D307129911859EFE4FA390F64F2823ACE
                        SHA-512:B5A609C117AC5D689623FD989BDFB19B9B69AEE85A58F36ADDDB5AAC9CC4B2CBD5E3E2248002BD34502BA55EA6345632D786B44F08657CDB2451EDC949779323
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10624" V="2" DC="SM" EN="Office.Outlook.Desktop.ConversationLevelAttachmentWellCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4214" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4215" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4232" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4233" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="4234" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="4235" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ConvLevelAttWellButtonUsage">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ScrollToMessageUsageCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Conversat
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2690
                        Entropy (8bit):3.9078381910356925
                        Encrypted:false
                        SSDEEP:
                        MD5:349928DBC417DBABF83BCCF623718BE8
                        SHA1:E8AD2264C660C5DA5BA4BB72010ECD4F75A55810
                        SHA-256:D5996B4EB38900CBC00BF99C2BF2AB398B229F1B68243EEC3A1598EE8DDA5CF3
                        SHA-512:44E4084B78B9BC8BC5C25C401FEEA60E9BBFF3470E338AA2576E4FBA5D0A19A75A2DAC4EDEAD6EBCF6783CF18B72B03C77826F144637782D7C66DE43D2DC81D1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10625" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdruu" />.. </S>.. <C T="I32" I="0" O="false">.. <S T="1" F="searchAlgorithmVersion" />.. </C>.. <C T="B" I="1" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="SelectedIndex" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="SelectedIndex" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="3" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="SelectedIndex" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="4" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="SelectedIndex" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="5" O="false">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1341
                        Entropy (8bit):4.836265291604784
                        Encrypted:false
                        SSDEEP:
                        MD5:62B246F01735D691F6D39795331FCB25
                        SHA1:CCBFBCD2BC7709252234C88C158724368D7180B8
                        SHA-256:244E300E1802580DE0A76CC73FEC6161563037FD30FBB7E78DF2682A2996B3BA
                        SHA-512:E41680AD13498202E1BA9208C7BFEBF47FA8C24C86BA379ABDD51001100F2F93409B7C5DDDF15803FFA6C1728EC400FF17916D57333BD563B719E2F7227E27D6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10626" V="1" DC="SM" EN="Office.Outlook.Desktop.PeoplePickerSelectionSourceHitRate" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdrut" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="searchSourceId" />.. <F N="searchSourceName" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="SearchSourceId">.. <S T="1" F="searchSourceId" />.. </C>.. <C T="U32" I="1" O="false" N="ExecutionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="I32" I="2" O="false" N="FoundUserSelectedItemCount">.. <A T="SUM">.. <S T="1" F="didSourceFindResult" />.. </A>.. </C>.. <C T="W" I="3" O="false" N="SearchSourceName">.. <S T="1" F="searchSourceName" />.. </C>.. <C T="U32" I="4" O="false" N="SearchSourceFinishedCount">.. <A T="SUM">.. <S T="1" F="didSourceFinish" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1779
                        Entropy (8bit):4.763988090772443
                        Encrypted:false
                        SSDEEP:
                        MD5:DC41E43C5B36CEF2AE702A73F26BE79C
                        SHA1:F743367DC7AB80DAE6CEE0D7378ACB0436F780C5
                        SHA-256:CEAFB6A575942193E5E532DD6AC3B0B849C42CDBFEDCB929ABAFB854315808C4
                        SHA-512:87C72CBCBF56DBD14A6FC9F25C9D552551946E9EF99F6D064D113F490A8A110C187B6ABF3E51A3DC828F01A1816913294D6906ADA5F457356213090EE81F888F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10627" V="1" DC="SM" EN="Office.Outlook.Desktop.PeoplePickerSelectionSourceRelevancy" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11265" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="SearchSourceId">.. <S T="1" F="0" />.. </C>.. <C T="W" I="1" O="false" N="SearchSourceName">.. <S T="1" F="1" />.. </C>.. <C T="D" I="2" O="false" N="AverageItemRank">.. <A T="AVG">.. <S T="1" F="2" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="DisplayNameMatchCount">.. <A T="SUM">.. <S T="1" F="3" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="EmailAddressMatchCount">.. <A T="SUM">.. <S T="1" F="4" />.. </A>.. </C>.. <C T="U32" I="5" O="false" N="FuzzyMatchCount">.. <A T="SUM">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1654
                        Entropy (8bit):4.840349820775216
                        Encrypted:false
                        SSDEEP:
                        MD5:6F85563B82B66E82BF44FF16FF5700E4
                        SHA1:A9CFD6FEDBB4E760D1AA1E0DDA8C4606F7247650
                        SHA-256:648DADBB57E1FD63CBC4EC04A90AD00D95F0B4CCC42C3865DADD120143610E7D
                        SHA-512:5B53CC3DA2771AEA6F6F16FB829AE16AA5256E7A3A0A3F4B9FE1B86A5674D4CAA9F52BE5274424FFAC515E56B60D191BABD786BA8ADFE18983131BCF6403208D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10632" V="2" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.DiagnosisError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="2" E="3" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="3" E="11" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="4" E="5" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="5" E="18" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="6" E="19" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="7" E="TelemetryShutdown" />.. <TI T="8" I="Daily" />.. <F T="9">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="10">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4049
                        Entropy (8bit):3.83813185940041
                        Encrypted:false
                        SSDEEP:
                        MD5:00020CB5745BDBACDA9BDAC965F3AF78
                        SHA1:D5AD4276EDB49490BC1910DCED5D95125018D610
                        SHA-256:B777B33D0AAA4500B93504234566829C3BF5932A56CFADD8719BF854644DA95D
                        SHA-512:30FBCA01752300A37BE9865C2806E883B8BDCF05E45589D14FA99A127B51A6FEFB9F76DD0F47B50B02CD71BC9D380B9F94DBD640811BF025AFA6BC980EDF7C07
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10633" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.TimeSpentInAPI" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="10" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TimeSpentInAPI" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TimeSpentInAPI" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TimeSpentInAPI" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4084
                        Entropy (8bit):3.8647165741335274
                        Encrypted:false
                        SSDEEP:
                        MD5:F394B5BC1B23CF3682C39EE240413701
                        SHA1:3AB2FA91062ABE09BDC0316C099524B75BCAAD02
                        SHA-256:54B4610403D359877A11E193126EC9378E205C0A162EAF79C708EBB918162104
                        SHA-512:6E06378D6258CB3EC99BA8ED87092138BBD7B560AF228E932E1F04134340E98341F1B0407B1027486EDB9D5847722132905AAB16FD16B050CD3C954958A803C5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10634" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.SARAProcessingTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3897
                        Entropy (8bit):3.714217430699541
                        Encrypted:false
                        SSDEEP:
                        MD5:C28A411C572C0B6A2DDE7CD339591532
                        SHA1:24D34A8C10DDCE41ABB1235DA83301D35FD1ED0E
                        SHA-256:C0C44B6F974CF570A0BBE0475A4902559C1ACCAB17B3ED12C76905D029835B60
                        SHA-512:1CB330014F653DEF4F513F433A5E09822DF6FDB7032735220E69561F0E5F22157A9D870D923B4747BFBAD81E2AC05CF216C3415C13B4537130CEA04E8D1212D8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10635" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.PackageProcessingTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10636" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):484
                        Entropy (8bit):4.739101847638196
                        Encrypted:false
                        SSDEEP:
                        MD5:7AF9EA3671B1151509D4BA4B6D578589
                        SHA1:D167ABC5338CEB51AD21243FDFE4128D5AF00E20
                        SHA-256:48B3BD4FFD3C024245E1FA438C85F402FA99DBA5F7C48BA4D4613C85A84558CF
                        SHA-512:52203B35468D2F25F20C7EC9301071ECCD82ACD438BB5F90DC4BC84AD1EB829A929397186B20A1C9B71ED59D13460FC0B199561195BE3D276C534D117B2B54FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10636" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3758" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="1" F="PkgProcessingCompleteTime" />.. </L>.. <R>.. <S T="1" F="PkgInstanceCreateTime" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1105
                        Entropy (8bit):5.09994528769971
                        Encrypted:false
                        SSDEEP:
                        MD5:419E12F6694A2C585D1A178A90CDAA41
                        SHA1:C9CA7C66A01A733F101D240F813AEB5662DC72A0
                        SHA-256:BAF5413DEC50AF20ACAF3381851A084DE07FE7135BB166E051B42DA62AA3E4A8
                        SHA-512:ACF4088938AE69F1BE8DAAD5E52AF7B60E7D77863589E94497C4771CFD65D7525E10E199B2A13547DFBDF8B72B7D4BC8E091E2D2E2A590C53DC3B4D6D0A95B76
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10641" V="0" DC="SM" EN="Office.Outlook.Desktop.ServerSearchSuggestionSelected.PostRTM" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7076" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="G" I="0" O="false" N="SearchSessionID">.. <S T="1" F="SearchSessionId" />.. </C>.. <C T="U64" I="1" O="false" N="ClientId">.. <S T="1" F="ClientId" />.. </C>.. <C T="W" I="2" O="false" N="ClientVersion">.. <S T="1" F="ClientVersion" />.. </C>.. <C T="W" I="3" O="false" N="ClientCulture">.. <S T="1" F="ClientCulture" />.. </C>.. <C T="I32" I="4" O="false" N="SuggestionBatchId">.. <S T="1" F="SuggestionBatchId" />.. </C>.. <C T="I32" I="5" O="false" N="SuggestionId">.. <S T="1" F="SuggestionId" />.. </C>.. <C T="W" I="6" O="false" N="SuggestionInstanceID">.. <S T="1" F="SuggestionInstanceID" />.. </C>.. <C T="U32" I="7" O="false
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1967
                        Entropy (8bit):5.0585162123390495
                        Encrypted:false
                        SSDEEP:
                        MD5:8A4BA7FA8322A12CBAE30438DAE8B06C
                        SHA1:0F7338B4EB8CD978A9B9543734B5E140C50DE783
                        SHA-256:89791DD62F7E5779A9760F91F73804E77FFE78DECDEBEB9EB3AD9AEC8ED53C61
                        SHA-512:076497B075591054EE3A930D280DE36C616BB20364B8CB195D00DFE8E9CF349F1D86089EF9A86FFBD7B265736DA2079B9F0B6DE07F478DEE0029B944E6156062
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10642" V="3" DC="SM" EN="Office.Outlook.Desktop.InformationRightsManagementHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1000" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="2" E="1001" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="3" E="1002" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="4" E="1004" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="5" E="3800" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="3801" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="3802" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="3803" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="3804" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <R T="10" R="11724" />.. <R T="11" R="11725" />.. <TI T="12" I="Hourly" />.. <A T="13" E="TelemetryShu
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):578
                        Entropy (8bit):5.2121422760306855
                        Encrypted:false
                        SSDEEP:
                        MD5:2FB37372ECFACB6729C856B4ECBB5959
                        SHA1:556100BBA3D7166D65BE8F59ADDE6EB8A4F913A0
                        SHA-256:8014165625A32E8C1A755096261CBFDB56E0CC1F21F7663C0394657239CCC0E3
                        SHA-512:8664553F45AEDAA00896BA5D61168F077358875EE95414EBDD9FF1D2D003895468581E49245D6151796A2F758EE0B471CC31AB8DBBAC2A3D5258172DF576E9B0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10643" V="1" DC="SM" EN="Office.Outlook.Desktop.ImapIdServerInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="101" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="W" I="0" O="falseNoError" N="ServerName">.. <S T="1" F="ServerName" />.. </C>.. <C T="W" I="1" O="true" N="ServerVersion">.. <S T="1" F="ServerVersion" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):4.398092692066297
                        Encrypted:false
                        SSDEEP:
                        MD5:CF52DB4F119209E42F12EC5FA20713CF
                        SHA1:AAF3D72A93118F0C598F955225853B54A88163E4
                        SHA-256:6F0ED0AABB899198C2AEDB81F9200D40459198432F0018BD6996021B8173DE4F
                        SHA-512:351B3515673262B531E7B2BE228DBCAB0D7145A5596148D282F472B9A9B125282C5AB7F6609778B84BFBBC11FC4EC8FC42CC56A6DB7DB1A9FFE56ACA1D5678D3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10644" V="0" DC="SM" EN="Office.Outlook.Desktop.StoreConnFromServerDNHowFound" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="810" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="DefaultStoreConnection" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="FoundByStoreServerKey" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="DefaultStoreConnection" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):601
                        Entropy (8bit):5.277891299223542
                        Encrypted:false
                        SSDEEP:
                        MD5:2A5F0BB262A5A68CFBADC00958EC49C4
                        SHA1:C65F352F1067693FBE1640574B656F9500839F8F
                        SHA-256:867E44045FC889AD459FDFE4726916A7127198BDC9A2FA91A9D53A013233270D
                        SHA-512:0A30BA968AC3A39BAE33F7F20FAFD8A070E773F05C85464BFA4B5E94CE5E3A6E0625635072572A200FC148A70D4A7A193FEDE6BFE875DB8CE619CD90E4A684B7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10645" V="2" DC="SM" EN="Office.Outlook.Desktop.TelemetryOnOutlookFirstBoot" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="415" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="416" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="FT" I="0" O="true" N="FirstBootStart">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="1" O="true" N="FirstBootEnd">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4845
                        Entropy (8bit):3.932422649152658
                        Encrypted:false
                        SSDEEP:
                        MD5:EE6E2F272951DDBE9319247D0FAA7A4E
                        SHA1:E4D5D09EC427D3E920C83E699592D9241DB79903
                        SHA-256:FA3670AE49FA7778450DE0A447F24A097DF501082EAE596C44B4B8A93D1F8A09
                        SHA-512:9471D5C93FB8C17C7250A6430E68DA060F25F78BD0014093A81FC840B00B1FA9B7384699A8CCA364ED40BC00C1EDE723C3BFE46778030DB7B24EFC02FE8867EC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10646" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="352" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="Planner Mode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="Planner Mode" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Planner Mode" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During F
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2248
                        Entropy (8bit):4.659184776077476
                        Encrypted:false
                        SSDEEP:
                        MD5:9ADFFAC8A44FD653681AC1E18E2CB37C
                        SHA1:6189CF1CD270A77B483AFFC5A2671B28BF23B8A7
                        SHA-256:83896E1513FF46C5ADFEA555E3D80E1763EC7193632B2D70FE4870088B5AFC63
                        SHA-512:C6A4D1F6EE7CCD67C275BC6F112D7475D9BE089A1BECA17E729589428B3D1685D3227B2399BC46A292D852C623D4CCF51E7E97FD44731196CAD1C9697590FE6A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10647" V="0" DC="SM" EN="Office.Outlook.Desktop.AttendeeListSchedulingAssistantLostFocusAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10646" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="FreeBusyAttendeeGridLostFocus">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InputNone">.. <A T="SUM">.. <S T="4" F="3" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="InputMouse">.. <A T="SUM">.. <S T="4" F="4" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="InputKeyboard">.. <A T="SUM">.. <S T="4" F="5" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="InputKeybo
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2237
                        Entropy (8bit):4.650423548009724
                        Encrypted:false
                        SSDEEP:
                        MD5:F8AC04FF763D9AB3D179A2F6D02E7D11
                        SHA1:16E7B70CD643EEE5C59B7F3755170B7D7EF0F2FF
                        SHA-256:E1426699D2845F7DEC2638963B22B6E87C6834EB7F603B3B046C1087C1244E12
                        SHA-512:E27CDBEE816C3BB3D7BC8C1FB65698C8784AC6D610CAA1F7A98732256E8DB9C56AB9C04459B3CAA6ADE22F9BCE431631F6D06DD102397999DF2BEE85D6448A16
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10648" V="0" DC="SM" EN="Office.Outlook.Desktop.AttendeeListTrackingLostFocusAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10646" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="FreeBusyAttendeeGridLostFocus">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InputNone">.. <A T="SUM">.. <S T="4" F="3" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="InputMouse">.. <A T="SUM">.. <S T="4" F="4" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="InputKeyboard">.. <A T="SUM">.. <S T="4" F="5" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="InputKeyboardMouse">.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2845
                        Entropy (8bit):4.344086938096499
                        Encrypted:false
                        SSDEEP:
                        MD5:54067ED027A72FD6ECE8939849EF8463
                        SHA1:DFB90DBB8D63E3CE1E180B71C52FD12A2D00C5FE
                        SHA-256:12FCD8D37E74A4CA75DCA0A871FBF818D63ACB5CE9FB46F66E0BE7582648AA8D
                        SHA-512:6645AECC4CA5C983ECE5CCB1C17D4B5AE1D9B14D78E22624DDFAAAFB0CEC2260BA2E666DC03B715C86DEA4424EEF96EA22879267C26B108FEB54C919EB4D7D1C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10649" V="0" DC="SM" EN="Office.Outlook.Desktop.FreeBusyMapLostFocusAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="353" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):515
                        Entropy (8bit):5.280761302407042
                        Encrypted:false
                        SSDEEP:
                        MD5:B0D0659E91355D2026A9A79991DF17D8
                        SHA1:ACE8BF330F75CD04B54A79AE438F8D29D61E64FF
                        SHA-256:922FF437201298BF577967B0898CDFBB28F0F3F437F031FD5D4A3937EDAB6B59
                        SHA-512:2371CAADB81AF61396484EC1DE2D507DA06A9CB06301A2E55ED6DE1476B4B75C49FE3AD558F3F05F7D71919DCF36D77E2B16A62C813C7341BEA851ECBD6EACD2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10659" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookInAppRating" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20730" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="Rating">.. <S T="1" F="Rating" />.. </C>.. <C T="W" I="1" O="true" N="FeedbackComments">.. <S T="1" F="FeedbackComments" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):699
                        Entropy (8bit):4.712692920339422
                        Encrypted:false
                        SSDEEP:
                        MD5:EFFAEABF3756C3E2047C976C41135B2A
                        SHA1:A69545C2EC1DCF17C56B0DF4ED76B5315EEA1EA9
                        SHA-256:2CC17C6ABA7DB98C5BAF4567C25CA68E58F546878399AEE9ADBFCB0C4CDF561E
                        SHA-512:65487A4747624B965E06A72ED5357A94AA8D3E52140743BDEFC40F880F2CFBD901A7C2C067B2379D2DE5830FEEEAB293FD97741C720F94FA783DB1106FD3835D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10660" V="2" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="338" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="339" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="2">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="U32" I="1" O="false">.. <S T="2" F="CountUrlsRetrieved" />.. </C>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4489
                        Entropy (8bit):3.7170559421323106
                        Encrypted:false
                        SSDEEP:
                        MD5:96A9B05F0BB30D832DF270FD34C31B61
                        SHA1:16610686ABE35565C75C80CB68470B5EEA448871
                        SHA-256:60891EA76C1F8236F043BBB6B1A93CC0A7A9A94287BA43D6672EB9EBD3862874
                        SHA-512:8166EB433DC1DD99A4C2962812AD219165AA6BF17F01C9E8C4AF32BC0336735CAFEC24D5A30D4E1087F6EE7D3383728D6C22A826523496C077146EBCC794009C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10661" V="2" DC="SM" EN="Office.Outlook.Desktop.SharePointOnPremUrlRetrievalPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10660" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="301" T="U32" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1201
                        Entropy (8bit):4.7047018694905365
                        Encrypted:false
                        SSDEEP:
                        MD5:DAB06A176A635F30C100621BEC0E89E6
                        SHA1:4F9293F82D6A077EA985FB4BF848C04925A28183
                        SHA-256:82A80F991BBCA212108EF506DDF85CAC784903D41641EDF98EB68283A9EC2AF1
                        SHA-512:DB62AAA783349CB6131A6A8D286C1C9212C3E3CA086B6050AA24E88D4F38CCC3D04288CAA453C24A2ADE9B086EF69E3DD5E4E8421B5EF0A8C11098879CB31AF2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10662" V="0" DC="SM" EN="Office.Outlook.Desktop.SharePointOnPremUrlFound" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4223" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="339" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Type" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Type" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Internal">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="External">.. <C>.. <S T="6" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1263
                        Entropy (8bit):4.815484846268293
                        Encrypted:false
                        SSDEEP:
                        MD5:AE0554F415F0C0A0BD9B38B75D55723D
                        SHA1:1825B37E1710897E2F82083B15AF6D161C07CF86
                        SHA-256:52A9BE47192D68E8BB1BDF82D47A75BC4500214FC085812B951B23B2CF7A9F4C
                        SHA-512:11A34602A50DF3BD87E8EDCBC4D4F78A2C42DF549F88E813A694AC565C2A3EF366BBC5B215A911CC8A45A5DCE7ED27585C61CDA59D5B9199615A023C0B1D30A0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10664" V="0" DC="SM" EN="Office.Outlook.Desktop.ReferralTaskSuccessFailureGetFQDNFromLegacyDN" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="212" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="213" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TR T="3" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="RequestMethod" />.. </L>.. <R>.. <V V="39" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="RequestMethod" />.. </L>.. <R>.. <V V="39" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SuccessfulTaskCompletions">
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7291
                        Entropy (8bit):4.2924586770926245
                        Encrypted:false
                        SSDEEP:
                        MD5:6C8C9AB257C887579D14B2C1A3A6691D
                        SHA1:675609E8BE93C95F88EE976DED8A13102A4E6AE8
                        SHA-256:4E5366C2C06BCFD4D243FC54BFA0136A17D9FA3C73DBADA09793098555471C79
                        SHA-512:81D707700F6D5D4CDDE0E43A4DAF36AC5B785A1D616CFCA129C0E16E8B7EB79AB6BE1F7C65BF5602FE24EACF1B41476C2EAE834BE1B202C811BE95EE64BF0480
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10665" V="4" DC="SM EUII" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AuthRefactorFlightedOn" M="Ignore" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="3" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="4" E="7092" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="5" E="7094" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <US T="6">.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </US>.. <Etw T="7" E="7091" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="8" E="7093" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="9" E="7095" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <US T="10">.. <S T="7" />.. <S T="8" />.. <S T="9" />.. </US>.. <UTS T="11" Id=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):972
                        Entropy (8bit):5.074924607619298
                        Encrypted:false
                        SSDEEP:
                        MD5:AC519113BFA0619F92C7CF1D52C4B3C4
                        SHA1:6450E3C28C756156F2216094D834C97D47BFF881
                        SHA-256:9ADC20294144947971736F3EA343D65710FC3A530155A3B3AACF4C85D217809F
                        SHA-512:1591A41225736266EDAE43A7D453A7789AC1285AC22CB763F895DD68FC788761C13D19AA535E047408C3B87C430C2FC15C0ECBE89C82B6EB63A188E1BA2C07EB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10670" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentShortcuts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4227" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4228" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="BrowseLocation" />.. </S>.. <S T="2">.. <F N="BrowseLocation" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="BrowseLocationType">.. <S T="2" F="BrowseLocation" />.. </C>.. <C T="U32" I="1" O="false" N="BrowseLocationDisplayCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="BrowseLocationClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1078
                        Entropy (8bit):5.0144713527098554
                        Encrypted:false
                        SSDEEP:
                        MD5:04C64E6D8665B380B075B4D9680E95A7
                        SHA1:B991FA6FC0BD28DC740D694D2B8F1EB5E399E13E
                        SHA-256:6C9DF1DE65C45B8965B4646DF85FD8FBCCFA2532021D94327C89500F3674E0FD
                        SHA-512:28CECD71B745B4C25E2F08B465BDC90A3480822F7396734054607FBA0F5C0ED034E65D008EF51615D3607A40E827053705ABFCB3680ABA5AA4BE9B4BDE35E345
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10671" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsPropertyStoreResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4224" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. <F N="PropertyStoreResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="F" I="1" O="false" N="AvgTimeInMS">.. <A T="AVG">.. <S T="1" F="TimeInMS" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="PropertyStoreResult">.. <S T="1" F="PropertyStoreResult" />.. </C>.. <C T="U32" I="3" O="false" N="CountResults">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U64" I="4" O="false" N="MaxTimeInMS">.. <A T="MAX">.. <S T="1" F="TimeInMS" />.. </A>.. </C>.. <T>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1666
                        Entropy (8bit):4.698378831456289
                        Encrypted:false
                        SSDEEP:
                        MD5:9BF3249EE45635399FDFF439060F656A
                        SHA1:89F92582EA905535E4B146641C21D8B0715286EC
                        SHA-256:DCA735297B74930BFEA715A4F1E641D54BB1620AB2297A74EBE643A7F12EC885
                        SHA-512:BCCC94E59E9AD9B626C97209972029BF0420967DAC13CBF8E6C19BAEEC957A2EB6F36A23ED7E8FBC1D2D10E2B166C01C8DF4CE047255244FA2CC6DCBE4F42469
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10676" V="2" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AccountsInProfile" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="414" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="418" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475411-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475412-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):800
                        Entropy (8bit):4.860299152352607
                        Encrypted:false
                        SSDEEP:
                        MD5:A9727DFDFE19840889B273B87FA4A145
                        SHA1:64FA94553F688D9860E8FF8FD4375ADFA5C94B7C
                        SHA-256:067A9433AE90DD88E2CB0316DC8B6981B5DBF094F18CDCAD88D8942405437FF5
                        SHA-512:C17C075191E4A691B4844FBE9ED98CE32CFB2231E5D7DD52923A327D7CCF9C8480526A9DBDC902D73210BFF572B66A69B73A2AC7B27049791358C0A5FF38B5DA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10678" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="670" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7063" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="7034" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <G>.. <S T="2">.. <F N="ClientRequestId" />.. </S>.. <S T="1">.. <F N="ClientRequestId" />.. </S>.. <S T="3">.. <F N="ClientRequestId" />.. </S>.. </G>.. <C T="G" I="0" O="false">.. <S T="1" F="AccountInstance" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="2" F="AuthScheme" />.. </C>.. <C T="U8" I="2" O="false">.. <S T="2" F="Prompted" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3272
                        Entropy (8bit):4.135926409353128
                        Encrypted:false
                        SSDEEP:
                        MD5:99A5409CC6C157A11DE8B61194BCC3D6
                        SHA1:5C0F64E64020AB7B33C1B9D69FC1B23CB48B10E6
                        SHA-256:D04E1D3A05C5C4C473B051BE5556D50DB4F67BDBDC699A14A26062958986A097
                        SHA-512:A782FF0629650D190971D04E739E131A7390320D63F3ED5EB8B45A8870A88DDE722810729231EC0735CA5C3867531203FB8AC481CB520F81EB03E70311BF0D09
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10682" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardAddEdit" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="blelq" />.. <UTS T="2" Id="blelr" />.. <UTS T="3" Id="blels" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="MsoAddEditType" />.. </L>.. <R>.. <V V="Add" T="W" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="MsoAddEditType" />.. </L>.. <R>.. <V V="Edit" T="W" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):743
                        Entropy (8bit):5.100051536114664
                        Encrypted:false
                        SSDEEP:
                        MD5:5641096ECB4A8F6BBC492007CB270A8B
                        SHA1:52278332259B61B8662B5D1C2CC2DF50ED00C85C
                        SHA-256:6F68A41FF6510BEA504FE2AA0BFC4BE05E13093861985A1AE643B8C67B80B647
                        SHA-512:0B77E5562A68CC3E39D2464315A0A616C5449BC411C37D72D5D0B176FDD49A3ADB551B34C8A48E6CA442E1A58ADF636EB56086A385482157B218437BCE181A4D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10683" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.CallingFunction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3760" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="DiagnosticScenario" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DiagnosticScenario">.. <S T="1" F="DiagnosticScenario" />.. </C>.. <C T="U32" I="1" O="false" N="CallCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1317
                        Entropy (8bit):4.638570457615204
                        Encrypted:false
                        SSDEEP:
                        MD5:666F009C533CD289740D021DB5B24BC9
                        SHA1:C63E04D19EB1FE92EADE4369641C7BAFEE63DD78
                        SHA-256:57F9BF2A094BFE8BD7033D59E3C79965CEC806F3084A55C88227BF0362640A25
                        SHA-512:3E5C88EE9E94AD22C5567921DCFAD6BBD303B3B2BCC13668427CF401E2DA8DDBA2A77C0A3252041D6A1A4B87D675FADC72DD0BE8320C201002CF6206779ECAF7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10684" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1016" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="1017" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="1018" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="1019" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="5" E="1020" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="6" E="1021" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="7" E="1022" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="false">.. <C>.. <S T="5" />.. </C>.. </C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5236
                        Entropy (8bit):4.53088724832978
                        Encrypted:false
                        SSDEEP:
                        MD5:F0D3B33E5A688B26ED6F0A5CF8F73E43
                        SHA1:12A6B4CD1C57BEB97AF0ED6497D42658DB0153A9
                        SHA-256:1849767FFCC708DDEAF5651B9CED03332217E0B1CF401D2E42EC8C5CB021BE8A
                        SHA-512:27297F8949E723EA0988CC484CDC803AC5CB57EC1C3CB4BF4526CB0E5D1D0045E9E34D7D3280F3140DF189EDFFDE338B50B294242C8CCA64DE1E75131365B42B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10688" V="5" DC="ESM" EN="Office.Outlook.Desktop.ExchangeAvailability2.MapiHTTP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="817" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="ullNone" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ullDead" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <TI T="3" I="15min" />.. <A T="4" E="TelemetryShutdown" />.. <SS T="5" G="{d024ae8e-84fe-4491-8801-3b0e647439b7}" />.. <F T="6">.. <O T="AND">.. <L>.. <O T="AND">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1848
                        Entropy (8bit):4.370899785242188
                        Encrypted:false
                        SSDEEP:
                        MD5:4E196EBFEBBE4614513498E6BC64A72F
                        SHA1:254846EB51C5E6EB50AB2B1B5F9F04A55799163F
                        SHA-256:922C52F83B91DA65B1BBB6C29FD62A98A86ABDFA47E400246E7913EFC4D98022
                        SHA-512:FB0763E2EED81CE62675877D15EF4115FCFE798AE62A46E749D0BD167441F4B439478CE1C95457CE232409D10DE3A69FCD61DBF8B67259187CAB29EFDDE9AA47
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10689" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardAddEditErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="blelq" />.. <UTS T="2" Id="blelr" />.. <UTS T="3" Id="blels" />.. <UTS T="4" Id="blelt" />.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <SQ T="8" R="([5][4])|([6][4])|([7][4])" />.. </S>.. <C T="I64" I="0" O="true" N="AddEdit_Error_HRESULT">.. <S T="5"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1270
                        Entropy (8bit):4.868272845617514
                        Encrypted:false
                        SSDEEP:
                        MD5:7ED5436F835CCA784D4AAC7176D507D5
                        SHA1:EDE910B8F99D9D3082388744B409B3AB8C198495
                        SHA-256:1D6FCEC2CCE2F1B75569DCADE796EC7515AF56F5342FAE18F1238F3D16E5772A
                        SHA-512:82318ED33F551F26AB0E4566E5DFD60745A1F933CC61EC13128A667F0FB6E30BC7BCDDD32C73DB55173D3BFDF21BAF70723E300E1C99E63A1805D9668C9FE0D8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10695" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="356" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="443" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="441" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="2">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="3">.. <F N="AutoDiscoverTaskID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="1" F="SSLErrorFlags" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="SecurityFlagsToAdd" />.. </C>.. <C T="I64" I="2" O="false">.. <S T="1" F="HRESULT" />.. </C>.. <C T="B" I="3" O="false">.. <S T="1" F="fIsCaptivePortal" />.. </C>.. <C T="B" I="4" O="false">.. <S T="1" F="fDialogSupressed" />.. </C>.. <C T="U32" I="5" O="false">.. <S T="1" F="CaptivePortalDetectionTime" />.. </C>.. <C T="B" I="6" O
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1543
                        Entropy (8bit):4.556151531652635
                        Encrypted:false
                        SSDEEP:
                        MD5:F119B8FFF9098AF77EA29BD9FC8CF6B5
                        SHA1:DB3B8BF701644AEABD51FBDC0B336DAAD4735C6B
                        SHA-256:859F80F276A22CEE18949EB7D8185293E1A3562955E5D9D9F6B216BB79F19564
                        SHA-512:58B9ED6249E21E4302D1EE0E1AFBB247B410DCDD3F7D797126DD01C1EFE31CCA1E1868C5ADAD1965AF07C4D08DE3C7B92A936F7E72EC024477462D4FF8959FD4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10696" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7059" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7072" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="Status" />.. </L>.. <R>.. <V V="17" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="Status" />.. </L>.. <R>.. <V V="19" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="ClientRequestId" />.. </S>.. <S T="3">.. <F N="ClientRequestId" />.. </S>.. <S T="4">.. <F N="ClientRequestId" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="1" F="SSLErrorFlags" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="SecurityFlagsToAdd" />.. </C>.. <C T="I64" I="2" O="false">.. <S T="1" F="HRE
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1566
                        Entropy (8bit):4.843283995145095
                        Encrypted:false
                        SSDEEP:
                        MD5:154E9AF31A47A39D31B0124DFED37D21
                        SHA1:552D26B92C4DB217935D58AE38CD5002502901E4
                        SHA-256:6BAE353AC2EC6B713FA62931243BCA7A212639FDCF5931B8E536771C0983673F
                        SHA-512:7BC90443EB5642F466E303B78477ECA0CE47871A60B80AE8098093BDBB1F073739C9718DDC4F995F6BFBAAAFE1340B650BE57FAE84D35BC6F8DBE976A5A55290
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10697" V="2" DC="SM" EN="Office.Outlook.Desktop.AutoDiscoverHandleSSLCertificateError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10695" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. <F N="6" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SSLErrorFlags">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="SecurityFlagsToAdd">.. <S T="1" F="1" />.. </C>.. <C T="I64" I="2" O="false" N="HandleCertHResult">.. <S T="1" F="2" />.. </C>.. <C T="B" I="3" O="false" N="IsCaptivePortal">.. <S T="1" F="3" />.. </C>.. <C T="B" I="4" O="false" N="IsDialogSupressed">.. <S T="1" F="4" />.. </C>.. <C T="U32" I="5" O="false" N="TotalCaptivePortalDetectionTime">.. <A T="SUM">.. <S T="1" F="5" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1571
                        Entropy (8bit):4.844163444873834
                        Encrypted:false
                        SSDEEP:
                        MD5:1A6570C846569EDB64B3C40FF7C9AAA1
                        SHA1:69B152EF819A21EB379BB6F2120131F6A5644C51
                        SHA-256:EC8C207232BF2B80E85715BF9E2858F090793A45BC7E7320C4E0292998DDEAEC
                        SHA-512:07BC800E74D1F1F4CAABD64A76B27C18C070BA181EE3468FB3FD3125BDFF7B417821A15A2403323F298B0AB896FDF60DC73723D47DAF36A1D742A47C546C1300
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10698" V="2" DC="SM" EN="Office.Outlook.Desktop.HttpServiceClientHandleSSLCertificateError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10696" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. <F N="6" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SSLErrorFlags">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="SecurityFlagsToAdd">.. <S T="1" F="1" />.. </C>.. <C T="I64" I="2" O="false" N="HandleCertHResult">.. <S T="1" F="2" />.. </C>.. <C T="B" I="3" O="false" N="IsCaptivePortal">.. <S T="1" F="3" />.. </C>.. <C T="B" I="4" O="false" N="IsDialogSupressed">.. <S T="1" F="4" />.. </C>.. <C T="U32" I="5" O="false" N="TotalCaptivePortalDetectionTime">.. <A T="SUM">.. <S T="1" F="5"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2233
                        Entropy (8bit):4.316460563047353
                        Encrypted:false
                        SSDEEP:
                        MD5:95344DF7161F68E0A4D12854F1959544
                        SHA1:ACA58090D347E9665A1EA02351BDBF88AC74AA64
                        SHA-256:B0795BD883E2CB5B3803257110F6739D714996D79B69B9F9D972124C648724C1
                        SHA-512:D3474962DCE44BBCBE03705BBBDC0710CF3A915BB4328476C150D98D780AC3587D7B4B22F9CFAAC34B9722E86082EBB743EE261851B2531DB2E83A3B015D42F9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10699" V="0" DC="SM" EN="Office.Outlook.Desktop.AddRecipientUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ber0h" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="1" T="I64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="2" T="I64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="3" T="I64" />.. </R>.. </O>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):660
                        Entropy (8bit):5.274276796119823
                        Encrypted:false
                        SSDEEP:
                        MD5:F69833CB53077551B90BC60FC4BF3F18
                        SHA1:80718E0A3A3960DBDDCE5392C582143BEBC86A97
                        SHA-256:DC029A990C150D234C0798BE225DB2C437CC21BF25BF32A3A12065A256B52817
                        SHA-512:D837C56DC59D414971F9F6508699F8C0B0895713489FDAF2F7BE11FC9D00BEEFC4F07D71C899CA7FFD7B23F2A1C14F0B737860590734AC8AE63434659B5191A0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10701" V="0" DC="SM" EN="Office.Outlook.Desktop.InAppPromptMsoFloodgateEngineStartStopResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="215" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="216" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I64" I="0" O="false" N="FloodgateStartResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="B" I="1" O="false" N="FloodgateStopResult">.. <S T="2" F="Success" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1718
                        Entropy (8bit):4.595621349152158
                        Encrypted:false
                        SSDEEP:
                        MD5:0059F14ACBDB3A47DD3F422B43FE7191
                        SHA1:84C207905B0A840E03E045DED62047CE636C0C52
                        SHA-256:4A384290A95C54E7D959C38C6F5D1175D3187DE382757046CA28C1DDCCC35847
                        SHA-512:61BD6359B4109B703FC709F16111FA449F692D03007940B0F851BBB11AEAD05903E0C4E6CE8BB2119194529C48C0BA8DCD6F03AF05FDB4002DABE523740402AC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10704" V="0" DC="SM" EN="Office.Outlook.Desktop.MCRP.VisualV2" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="20045" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20046" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="UIFlight" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="UIFlight" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="UIFlight" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1602
                        Entropy (8bit):5.060767159898663
                        Encrypted:false
                        SSDEEP:
                        MD5:BC003388DAD4124BC2E2F0A6DF013D42
                        SHA1:2FD87593656A42B45AF294BE3D627631C9F17E9B
                        SHA-256:577B254FC1083648521747D25F3194FABB3A237616A786EB0155904AE68BAB91
                        SHA-512:82A2A9D14FF7CE9C766D8226B9951733BD6EA8B7C7FDC21110B92B1C3C7B588B2A2FAACB41DBDCA3168E14DAF0A065F0D626B45AAA0CBC6324BDBEAEF7B64DF8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10705" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentImageThumbnailGenerateCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4236" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4237" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4238" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4239" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="4240" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="4250" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="GenerateThumbnailStreamExistsCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="GenerateThumbnailMapiNotEnoughMemoryCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):488
                        Entropy (8bit):5.300184761134992
                        Encrypted:false
                        SSDEEP:
                        MD5:431C1799C52DBCBB3862D1AADB2D382F
                        SHA1:1A1D5EF7C90C59352B10BCCFD7B8CED1439E5F98
                        SHA-256:A83F9B3DF1535231BB64C5E96DCE7323C2DCF181A6920625B9E2DED84ABB3A95
                        SHA-512:63597167F5016977253CC30DC90733C797891FD5277F00635FAF3B8672050CCD550770BD9AB8CE0A1ABF84D928175D25E6882E290A8F12CF5674D3781B6CA0C3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10707" V="0" DC="SM" EN="Office.Outlook.Desktop.POP3.InvalidPopBlobExceptionReason" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1000" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. </S>.. <C T="W" I="0" O="false" N="InvalidPopBlobReason">.. <S T="1" F="Reason" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):975
                        Entropy (8bit):5.1291781033179324
                        Encrypted:false
                        SSDEEP:
                        MD5:17F9F4955A2B3C72AB6D61D95AA4BC05
                        SHA1:306A0E2962C151CB17CBDC54B34985231F99ABAE
                        SHA-256:A4E3DAC9C4EC740C6DE965BEF0B3A60A47647770FC9FFB81719B0E1B173FD415
                        SHA-512:1530E79B248C5717783DFF0760F3FB95C1124E97FF2D9E4825416260D071E19468FC8CB590A402A36CD2395A0B73E7A7CA108D97D273D653D416AB07A86C6375
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10708" V="0" DC="SM" EN="Office.Outlook.Desktop.POP3.InvalidPopBlobExceptionMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1000" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. <Etw T="2" E="1001" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. <Etw T="3" E="1002" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="Count_InvalidPopBlobException">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FailedToSaveResTag">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_FailedToReadResTag">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1027
                        Entropy (8bit):4.470901556113302
                        Encrypted:false
                        SSDEEP:
                        MD5:59A3740357D8EEFE69FD938E54ACD0EB
                        SHA1:2F73688861A9C1820E78D5B003F4FF757F6BA1E2
                        SHA-256:88795A98DB9351DB0B25BC712BF496CA88AC379A21CC28B951BCEEA372D903FF
                        SHA-512:CF1516609A9095613FAB290D9AD043122F912AA1CFB771097626CC78E83334B64DAA9EDA2D922E456AE8FAFE0B448E08E9D0323BA92177706F4D167C515E0E62
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10713" V="1" DC="SM" T="Subrule" DCa="DC" xmlns="">.. <S>.. <Etw T="1" E="6028" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="CallerKeyword" />.. </L>.. <R>.. <V V="MapiHttp" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="NewState" />.. </L>.. <R>.. <V V="2048" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="3">.. <F N="CallerID" />.. </S>.. <S T="4">.. <F N="RequestID" />.. </S>.. </G>.. <C T="FT" I="0" O="false">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="3" F="ConnID" />.. </C>.. <C T="W" I="2" O="false">.. <S T="3" F="ClientRequestId" />.. </C>.. <T>.. <S T="4" />.. </T>.. <ST>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1032
                        Entropy (8bit):5.040346653370313
                        Encrypted:false
                        SSDEEP:
                        MD5:FACF9E5E5EB7B519B506F47A1F27E96D
                        SHA1:619683A978789BB1070F13CAD9C6CDACBF8804F9
                        SHA-256:44F68E3087B4BAC7C4C3275A87AF55D900AB8D38CA60FBC33167C6C54F6BA43D
                        SHA-512:1D1E6053ACF29CD0FF4959DA53A268D2631F39C39C34CEC73B989A2BA85E7574B247932CEEDDF518894682362D02D1D2E578CA3357353C77B134A9E67C7EC63B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10717" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataDetailsErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3476" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountGroupsDataDetailsError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):699
                        Entropy (8bit):5.128210137833051
                        Encrypted:false
                        SSDEEP:
                        MD5:DC99ABE1F69F3E7D1CCEBCD2ECCC6897
                        SHA1:A6DB1A637790B4F54EAD8DB3149D4099BE6C744E
                        SHA-256:F3C033B04A5E3EB0D524BE8C76F7F4B0A3E6BE33F248B749C45390550CE7A5FF
                        SHA-512:20F3D1F5F287B05B2128767935E9D4EDAE01D8F2AE243B30CAD2CA29787BAB24D9B873D5CA956558EAC412D71529F256F112D3D5CB35468499DCF452E8E5B8BA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10718" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataDetailsSavedServerCall" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3478" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FullDetails" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsFullDetails">.. <S T="1" F="FullDetails" />.. </C>.. <C T="U32" I="1" O="false" N="CountSavedServerCalls">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):698
                        Entropy (8bit):5.159252596670504
                        Encrypted:false
                        SSDEEP:
                        MD5:23913A0C3E7E5610AA204F35449EA3C6
                        SHA1:74C6A9F7D6E3D181A8758D33822F1EC14DC23717
                        SHA-256:D20CC196666CB34A28921C12F5D5BA0B75CF341500346CD0263C2D1E7FC37633
                        SHA-512:073D78C05947E9C7514F51220FA3DF16C4B8CAFC768B317DC386AC8C2ABE15139B2837BCFB4FC9FA054B17A1249C5161180E6FCF82C16BE16AB418549EC16FE8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10719" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataDetailsRequested" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3477" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FFlightEnabled" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FlightEnabled">.. <S T="1" F="FFlightEnabled" />.. </C>.. <C T="U32" I="1" O="false" N="CountDetailsRequests">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1027
                        Entropy (8bit):5.024812970941374
                        Encrypted:false
                        SSDEEP:
                        MD5:702AC93C98BF3C733E134BBB99DFC78C
                        SHA1:D930A9F72972D98210E4A63BFC249E3EF8695A28
                        SHA-256:2484353F9EBB44241D1E70114C2DF411275D61914D9808D7D300BE6D7386216A
                        SHA-512:D0080B95395ABEA0C815A54D16FC8FE69AECE9169B5CB82FE3DD0DBE43BC03EE3E2A03C47CDE3E3BB5FB2BB7B3D8362F308AA1FAD5C69C3A2C879529DDF4352B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10721" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataContentErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3451" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountDataContentErrors">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1030
                        Entropy (8bit):5.0477112915064195
                        Encrypted:false
                        SSDEEP:
                        MD5:9073D8E495CE954CC1101F3715B4716A
                        SHA1:11B60AD602D97CABA662ECC224566B32F85C28D5
                        SHA-256:EB6AE0CBCAD4549D1F96A19042A1FDE91E17923C96A6DDE753F3B2BFC642FD37
                        SHA-512:1DED90125D4F3222846B05C0CB502403E92DE167ACA97E18965EEB5D9850D64C0038237749451D7EEC97D7661F643BAC72D3EEF9C358FB97980F002BB99302C3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10722" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataJoinedErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3351" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountGroupsDataJoinedError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1232
                        Entropy (8bit):4.655188184670387
                        Encrypted:false
                        SSDEEP:
                        MD5:EDA75561B8C19B4C4D92BEE6AFC98DC9
                        SHA1:5ADC7790F2EF746B0804A84B4D1515FE5B38AFDB
                        SHA-256:83B64EE2E5566C773FBD564EC6EE4CB1AE70E7C2E0900D889701D396298E297B
                        SHA-512:0AF4C19F220325D117DF33D2A03AE2B14D9DEDB105724851A70E6665832C6A8A5348ADAB1AC5D6D210A95F89AF1EC95158DB265C670E6E1BB3A7FE46A93D19F6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10725" V="0" DC="SM" EN="Office.Outlook.Desktop.ClassicReadingPaneLoadStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10726" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </F>.. </S>.. <C T="U16" I="0" O="false" N="CountOfTimesFullyLoadPerfEventTriggered">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="F" I="1" O="true" N="AvgFullyLoadPerfTime">.. <A T="AVG">.. <S T="4" F="0" />.. </A>.. </C>.. <C T="U16" I="2" O="true" N="MaxFullyLoadPerfTime">.. <A T="MAX">.. <S T="4
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):688
                        Entropy (8bit):4.652872274228483
                        Encrypted:false
                        SSDEEP:
                        MD5:5AA209B1409D10B0EA859A20F1F582F6
                        SHA1:B6C5E62A13EF2D372C3FDC97AFF9CF85563A6503
                        SHA-256:A367E3290DCCE6C50E5C976188C19327378F40A78BFE159597102E74F2A5C557
                        SHA-512:BC061738C0D3858DB8C28A6D2952F858C25E82E2B920A2265490707D09CE1F1662C3289F1066E94E65D2520485CE53179F209C8E433AAB47A59E0B78061CCADA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10726" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="6109" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6110" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="EntryIdW" />.. </S>.. <S T="2">.. <F N="EntryIdW" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1144
                        Entropy (8bit):5.06980741556941
                        Encrypted:false
                        SSDEEP:
                        MD5:B91E06D9D66C4ABC56382A42E3A1280F
                        SHA1:754A56A921CDE2E6981910B32211B15EC514C0FC
                        SHA-256:E430F9004AD25E89903ADF485937FD4AA6ED8196613360EB975D0B0F87641A4F
                        SHA-512:9F5E66D2BFDE32D3D3D0B278A2A80D87BAC476464BE8086774BBACC4730160464D1015390761CDA7276B30A4858F7C82F21DEC7BDCF2B137B553C74887953CAE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10729" V="0" DC="SM" EN="Office.Outlook.Desktop.MCRP.ThreadWhispersInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="20048" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20049" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20051" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="WhisperRendered_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="WhisperClicked_Count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="BacklinkRendered_Count">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="BacklinkClicked_Count">.. <C>.. <S T="6" />.. </C>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1126
                        Entropy (8bit):4.879603911423696
                        Encrypted:false
                        SSDEEP:
                        MD5:765B7B60BE6DF7223942AC314F56B1B9
                        SHA1:BF5330C9FC17AEB8E4D198BFC6C4C9D534ECC01C
                        SHA-256:885475B97150C479CEA095B07DA88E71BA6C8C49248F3F83889A560700B45051
                        SHA-512:C37E192A60EC8F35309D85A2FC3DAC978C170DDE8D3ADAA6E514B69A6CBB8C8F3A2CDD341220D1D8CCD186B878CAED5BA773AC748E219549B84EB5FA27C4F808
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10730" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.HttpRequestResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="HRESULT" />.. <F N="HttpRequestKind" />.. <F N="URL" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="HResult">.. <S T="4" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="HttpRequestKind">.. <S T="4" F="HttpRequestKind" />.. </C>.. <C T="W" I="2" O="false" N="EndpointURL">.. <S T="4" F="URL" />.. </C>.. <C T="U32" I="3" O="false" N="HttpRequestFailedCount">.. <C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1685
                        Entropy (8bit):4.562340878031908
                        Encrypted:false
                        SSDEEP:
                        MD5:B57497B3C1004D7720671FE752879557
                        SHA1:34E9DD2EFD4AB25712FD7AB620587CCFCA8505FA
                        SHA-256:17FA34811E4D8DF37ABCB06918CE50D735913492370CD810BDB347580582B011
                        SHA-512:A28F87BB0ACF9370FBBE223946F49101647E14DEAB68DDD991FCB0F895637101E98498B4B1FFE8FD4C13B48F823CE6699B3CB347F5C3D6A5D339445C72DA9089
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10731" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.OpenHelpShiftTicketResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3773" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3774" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1038
                        Entropy (8bit):4.724554991273104
                        Encrypted:false
                        SSDEEP:
                        MD5:E2B2476E614450B94D9620FE839BF4B4
                        SHA1:52E74D9E382574C0468B4D5F5C4A7D51B8ACEFCE
                        SHA-256:8C86D10255B75C82417B327AA7805C71F1E39B73A59F1F3636AFF55B6DCAB40E
                        SHA-512:ABFFA0115AEBEB8F256C0C45E66FF9C26D24276D08E5FF7D54507E9A81F88F45DB03041488CA49C55CA7741E35DF8579AF0EADB6D557F04D075DBD979294B71A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10732" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.HttpRequestResultSuccessFail" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3772" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="HTTPRequestSucceeded">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="HTTPRequestFailed">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):758
                        Entropy (8bit):4.70014845671891
                        Encrypted:false
                        SSDEEP:
                        MD5:D6DA2A20557ABDE506656F567B9449C0
                        SHA1:78D9920B7DA9F28558973F40352E047792269B21
                        SHA-256:B5A707A403CFC86C04C411A81DF57C2CA949684A703C81EA63F2A9DD7CDE0F58
                        SHA-512:6013074491CA816CA6C1A7034FE7930AD17FC1F2388ED2E0D9ADED77F95C6C2F541EA2B9412819E47BFC2423407821F3403F8BCDE5508FC50AA065393A8430BD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10737" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="20004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20047" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="ConversationIdW" />.. <F N="ThreadIdW" />.. </S>.. <S T="2">.. <F N="ConversationIdW" />.. <F N="ThreadIdW" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):775
                        Entropy (8bit):5.149938745161758
                        Encrypted:false
                        SSDEEP:
                        MD5:3A35D76F3A8F716B547B54AA227AFA3C
                        SHA1:7C44BF0F2686ABA6ECFF14C73B1422A2023C851E
                        SHA-256:30CF20A2269F920756A7D20A2B649BF087F2B8C55217AC9BB9AAB5D59BF55182
                        SHA-512:4EFBD8F8FBD6852F51C5397C005CE005B7B7C4D2C75183D818EF32C627F8B1C5A922E2A4A04B0A1436BA90C9D10020B558659EE642612355B5C13A0468C07642
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10739" V="0" DC="SM" EN="Office.Outlook.Desktop.SchedulingAssistantZoomChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="355" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="356" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountSchedulingAssistantInitializations">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountZoomChanges">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3228
                        Entropy (8bit):4.247067069050775
                        Encrypted:false
                        SSDEEP:
                        MD5:C9650F76052C1626BFAE4C0E2A22A812
                        SHA1:FD854A3A1F28CB50A24B4AEDD2156D158456EC62
                        SHA-256:517D86C14935F3ED9A72602ABDEFC275663F4AC6FB863617C8126FD695685D1A
                        SHA-512:9A3C45B58376590A5A37FE092EDF46BB3F65A34EA11EF07C041CDFA5BF607BF914A4F0DEA0709E91BC8D6B7233F8FB77956F3204EDC8964D60DD11553DA4098F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10740" V="0" DC="SM" EN="Office.Outlook.Desktop.EmsConfiguration.ResolveNames" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10684" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="6" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GE">.. <L>.. <S T="1" F="6" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="5" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="4" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1654
                        Entropy (8bit):4.554017495890807
                        Encrypted:false
                        SSDEEP:
                        MD5:CCBD4BA6FD3CE83A50A03D3FA380820B
                        SHA1:27E9AA847B689DD9D065914D84D9F66B4D6D0909
                        SHA-256:20E62A24204252A81F29378EFEE18DBEBF0680D0FBD60C0FA9D278786158A355
                        SHA-512:03E92B546EF16ED5405DF364869F2D199188D545C13148C7909CB6D3C4E13462179276DD76B45C2CE758D3C43F0E01D921B374375F8715C6F18163F95F2D3584
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10741" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.SARADiagnosisResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="17" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ResolutionFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ResolutionFound" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="NonEmptyRootCauseDescription" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2051
                        Entropy (8bit):4.021274365490137
                        Encrypted:false
                        SSDEEP:
                        MD5:F7EDEDFBF2FC81D57452BC1389AB1824
                        SHA1:B6FC44494F3CD8BE8142642EA6D1E567FE545E99
                        SHA-256:A4EE086DB47F26AAD4CD2EC67EDABAEA35B82A2297DDE1E4CBC6656EF8B3D21C
                        SHA-512:85C201E6CAD9DFD92AB4112F810D2F0D454A0F7431533842BC5A33E2F6A5C386A5F6FB0FA28AFEB24F01DAC355F8662C9B8B400CB2E5157391032DF6CEF9EB92
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10742" V="0" DC="SM" EN="Office.Outlook.Desktop.InspectorVerbStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10743" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):4.630679580795938
                        Encrypted:false
                        SSDEEP:
                        MD5:5CAC2B8B663329D4F4B71EE341068B7D
                        SHA1:18C302FDDC261BA7AE68C6683EAAA335BE8F4ABE
                        SHA-256:19F1142A05C036E80A4958E68CAB8B8D3B46D83767A68289BF131449AB9DFB65
                        SHA-512:BD915CA197DBFDB060F6AA56D070818D72054D5536C1AD60D807905CCCDDEF9EAB19A1C2C4D213D88EA3A96BA4C3BC2F2753E8716B7465510AD1FE58CAD64232
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10743" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="6111" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6112" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="EntryID" />.. </S>.. <S T="2">.. <F N="EntryID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="I32" I="1" O="false">.. <S T="2" F="Verb" />.. </C>.. <C T="I32" I="2" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1151
                        Entropy (8bit):4.825890710775881
                        Encrypted:false
                        SSDEEP:
                        MD5:7B714825A1E78CC5348D249A411FF3E7
                        SHA1:7AF6AB375BC8BD26858A0409FB0E7D839C090A47
                        SHA-256:7B2AA7D4B000D6C4EEF353E84C8C6056061123B4B11F5BF0534F88DE1CDE4CE3
                        SHA-512:9A27DB1C1F0E091B0C88A0EAFE263445148E8553B358A1D4B7A0970523E26E2A46708343C64D6B34D3AA16B60A85923FCF83970A282C8E2C680B6AE98A277C19
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10744" V="0" DC="SM" EN="Office.Outlook.Desktop.UnsupportedHtmlTagsInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="4204" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="323" G="{bb00e856-a12f-4ab7-b2c8-4e80caea5b07}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="HasUnsupported" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GT">.. <L>.. <S T="4" F="unknownUnsupported" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="UnknownHtmlRenders_CountInNotModern">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="UnknownHtmlRenders_CountInModern">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1655
                        Entropy (8bit):4.541476459013172
                        Encrypted:false
                        SSDEEP:
                        MD5:9344BE5D8457F75D478A00C82F9946E5
                        SHA1:AA2AE901819CCC0EFA809B6FA9731769089FDB50
                        SHA-256:746DC7F2E803E846F58CB7B27C086A0E26B7A80A502CD9D859AEB1610CC61C0D
                        SHA-512:23BB8DEEFFE4C9AC8F7B507A52B4C611A58D81F9D0AB21417114CA3C4ACBB5BD9846251B3AE38350B4BBB4978308BF563233D7AB66B79D99786AFF389C83B83F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10750" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.GetETLFileUploadURLResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="24" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ETLFileUploadURLRetrieved" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ETL
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):5.086988211731638
                        Encrypted:false
                        SSDEEP:
                        MD5:B34CAD4A18D3477263505F28C73B1098
                        SHA1:0A271C6D985BAF4D62020264A09C5171E79FEB97
                        SHA-256:7428F9F31B1C238B5C063BE77873B158B7B1EA6A8B7CD9B3060DF131037A7DE5
                        SHA-512:393F07293B4B811B6D9CF5EA1E718E4F6B0BD52516A0657A1F92161930F5B8223F6BCA678EEEE8A630F6CF374B98026758791379E0D43E2C5E14D8ED363ED8E0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10751" V="0" DC="SM" EN="Office.Outlook.Desktop.Subject.AtMention" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22200" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22201" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="LaunchCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SelectedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3027
                        Entropy (8bit):4.253812969954003
                        Encrypted:false
                        SSDEEP:
                        MD5:F481EE9288B0A9FBDBD2E410DC3C8354
                        SHA1:1E2FA600CC09A3C75F2F2EEBE2C299091E78D26D
                        SHA-256:5AAFBF18408D48B368FC3EA8E757DF8713E6FE3D8B248D0C0F6124E55CF50DD0
                        SHA-512:EA8293F1B0854BE3AA14189CAC744A93B20EFF57EDC1245EFF246ED2D564E08D6899E5210576DBF091BD8111C489E981892F0247DE96E25C31224014502210FF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10754" V="1" DC="SM" EN="Office.Outlook.Desktop.NavPaneModuleClickDistribution" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3204" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleId" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleId" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleId" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Mo
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1184
                        Entropy (8bit):4.706862813147077
                        Encrypted:false
                        SSDEEP:
                        MD5:557669BBCBE6E9D9B2221B57A754ABFA
                        SHA1:5323F9A426F9C2D7DA645D84AD003F4CA2E56B37
                        SHA-256:5A7FBEDF0579791EFC64B4E8995D0C1652632C3BC843BAE40066E649EB221245
                        SHA-512:8E3D7DC6445E5E19BCEAF67581CB2F9045B7219395D9266B6841B30F7B338D04AF68CA1203602BE9C8D121567D8BF7ED7E536078093CBAB0358C5218F55660CD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10755" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.UploadFileResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3777" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="ProviderType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ProviderType">.. <S T="1" F="ProviderType" />.. </C>.. <C T="U32" I="1" O="false" N="FileUploadSucceeded">.. <C>.. <S T="4" />.. </C>.. </C>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4053
                        Entropy (8bit):3.836061934703254
                        Encrypted:false
                        SSDEEP:
                        MD5:84CEF52ABA34364BB85B0F3AD2C2CBA5
                        SHA1:271185CCF86F4A64209F085D8DB18AB44F160F10
                        SHA-256:B3E9900C287721A7AAAC8A13A6E879AE71D8E46DF738A3D42BF4F8427A140C26
                        SHA-512:3EC575C7CD421F484A02AA5A995DE481F71BF2751D80496345604679FB1C8B08C490731987C01A9B1A3BFF9E146F8AF2066C4842A779F5121FAB43AF3483C505
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10756" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.UploadFileTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="25" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4130
                        Entropy (8bit):3.900669303722967
                        Encrypted:false
                        SSDEEP:
                        MD5:60786B80936C9644A9B6A50192307428
                        SHA1:3B73B41BC2F4F231AA0217E56506E4D889F6F871
                        SHA-256:D1B3C48AD31F2FF5AAC4001E1B57ABA19ED1FEDE5EBABA948DE5318AF7B0F716
                        SHA-512:F4D1BBC08D54B41459A6AE1E8F268A33D552CEC8F2727DFF13149F5B841283B97DDD05096606A7CB5F6F520D58FF826D43BB29BD2C53A1CCFBCC3AA44E9CD957
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10757" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.OpenHelpShiftTicketTotalTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="14" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="5000" T="U32" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6421
                        Entropy (8bit):4.217545078480636
                        Encrypted:false
                        SSDEEP:
                        MD5:99A376E93471334EC88A6473602A8659
                        SHA1:E77FEE174CC5B13D26A233A02605F0E9F4093A0B
                        SHA-256:69F269B5CFCC9D7266600262032DB238D67F6F405098F8B7B1BF1FF4E4E4C11E
                        SHA-512:47E647493A538799F292EEB05265D08D2B04B9144717C0560408BEFD229E0E0ABC691E478A0E875E115A3D2E9BCAD8ABB585960F12BCE8E7D9033AADB1EA66A0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10759" V="2" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetAcptRcpt.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="357" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):909
                        Entropy (8bit):5.091434923170552
                        Encrypted:false
                        SSDEEP:
                        MD5:E77476C1500E35E9BFCF41725DEE327C
                        SHA1:62695740BCA5F20509D97B095F116912C758E578
                        SHA-256:898366B722C3FA76D9654F99C7C68BC32678723ECDC2529E0D9230080753EC12
                        SHA-512:E0D0C70F91AFDEA3C463FB04410DAEF156AB10C2E635B4F7CC48B33AA083369F524791739C70831D886857C122C2C3EDAFCA15A88C388528BDE87EC4A0C6A488
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10760" V="0" DC="SM" EN="Office.Outlook.Desktop.AddinsLoadPerfInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="147" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="214" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="3000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="LoadedOnBoot_Count">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="LoadedAfterBoot_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="F" I="2" O="true" N="AvgLoadTime">.. <A T="AVG">.. <S T="4" F="DelayTime" />.. </A>.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):718
                        Entropy (8bit):5.05355657164101
                        Encrypted:false
                        SSDEEP:
                        MD5:BC16F0A276623F9D01DB0761CF81ABCB
                        SHA1:37E9847C1A350ACE7CF348C46E8B5C224F1930E8
                        SHA-256:8712FA85D202A75CB2DC661B31EC7C8A910107A84C11D93794DA3C5B0E816197
                        SHA-512:F54BA27C648DB9D5ECDA0BEF5BB51EAE537FC6A16FD206DA5A1CE681E3DC4F3173CB7B81193896AD23054BD058F249C25B13204C56D3DC0E3DF5093EA4C5B0FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10761" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsWebRefPaste" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4242" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="1" O="false" N="ResponseCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):5.058525313468289
                        Encrypted:false
                        SSDEEP:
                        MD5:7AD05071AC6E15295D633092EF954AD0
                        SHA1:F65C5A7DE4AC38AD5DC9003EE611EBA758411285
                        SHA-256:EF14C8A6ABBC342594D2E19F0C52EFD1504627E0C4C6B52BE4CC521D54A80227
                        SHA-512:1BD0DF7E8FE190F317ADAC27C6CB575084C1F73558F5A930E76CE2B06FC32570DBD1ED3D069CC7C1A4BA4603C26FE85FB4E7E427DC38F4A9B026CF9F0A134D99
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10762" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsWebRefSaveAs" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4230" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="1" O="false" N="ResponseCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):5.181057119492566
                        Encrypted:false
                        SSDEEP:
                        MD5:A5E250615511D18DC0ECD4A023B28334
                        SHA1:92DAA4795C76E82BE0B5A8B515E64A05C423758E
                        SHA-256:F74148CF462583CFE1B5A629BF3E1DC571F5465C616C00BA3F94201C50E0A7A2
                        SHA-512:32084EC602802D333A8DA88CA1E72B4418829D030E06779CED439A0B73065447F4EAB7AFCAF13CFB42462E9D588859A8A0D73E8D581745B10C0CCEA550FAC93A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10764" V="0" DC="SM" EN="Office.Outlook.Desktop.AddinsDisabledStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <C T="I32" I="1" O="false" N="Reason">.. <S T="1" F="Reason" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):580
                        Entropy (8bit):5.170919110449742
                        Encrypted:false
                        SSDEEP:
                        MD5:B662E3D027D5B732A2C86143A22A71DE
                        SHA1:5530D7AB14C74BF065C6E30C4C8F837DB63B3FD5
                        SHA-256:BEACBBA66AB2535012CA69C65A85A71A302D21A8EB23BCE7E6055CBD0F26F432
                        SHA-512:FBE77C1B964B2063C9D206A2C849FDF161A9D94687286FBF7EE443A598D9098284E11DB498B9F87997879736666931505CF1E24AF2FD7256EEF80CDFF90CC6E1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10765" V="0" DC="SM" EN="Office.Outlook.Desktop.AddinsRuntimePerfInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="3003" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="true" N="ExecutionTime">.. <A T="SUM">.. <S T="3" F="TimeElapsed" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):582
                        Entropy (8bit):5.203905853647658
                        Encrypted:false
                        SSDEEP:
                        MD5:F6A40762C802CCE35020135D6FB88944
                        SHA1:F62D99C1FF4BA3F63BFB84A87A9A9C8F5EBED36F
                        SHA-256:DD4EAB916F872602D70421ABC4D5967077F687C6AA11387F90BF08ADCD2056D7
                        SHA-512:F77C456FAFA56B27981AAC66A1948F9918EEC815B177D98B5F993832413992467332462EF0B8FC9600C21D7780069E63FB51A2EE38D67CE37665ACC5BB1435EC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10770" V="0" DC="SM" EN="Office.Outlook.Desktop.AccessibilityCheckerUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="15010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="AccessibilityCheckerClicked_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1115
                        Entropy (8bit):4.641491901940376
                        Encrypted:false
                        SSDEEP:
                        MD5:6D65E5D863EE2A8D3BA656EBB7E33162
                        SHA1:719966BF569DC04DF10652209916480AD76DB202
                        SHA-256:72677F75CAA3D73F33D8F5F84B0E7BF2933596E7FDD4149A19F0857C81748FF2
                        SHA-512:D493AB00A03154E8D747BD56F0E88D03B91085B64F45AA4B607A58B176281492D0301AACEF70AF497C06AF5F817E86329949AA00D2EA468473AA976AF4E67881
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10771" V="0" DC="SM" EN="Office.Outlook.Desktop.DeleteSuggestionUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ber0i" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="DataSource" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="DataSource" />.. </L>.. <R>.. <V V="1" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="DeleteSuggestion_DataSource_0_Count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="DeleteSuggestion_DataSource_1_Count">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="DeleteSuggestion_Total">.. <C>.. <S T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):609
                        Entropy (8bit):5.258518464171147
                        Encrypted:false
                        SSDEEP:
                        MD5:3ED6266889B063E8256FD55CF83BF496
                        SHA1:8C9C8DB4623105F2A1EBF241601C6FE6C3DB558F
                        SHA-256:95B8508F090313E3B5A788AAA657A2FADA6CA9E3A72BCA3EA83F043839903E2E
                        SHA-512:E91DB169E46FA13598EFEB1B33C4DEF800554D43E7072C24E9D293A8BA57CFA8F91B0F473C23EE22BA2D21F83A3DBEF062F0B053790CC7BCFF013D1C2AC77097
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10775" V="0" DC="SM" EN="Office.Outlook.Desktop.ConversationLevelAttachmentWellErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4247" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ConLevelAttWellAttachmentsCountNotEqualToExpected">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):537
                        Entropy (8bit):4.771450186310447
                        Encrypted:false
                        SSDEEP:
                        MD5:D0641CB4093402E90C9C3532A33B1461
                        SHA1:9231742E8E259F243E49035FE4DB6CAE97592F3F
                        SHA-256:805B2B64EB1ABA039585CBB2FD29D831DE7C9270A8575E1E4DE87F4362F7541C
                        SHA-512:270788BA78960F78AA9113949442F40F6ED43E3771903E68D3A5BC819E3342D63A188BB68E62B7E808BD2D63F8F2B415723D76F880BACD83D6D99D5CC1E97798
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10776" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4248" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4249" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4266
                        Entropy (8bit):3.640353454574905
                        Encrypted:false
                        SSDEEP:
                        MD5:04194346E4EDEE758102130EF0D59C2A
                        SHA1:40711DA4CB2B8C923D30F0DA89ACAC7303FC4092
                        SHA-256:6F7EF4CF703ABD1A83B346A214B65CE48A3D890D7DAA9B448610472D76BB17AE
                        SHA-512:2946250C0E9FE5AFD712349AF745AC33E6C2075484C16CE5FC0E7DAEB98A0A25C8CFA228399FBDDB94E4030CC604F9F0E20BAA8199E8CB513EFB6D07E351F304
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10777" V="0" DC="SM" EN="Office.Outlook.Desktop.ConversationLevelAttachmentWellPerfUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10776" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="501" T="U32" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):15109
                        Entropy (8bit):3.872226608992995
                        Encrypted:false
                        SSDEEP:
                        MD5:0C0B628026DB23C2D486CE636331F8FD
                        SHA1:6989EF24F273EF3A7F5D1C0D34D37DBE83D6BFF1
                        SHA-256:F807DF0A8B6E0DD2EFB6AA94420023497DBCD3D5D7CF30742EC042B750F87482
                        SHA-512:4BC7184E0607216AD4D6734B127F0760E791C04AAD941F9160DDC4B00A1FD15A6AB8A3D8882C6454BE5D49257705D6EED22ADC15D67FBA0458596F5DD16A8BD3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10779" V="3" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsLogonHelperResultsStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2066" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147746077" T="U32" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):479
                        Entropy (8bit):4.329435177677775
                        Encrypted:false
                        SSDEEP:
                        MD5:6F934C775A771C17017E8BC2085D9A37
                        SHA1:84B8A31BE7DF60E200DA64A5C3CF9960D0A2F636
                        SHA-256:F0A4C86159BB76DBE5AEFA4ACBD458603FCD36DC672F5D40178B3A7FFE034924
                        SHA-512:F159A83ED11531EA1B3B357947763FE0C053D3E3DF12E5B6C32130D764067748322E7E5A73003AFD7147F682951E6F1A23526B7F8BA227FE1DD4A809525C870D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10781" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="bgo4t" />.. <UTS T="2" Id="bhlvy" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):536
                        Entropy (8bit):5.1310885117643315
                        Encrypted:false
                        SSDEEP:
                        MD5:0613F23EDDFDC6270B9956260403689C
                        SHA1:D6CBEB4F9D71F9223B4CD7E8DE4A074CBF08278F
                        SHA-256:4499CC092E419610F334A50A500B305161AE68DFAC88DC4E42B233DDFAD0CDB1
                        SHA-512:908206151F6CDB44FFA4C25EE7653CC885B807FFC318D0FD900D65BE028327894A9C6C16F8540EFDC399FE0CD7318640E2CAB0D42343D8B2FE2A721E6F6B6D1A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10783" V="0" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompleteZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bg085" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfZeroInputSearches">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):4.825673007247234
                        Encrypted:false
                        SSDEEP:
                        MD5:478DA0EDAF828CE7FAD17CB9A41C741E
                        SHA1:09BF669F108E10E6CFA738C0FBF01612647D5C5F
                        SHA-256:8737205FE766B0B5529AAE314794BD4BB4B1EA7970257289C14A26C54EA97091
                        SHA-512:9002600D2E10E95B9DAF3347F0765826A1248B9D6C776910441C42C4CAD7DAA15F05B1E2B4340D6E91A79BC7E71D47F91B65CFFBE8B535C1FFD2ED5E1085175D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10784" V="0" DC="SM" EN="Office.Outlook.Desktop.PeoplePickerSelectionStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10625" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="I32" I="0" O="false" N="AlgorithmVersion">.. <S T="1" F="0" />.. </C>.. <C T="I32" I="1" O="false" N="SelectedIndexPosition0Count">.. <A T="SUM">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="I32" I="2" O="false" N="SelectedIndexPosition1Count">.. <A T="SUM">.. <S T="1" F="2" />.. </A>.. </C>.. <C T="I32" I="3" O="false" N="SelectedIndexPosition2Count">.. <A T="SUM">.. <S T="1" F="3" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="SelectedIndexPosition3Count">.. <A T="SUM">.. <S T="1" F="4" />.. </A>.. </C>.. <C T="I32" I="5" O="false" N="SelectedIndexPosition4Count">.. <A T="SUM">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1428
                        Entropy (8bit):5.043679177232869
                        Encrypted:false
                        SSDEEP:
                        MD5:0BF7A0F1043436AFA1F662F919AFEFEE
                        SHA1:C39E9308756DEF1827EA8347CA5C67C6EC836E8D
                        SHA-256:945B700A9642AEF2F81993D5997326FB89C4A2C1861020EE642728213B23E90E
                        SHA-512:6709750F32CEFF8119313540A1E03D9799EFEC0D831B98400FD54110876DC5DF96DAE70AEC5611C3BF23634C56392FB4F9B8B49DF70D6634CCF9FF814B0E244D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10787" V="1" DC="SM" EN="Office.Outlook.Desktop.ExchangeInfoStorageStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="819" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="820" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="821" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="4" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="NumNewConnsAdded">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NumConnsRemoved">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="NumCallsToGetAllInfo">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="3" O="true" N="MaxNumConnectionsReported">.. <A T="MAX">.. <S T="2" F="NumConnections" />.. </A>.. </C>.. <C T="U32" I="4" O="true" N="AvgNumConnectionsReported">.. <A T="AVG">.. <S T="2" F
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):5.045465152145595
                        Encrypted:false
                        SSDEEP:
                        MD5:BB2534A5BB291169F1A47B95B96F879D
                        SHA1:2942A1518DB2266A5E9E83D066B851C6417125AC
                        SHA-256:830000B921E320A79B8DEBACC33383AB056293EC85B8EC97B701FFCE6C3E6677
                        SHA-512:7C89E12F542F37049DB1C0E114D38D9775FAA8014B4F26CCC16CDEB03536B417E33CD8E11133435B9752B1FAB8A7988584CE0A04B01F955506C238E144EA3C6E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10788" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsApiErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3201" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountGroupsApiError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):5.036294966960726
                        Encrypted:false
                        SSDEEP:
                        MD5:BF4C580CAE133A50DC3B0E62DA4EF22C
                        SHA1:F0ABE04914A9D13CF4677B5B27CD1BBB8DB78110
                        SHA-256:3828D7A7183C1514FD5A7CB95C10CC3942EF5ED5837DA8560FA8F75542375BA0
                        SHA-512:B0BE7BA07CC0999DF0DECC8FCB26999E33800DBFA852B0CF2FBC81961316685AC72985FF19EE72D8F7DE8EBAED26FCCC4991634F0B21DD92795FC3140C8FC1FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10789" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsStoreErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountGroupsStoreError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):937
                        Entropy (8bit):5.023117170680329
                        Encrypted:false
                        SSDEEP:
                        MD5:A8D2672E23073CC74A8274A294552FA1
                        SHA1:BB2DC7DF6B69B243F329C0521BC06F2E928556E6
                        SHA-256:20A4BCF7780D0831FA6E0BE12211380E5EC9212F7B439CD363B4FA6A7BDA0539
                        SHA-512:C110403C997FAB7B75C01637286E1232CB817AE6D6D4E589B3D59D9507D117F9AD55612D9B037C613E06E161153CB14B419242F5BA425CB46D3777789446198A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10790" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupsHierarchyErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="StoreType" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="I64" I="2" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U32" I="3" O="false" N="CountGroupsHierarchyError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):779
                        Entropy (8bit):5.161151811323201
                        Encrypted:false
                        SSDEEP:
                        MD5:34D8D0BE5EC9BA54086585D52DCAA765
                        SHA1:A34B03741597DF1BF8873986DA2551C26B1BCE2D
                        SHA-256:1645D706B39B8595C8DA53989E5958906F14C95F751366CE8379B8A36131A6C5
                        SHA-512:70F3340971B6ACBEE822EABECB765A4A9B730277A18B8B50708EBE61998EFCB32D0192B74B5C981BBE2D1A9D1400AFABB3F6C5878E36810C1C55331CF6DEB789
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10795" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_FolderBarFocusedInboxEnabled">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FolderBarFocusedInboxDisabled">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):451
                        Entropy (8bit):5.366900726500801
                        Encrypted:false
                        SSDEEP:
                        MD5:49BCDE64B5A80FB149C06EFAFF42B05B
                        SHA1:DDF3DEC0B08B9560F73DFC4F70B69794CC723A00
                        SHA-256:9BE698D7058DFCE0731108CD09E931B468F23F58230C35BBA7E14F5F5B43D836
                        SHA-512:E4B639272CC55BD9D209B55F995ACD86E1DB05A53A8FA5D7F84F860F332F65E3EA6FACFDD04592F3ED80C7B6F5EF1E9DCC8170264A144C65AEAA5ECB4B8F2ECA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10796" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarPivotFocusedActivated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false" N="UnseenMailCountOnActivation">.. <S T="1" F="Count" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):449
                        Entropy (8bit):5.374048743236743
                        Encrypted:false
                        SSDEEP:
                        MD5:FD45346EFEE8BDE1CE59658150E87204
                        SHA1:AA2E330556025428A9C770AECEDE075BE3060C64
                        SHA-256:29E9D20B98DB4185F562D7A484471E2852D63B0FE89F5FC73D4D7F1B94240F0E
                        SHA-512:AFEF9A8FECC55C8E2F70DE33060C8C34C3557BC7B46F276A1B4D979531BB03A05433EBD7E0E5D7E536C7BC7858F449C0F3BC86AAE3B8D877F6F4C81F6BC06E30
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10797" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarPivotOtherActivated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false" N="UnseenMailCountOnActivation">.. <S T="1" F="Count" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):999
                        Entropy (8bit):5.154650853375804
                        Encrypted:false
                        SSDEEP:
                        MD5:C18FA821BC2342FDD9DE87C4DC81969E
                        SHA1:B1591B4733CAAD1AD880D3BF0721045AACF7E476
                        SHA-256:BAE15FD17C1572DA5672684F2F113E5F6BDAB555E0E5B35A8FEE54DD4360B95C
                        SHA-512:CC049C0ACDC4193487632046533700A869259D7FEBA6579338D7BAD356F92D3A0EE67942F4E9DF254A640BCE7E8F5323FA690EE227CE3424ACD202C329FDBD13
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10798" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxUnseenMailHintUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9011" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="9012" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_PivotFocusedActivatedOnUnseenHint">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_PivotOtherActivatedOnUnseenHint">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_UnseenMailHintDismissed">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):960
                        Entropy (8bit):5.079567413942803
                        Encrypted:false
                        SSDEEP:
                        MD5:A0A46C8B589CCE40341A90ADBA317250
                        SHA1:CF97D024EEEBF86A9C15B0EBF547ABFD3C35AD53
                        SHA-256:FB0A4B1603A188D29C9B7732A97580CB503F4E4B1570BFC4C3535D0D0E7295E5
                        SHA-512:7AE86E1F4FF6455BCC281A3A156283ED457C3F79C7AF05E921411648CC05A28ABD23D653B256A56DE51EA5BC1D19DE06D0B1790B196D8DA9305B828D7BB6C527
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10799" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarFilterUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="9015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_FilterAllSelected">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FilterUnreadSelected">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_FilterMentionsSelected">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):455
                        Entropy (8bit):4.385258368553274
                        Encrypted:false
                        SSDEEP:
                        MD5:D32DB9ADFAAAEE45D3B6AE82A3292BE4
                        SHA1:3F56B0B338398FB2BCCB8EC1645F2D5A07AEA938
                        SHA-256:3967AEC34F6F912314E4B09F719349EE20160EC6E460DB0F4DC55EBD81D2F075
                        SHA-512:326E86F467BF6292A7AF84F058D9990401C3DC1D27F2196060DE94DF2DF73FF8DD8EDAB77D998FA3775AB4C0B4AA4FF4311A58EB9F225E476AD2754465BD1937
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10800" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bhlvz" />.. <UTS T="2" Id="bhlv0" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2683
                        Entropy (8bit):3.339202408736384
                        Encrypted:false
                        SSDEEP:
                        MD5:3F36A9C98F1F9A7C0274B018EA824F2B
                        SHA1:D4D59977A39D2A21F26DEC9A296DDB6DD89E9482
                        SHA-256:FA747FCC832754D1C1F4181E8E225898E66E4FE466940EA53F3FF67A7FEDE0C5
                        SHA-512:AB2E7FB650998947F29EF1C4B99C7ACA4DED646F334B0D6408527A1309A7316441B5464C7B3D5FAE0399051E8EFFBA4A9B9BE53B39C9F59C74AB4274F386D3FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10801" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10781" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2683
                        Entropy (8bit):3.336471169334665
                        Encrypted:false
                        SSDEEP:
                        MD5:34009FBF6298E1EAED5DB556C610DCE4
                        SHA1:4023B2C284673A052F31C40F92F1E9E062BFF840
                        SHA-256:BE81E59C2BBA681945CFD10AE299D0AA83B638D0943CBCF5E069F4B28213615F
                        SHA-512:63508D855ABBA44ACDDE3BE0411C7F7CE6385B997679E794D2C45CF7D7EB4D215A2C8975AE5161C6B11B58488949FC5B09BA70D6668FC9E9EED064BCD63548BC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10802" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10800" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4305
                        Entropy (8bit):4.705471543668782
                        Encrypted:false
                        SSDEEP:
                        MD5:22ECF976C9843FD6C46022B73B3948F2
                        SHA1:46DB28D4FE84D38FE72949B882C67A7AB7EAD845
                        SHA-256:B33939E23CAD9B9B9C13B16E1015E9F9FCA182C15C6AA1EB004F40EEAC05C8AE
                        SHA-512:0CEBC1457B6A68A2E61F6AFA0B48D0913978EE839C718AA74C875CAD59BE59B3C95F255BFB49DC16322031F12069AD42452B91F8BA35310FE28C37060E9F2AF4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10803" V="1" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompletePerformanceStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgo5g" />.. <UTS T="2" Id="bgo5h" />.. <R T="3" R="10801" />.. <R T="4" R="10802" />.. <R T="5" R="10880" />.. <R T="6" R="10882" />.. <TI T="7" I="Daily" />.. <A T="8" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="SomeAutoCompleteSearchResultsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NoAutoCompleteSearchResultsCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="I32" I="2" O="false" N="DisplayUnder50msCount">.. <A T="SUM">.. <S T="3" F="0" />.. </A>.. </C>.. <C T="I32" I="3" O="false" N="Display50To100msCount">.. <A T="SUM">.. <S T="3" F="1" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="Display100To2
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):995
                        Entropy (8bit):4.289383640645895
                        Encrypted:false
                        SSDEEP:
                        MD5:FC2C37EE38A3EAD195CA7034A4C21811
                        SHA1:A8E252007CC0BE00E4C9CBACD4EBEFE7A63C1880
                        SHA-256:71DDAB80391BFA696D2A9D7F10A656DA92FC854A525F81A5BC38DEDB6C23B881
                        SHA-512:34FA6D3E8B800915894871D97A57DCC004AB5AACB9C0B04CE733EE564F79C4014432502E51ED57B263CDB46A390F0B642DC85D6EA78E1AE822D75F0EB87B290B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10807" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhpn8" />.. </S>.. <C T="I32" I="0" O="false">.. <S T="1" F="errorCode" />.. </C>.. <C T="B" I="1" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="HrInit" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="CompleteRecipient" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="3" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="HrShowAutoComplete" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="4" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="HrDeleteAutoCompleteItem" T="W" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1061
                        Entropy (8bit):4.899146707537674
                        Encrypted:false
                        SSDEEP:
                        MD5:ACEF7985804D93211B6B522A14E8D515
                        SHA1:C68809DCAD83C8DE77C39FAEB28163067408A588
                        SHA-256:0EB6285F536AD8D31EE2558BB0A1E88E58E1B071C8D6EE56FFC162A125E552D2
                        SHA-512:C5CD22BC1D00A1CD6C5E2ADD466C0B563AD3B5DF0523CCBF9392FC8A427C17C3BFF3DCEF0320258A795AD71563A48B2A2AAAC67041BEC58ADFBF12EBDDA70780
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10808" V="0" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompleteErrorStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10807" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ErrorCode">.. <S T="1" F="0" />.. </C>.. <C T="I32" I="1" O="false" N="HrInitResultCount">.. <A T="SUM">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="I32" I="2" O="false" N="CompleteRecipientResultCount">.. <A T="SUM">.. <S T="1" F="2" />.. </A>.. </C>.. <C T="I32" I="3" O="false" N="HrShowAutoCompleteResultCount">.. <A T="SUM">.. <S T="1" F="3" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="HrDeleteAutoCompleteItemResultCount">.. <A T="SUM">.. <S T="1" F="4" />.. </A>.. </C>.. <T>.. <S T="2" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1499
                        Entropy (8bit):4.77143182696172
                        Encrypted:false
                        SSDEEP:
                        MD5:46055EACB2D7BBC1DCFD2F1BAF4DCC33
                        SHA1:D569C19D5342C472848CF8D07FB47FAD10AE6085
                        SHA-256:313DA9086B2E9FD07A99DE93C8F814E601384123C4CCE22582B18D73B8E60BBB
                        SHA-512:C8521C06327051A5AC2B9EBEE9FFE5AF88C188AFEA357D91CB7AFD5F79A4C9B24BBF6159155BAF4EC31348DDCF6FE27BA58FF1928C599656413B02CECA2E7D1C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10812" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.NavigateInNewWindow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8217" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="OriginFunction" />.. <F N="InitialChecksPassed" />.. </S>.. <S T="4">.. <F N="OriginFunction" />.. <F N="InitialChecksPassed" />.. </S>.. <S T="5">.. <F N="OriginFunction" />.. <F N=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1308
                        Entropy (8bit):4.7820199210090575
                        Encrypted:false
                        SSDEEP:
                        MD5:2A9B8697F67DFF630D637B9990D7AE13
                        SHA1:7CF5BA9224A1BF3BF8AFAC8EC8C6462797EF8D2E
                        SHA-256:B52B593352E24E347458FB374BC84B03676BE2A18EE5A5FF6033F895718F7B30
                        SHA-512:B830E799049B2A383A043B3EB13A4AC7F2E1CA84C63A1FF9C27E97C54068B0ED42333B69048E50E682E05F08082F4CFC3FA9AE616B2CE3832FBEABE6BE15474D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10817" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.NavigateInCurrentWindow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8218" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="IsQueryStringEmpty" />.. </S>.. <S T="4">.. <F N="IsQueryStringEmpty" />.. </S>.. <S T="5">.. <F N="IsQueryStringEmpty" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsQueryStringEmpty">.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):790
                        Entropy (8bit):4.264971683918691
                        Encrypted:false
                        SSDEEP:
                        MD5:7FDB0D30BCE859350AE0F6710C398544
                        SHA1:B2C812FE419BA84C432A0CE5147517FE1105FFCD
                        SHA-256:CF03A73CBA7372F2DD1B81EC9A9F452B6F779E54E88021F168F91656C2971244
                        SHA-512:7CA22C6822118D950441273CEFA5ECE3722C989FBDCF35D3FEE3DF39BD3CA47566DBFEBE2EC89A044E2564D2F998074EA73C85B7C100E9CFA59386D25A20D2B1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10818" V="3" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="blelm" />.. <UTS T="2" Id="blelt" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="U64" I="1" O="false">.. <O T="COALESCE">.. <L>.. <S T="1" F="CardVersion" M="Ignore" />.. </L>.. <R>.. <V V="1" T="U64" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8435
                        Entropy (8bit):3.4038221245401568
                        Encrypted:false
                        SSDEEP:
                        MD5:C747CD34026E1302C1614C323ADE9808
                        SHA1:BCFA859ACC88409E96449FF3EAA8EC933967B39B
                        SHA-256:2F50C4C4879C6036FE6E115C5063065C00380209A7D4461B5285B1F9DCE1F5CE
                        SHA-512:6E7620831D20384015CCFAAD9CE81EBEF444B6DFED9259818C8B7ECEED3F9BEAE1E1ABA565FD3069AE07F96F80931D72E7DCF87E958DB75E61E02A7A43058CE3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10819" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCardTimestampInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10818" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5508
                        Entropy (8bit):4.114083575416656
                        Encrypted:false
                        SSDEEP:
                        MD5:1DFB43EAA09AC0AE7EB5384813A40433
                        SHA1:60B268869771CF0CFD7C7CA8B74D3AA893C023FB
                        SHA-256:C242FB7C96AC9816B01125D1BEEAD43D73806875F03C8313E08206E9E2137796
                        SHA-512:9CDBFB054C7D15DDF638BB24252CEF20AB70AB4FFFF8CC674248A5A78DC3FAFAE0E46F9BE08E91C7BC2FD3E71182FB221156B76CBBB3732A3E1ABE59D421DF3B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="blelt" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="IsHosted" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="IsHosted" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="CardType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="4" F="CardType" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4453
                        Entropy (8bit):4.611929344749824
                        Encrypted:false
                        SSDEEP:
                        MD5:44E94A2EB7901D6FF85292A6ACAC80FC
                        SHA1:805C47614E74F202CAEAC376654AA91542DBE5A4
                        SHA-256:8BFFA7414C818F25F55F02040D08E59E220FC0009C577DF8930FB72B75FB204B
                        SHA-512:EB025C1EAE42B97944B919296632FB4B06F4E899F2442C5929B42F261D9B0CD736097992FB1E47C0B8CCB77F0F2DBC64E70886EB5637A42060181E7DC9D70E74
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10821" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardClickCountsA" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="blekv" />.. <UTS T="5" Id="bleld" />.. <UTS T="6" Id="blekw" />.. <UTS T="7" Id="blekx" />.. <UTS T="8" Id="bleky" />.. <UTS T="9" Id="blekz" />.. <UTS T="10" Id="blek0" />.. <UTS T="11" Id="blek1" />.. <UTS T="12" Id="blek2" />.. <UTS T="13" Id="blek3" />.. <UTS T="14" Id="bleko" />.. <UTS T="15" Id="a9ceo" />.. <UTS T="16" Id="a9cdl" />.. <UTS T="17" Id="a9cer" />.. <UTS T="18" Id="blekq" />.. <UTS T="19" Id="a9ceh" />.. <UTS T="20" Id="a9cei" />.. <UTS T="21" Id="a9cel" />.. <UTS T="22" Id="a9cem" />.. <UTS T="23" Id="a9cep" />.. <UTS T="24" Id="a9ceq" />.. <UTS T="25" Id="blekr" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4452
                        Entropy (8bit):4.616080154641149
                        Encrypted:false
                        SSDEEP:
                        MD5:3C4AD726AF98C553C2EDBFB9F106B71A
                        SHA1:1B8D4F15173C774CC3EB88E8E001BC93DD7B78E3
                        SHA-256:36C4D95619B7D07968DBA0E91F8F01AF384D0B239BD69A77C9F005EB3E883D22
                        SHA-512:70044DEE2025104E34B0FA47455B09268EF86FA045D7B4A8E789856C3CC128399511E853D7E719FAAB2B0E9A77D7CE3078D2BB248647F353694868F301C88B65
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10822" V="2" DC="SM" EN="Office.Outlook.Desktop.ContactCardClickCountsB" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="blek4" />.. <UTS T="5" Id="blek5" />.. <UTS T="6" Id="blek6" />.. <UTS T="7" Id="blek7" />.. <UTS T="8" Id="blek8" />.. <UTS T="9" Id="blek9" />.. <UTS T="10" Id="blela" />.. <UTS T="11" Id="blelc" />.. <UTS T="12" Id="blele" />.. <UTS T="13" Id="blelf" />.. <UTS T="14" Id="blelb" />.. <UTS T="15" Id="blelg" />.. <UTS T="16" Id="blelh" />.. <UTS T="17" Id="bleli" />.. <UTS T="18" Id="blelj" />.. <UTS T="19" Id="blelk" />.. <UTS T="20" Id="blell" />.. <UTS T="21" Id="blekj" />.. <UTS T="22" Id="blekk" />.. <UTS T="23" Id="blekl" />.. <UTS T="24" Id="blekm" />.. <UTS T="25" Id="blekn" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2696
                        Entropy (8bit):4.965168964040294
                        Encrypted:false
                        SSDEEP:
                        MD5:7994AE221F53ABF1FB3BAAD3775BDECE
                        SHA1:CEF4FFF1B183887611E4BEE01205145EA37282B0
                        SHA-256:EA5B45902DC96775E9FC9F862E25825DF06F1CBDB7BE315604F458D69EE60AC3
                        SHA-512:28ED525284A94ADC34594AFEFB7C460FC13BE55FDBA525C72FA03BC27BAF5B6C5E8D2BA6E05A244DF7894D40C38B46C86905C5DDF6805FE9CC54F0EB50C525A0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10829" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlook.Logging.Metrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="21000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="21001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="21002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="21004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="21005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="21007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="21008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="21014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="9">.. <O T="EQ">.. <L>.. <S T="7" F="Canceled" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="10">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1364
                        Entropy (8bit):4.76829343806172
                        Encrypted:false
                        SSDEEP:
                        MD5:95BCF8C7E0BD81EF03F686A70BB41BC4
                        SHA1:CB26F74468D9C87CCA37FD4F0C972462571033C1
                        SHA-256:785B31E3347B07F5138710C0D237457A54AA33E20EF278800A9F122414F01BDF
                        SHA-512:E077944FAAB284058B39A7756B4886B4617974F12490FA4DEA605795BFFBCCB07BF861C7C76B02939C9600FBBB025C9EDEEFA2D38C898657FEB7487A3C9CFE60
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10830" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlook.Logging.Providers" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="128" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="21013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="21009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="FromChangeNotify" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FromChangeNotify" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="2">.. <F N="ProfileName" />.. <F N="Enabled" />.. <F N="Level" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="LogProfile">.. <S T="2" F="ProfileName" />.. </C>.. <C T="B" I="1" O="false" N="Enable
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):587
                        Entropy (8bit):5.2288146299496425
                        Encrypted:false
                        SSDEEP:
                        MD5:FE3BF59F62679594B538EF61A57D8CF0
                        SHA1:B3D05F2938AC329CECFDB766C327438E21B78593
                        SHA-256:AFF0D0013DD2C9AFBE87DE47C18C20AA6CF4E0A0C905823F97875AB113F44E63
                        SHA-512:926B9EC78D80C4F26BDE5D5BEA90015C58AD22BA666436D3CC6D4D2CC5D2761022A83DD1A448C1A55FD0C6FE229BEED5D0B4B88843E18B36B7C9BC12204D6FCE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10831" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.OptionsButtonAddHolidays" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22400" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfOptionsButtonAddHolidays">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):567
                        Entropy (8bit):5.192498919771027
                        Encrypted:false
                        SSDEEP:
                        MD5:B857AD9DBA7632DB4FA59D606651D1BA
                        SHA1:00ABB5A6FE3F627985C02A2FE560CD8C4B88116F
                        SHA-256:4034A4ADDFEB97CEA5F1B119B646B53E4C73367BB6B40E2E16EEACF85001C944
                        SHA-512:6701396ACC6ABC9B2764E61926C2A7BD45CC358A6B582CA0101C5A6CD9C6A06CF2283EBBCD8AB288A791E33572C4A0D74D5C8953E10C6D0E73889DD5BAFADA91
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10832" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.CommandLineHOL" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22401" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfCommandLineHOL">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):577
                        Entropy (8bit):5.194499200189728
                        Encrypted:false
                        SSDEEP:
                        MD5:7F7A3B618E2D1442030B2465ED39E505
                        SHA1:83594F0DD160912888C204C99FB98A5CA1CBEC9E
                        SHA-256:4A0B4BB1E405BCA274BF5C7975CD156099FF671C29DE8017AD598C05903621B3
                        SHA-512:0001ACC43429F4882AB48F73FAEF40FCDA02FC5653499F84B16E58D3499F34548DF605025220132D76AAE4E1CE2918F1A39E3C81F4D8C8E6AB141BEDCDDABCA5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10833" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.AddHolidaysTransfer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22402" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfAddHolidaysTransfer">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1158
                        Entropy (8bit):5.12689155289185
                        Encrypted:false
                        SSDEEP:
                        MD5:DF18DB8E05DDA4FC76A9F64A8DB46484
                        SHA1:7A1624FD1F8483F729B86CE70B741EC596397A4E
                        SHA-256:D0278D7D0DA5E41E40C5E8B71B116689D9F990003CBB264684D939BED596EAA6
                        SHA-512:11E4530B6715503B0947FFF54882B9F5CDD31CB5C187D558729B1DA9DA755696E5242A3F24C1017259D52F91BEB634FA19B540ECBAB623C72A932E83B2535173
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10834" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.AddHolidaysGroupCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22403" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOf_AddHolidaysGroupCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SumOf_AddHolidaysGroupCount">.. <A T="SUM">.. <S T="1" F="AddHolidaysGroupCount" />.. </A>.. </C>.. <C T="F" I="2" O="false" N="Average_AddHolidaysGroupCount">.. <A T="AVG">.. <S T="1" F="AddHolidaysGroupCount" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="Maximum_AddHolidaysGroupCount">.. <A T="MAX">.. <S T="1" F="AddHolidaysGroupCount" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="Minimum_AddHolidaysGroupCount">.. <A T="M
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2183
                        Entropy (8bit):5.048469810735926
                        Encrypted:false
                        SSDEEP:
                        MD5:E8CC98189471039A9F440938CC82FA49
                        SHA1:7C285F6FCFE06EEB7047FBF4C1632B2925A4E8DC
                        SHA-256:88DD193DE3E18B24EE3D814B1698CAA148FE681F6A493C3E69674CB2FE4D5CFD
                        SHA-512:B80732ACDA1DEE58040B0358747D8A30A7C320D11C97AE61DE00B4134BC10E432BB06C00CF23E58B60E91D6D93B0F680C7F8ADDD84B402F6F02540C7744EA874
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10836" V="0" DC="SM" EN="Office.Outlook.Desktop.FeedbackandSupportClicks" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="20703" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20708" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20707" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20704" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20705" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="22210" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="22211" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="10" E="20730" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="11" E="20706" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U16" I="0" O="false" N="Count_OpenHel
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5178
                        Entropy (8bit):4.093194344076953
                        Encrypted:false
                        SSDEEP:
                        MD5:1C0F7CB02335D784CD8DD4B42CF6717D
                        SHA1:4C467E31A85DD0DA11ADE388E02D971A6B0905FA
                        SHA-256:D4A7137EAAE959D3C770CC4DF88F52D135F0B82B9B221D6689F9782B7E73CCB2
                        SHA-512:37673A3D6C3709E9098A509FC67D61D388520895E7D5B0145C61BEC63E5791770B5B02746F849AB453ECC4B02834D06E30128618F4780D8D5325475E5DA863AA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10837" V="2" DC="SM" EN="Office.Outlook.Desktop.CalendarViewModeChanges" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="400" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="401" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="420" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="CalendarMode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="CalendarMode" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="CalendarMode" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2489
                        Entropy (8bit):4.497566133266252
                        Encrypted:false
                        SSDEEP:
                        MD5:03D5B2DECE1B481D6CEE9113063E8955
                        SHA1:C53427E291EDCE495BCCC428F690759E9E9D7AA8
                        SHA-256:EF45755D9549452461C18E6BE93FF0A00836046A3D8AE5B8CD047E5D10B8D8EA
                        SHA-512:DA0328F8861A0B630204D8BB0F0A7EF5D27DE252BA79F23F38690AFEF76BA8B1B98F32521325D0AEF44309125E92A73FF46BFDACB77263386C95763AD26B936F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10838" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchUIResultSource" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7089" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchRes
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1525
                        Entropy (8bit):4.77334761805966
                        Encrypted:false
                        SSDEEP:
                        MD5:69FECF39B512C1116BCF4605D70042EE
                        SHA1:807CD3E3EB690BAFD0D7869B94722D0630DF77F9
                        SHA-256:D810655D3DC6EC2BD2EC3D03B6E5AFE64FADF4BA82DABCFDA3BF79385008BC05
                        SHA-512:18B18EC0AA4FD766D26864488DDFE2EA8DD19D7C36F435BEFE9F1B014D03D21B2C1ADC2F74C6083B793705DEAE0EECE8F51B2E7CC3EE66A863969649211CFEC4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10839" V="2" DC="SM" EN="Office.Outlook.Desktop.Groups.VerbsExecution.Metrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="336" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="337" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="3" I="Hourly" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="HRESULT" />.. </S>.. <S T="2">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <O T="COALESCE">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <S T="2" F="StoreType" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="VerbId">.. <O T="COALESCE">.. <L>.. <S T="1" F="VerbIdNew" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2514
                        Entropy (8bit):4.807512960860602
                        Encrypted:false
                        SSDEEP:
                        MD5:8A5750DE3007ECEA395CAB6550FDC67C
                        SHA1:B32FA8915D807119E7EBC07FADD10AECF4E0D06A
                        SHA-256:991A2A4FFE4E3BDD23492E8D5DE4BD3146D45ED373E76A8C47F6F551E75DD10E
                        SHA-512:39A4D1ECF419AF2C1107A6045485A0E0ABECBB45EFB3FCE8E686E63ED56EAB16F1119D34BC60E49D39BBFEE51CA119B354763BCB703BACDF0C18CF6F2A3FC1C9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10841" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ApiCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3201" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="3203" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="3204" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="3206" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="5" E="3207" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="6" E="3208" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="7" E="3250" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="8" E="3251" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="9" E="3252" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="10" E="3253" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="11" E="3254" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):9082
                        Entropy (8bit):3.7506683981346014
                        Encrypted:false
                        SSDEEP:
                        MD5:FF61FF98069FC4481501DE0B020ABE8D
                        SHA1:CD6A0CC21E49B7EF6C49BE39028F92B274CC5642
                        SHA-256:F401D4BE65BF576A70AF18E3783CB2FC9F90237FF05620AE95D4512F0E60AD36
                        SHA-512:00ACAF32CC18FDBBBAD9D016DC3372E62A14C8A4C825A47574DA30CE52A1BB38E8EC4D1F9D99B87D93E5B507139218D3A5055EA20B6B7FDE9E1824DA9C2A529F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10860" V="1" DC="SM" EN="Office.Outlook.Desktop.ModConvVerbExecutionFailureRate" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10861" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="LT">.. <L>.. <S T="5" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):393
                        Entropy (8bit):4.838353697219681
                        Encrypted:false
                        SSDEEP:
                        MD5:25FCE034336F890DC7AD11723FA7B35F
                        SHA1:4FF47C1D6950E1820B46CA78A5231C9130A75D9D
                        SHA-256:C78A9DB7B723DE7C3B977C4F633BA61AEB2D564475F8C73BD98742232A91928A
                        SHA-512:86E44CC7734FC855B33198FC585E9340FBC620844020C79806E79AEABA0502708CE4D469455B3CE38A14A6B463DAA05FEA11AA88B3922586F9477F7408E13A90
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10861" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20054" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false">.. <S T="1" F="Verb" />.. </C>.. <C T="I32" I="1" O="false">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1901
                        Entropy (8bit):4.99213994548585
                        Encrypted:false
                        SSDEEP:
                        MD5:57E71E3AA9BF05172515C67529D1622C
                        SHA1:9EB3ACBE10F54607C97ED889C588328AA7197E8F
                        SHA-256:456C7F5C09555465FE27D30FDC617BF85432653DA9AC906B37B72D53F636CB4A
                        SHA-512:836FB8C13E4A0E7CE79D3FC96E5C3F447E5F2980E1E41D1A14B0D1D2C39A528239E97314A38394F4EA74B12A63AB4067AEB2FB1151B0EFEB51ED3B27E81A3275
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10864" V="2" DC="SM" EN="Office.Outlook.Desktop.DownloadFilesUsingBITSWithAuthentication" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="64" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="26103" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="26113" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="26120" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="FunctionName" />.. </L>.. <R>.. <V V="DownloadFilesUsingBITS" T="W" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="4">.. <F N="ThreadId" />.. </S>.. <S T="3">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="JobDescription">.. <S T="1" F="JobDescription" />.. </C>.. <C T="B" I="1" O="false" N="FManualDownload">.. <S T="1" F=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1651
                        Entropy (8bit):4.575370307988862
                        Encrypted:false
                        SSDEEP:
                        MD5:6B48D65A351EA5438E63B2AE44A777B5
                        SHA1:0DDCAA9BFCEB482658DDB5A61B9D80313C2B1DA0
                        SHA-256:066ADBF47AE7B0495E5FF7E28FE2F4714012F18E42FBB6210D4C7C55434A393E
                        SHA-512:B978F669E3E3B161C3E012F927F98B49378B143CFDA35F1C82121F6949BACC063396685989F133802445B640541E234ED2E878B19FBD480C80248B4637CECF8F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10869" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsProviderResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2067" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="fLogonObjectUsed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="f
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):455
                        Entropy (8bit):4.399188454050293
                        Encrypted:false
                        SSDEEP:
                        MD5:D6C398FAC8F9D87101DB8FEF53C2B876
                        SHA1:C01F2FFB8D8C3FCEBCD0B29709C1C4F40044D83D
                        SHA-256:653F87BAC5821A543929EC0015FB8B6F86C77B227F6AB063210D9B594D5D376D
                        SHA-512:C7771791F75D9DB8A9A9B78DB310F988BFEFBB89EA2011770F7857C5780CAA1DE2F87070C3E886B77A8142E43B83CDA74A27D09F771DBBF38292F1F61976F47A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10879" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bgo4t" />.. <UTS T="2" Id="bisag" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2683
                        Entropy (8bit):3.342342111015339
                        Encrypted:false
                        SSDEEP:
                        MD5:D5628C2352A9B3D4C4602F5AFA2036E4
                        SHA1:E7D8230316AC0DD065D2638EEC718EAE75794AC0
                        SHA-256:7466102BD56EFEC53753921C3F7A6D7E03C0F5BCC8BDFA9E071D413A31E71BD3
                        SHA-512:1E83F499724E6DDBEB51ACF21191075C5B502FC34967D2137EF383951253FF835AA7F9261A600CE6ED7F9E8B11A72BF59A65724850B5113249F0AFD6FD374CE8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10880" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10879" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):489
                        Entropy (8bit):4.337646480264813
                        Encrypted:false
                        SSDEEP:
                        MD5:9776094DC797155D2034F31172F11855
                        SHA1:64D1EBADBE368C9871662A8E55A508A916A0D3DD
                        SHA-256:D29FF2CF8D1225E5908F202F04F77FF6687E74444ECF6D4C08CE772AD3CD85C3
                        SHA-512:B949FA714541012864CAD0E3F664AB0C02DD41470B8F1A3E2EB18A825341EBB2859C6EE0E3654AB3E426EAD57F06E81E9D1B2469F088B055135FECF95D7FBCCA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10881" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bgo5i" />.. <UTS T="2" Id="bisaf" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2683
                        Entropy (8bit):3.339338030411146
                        Encrypted:false
                        SSDEEP:
                        MD5:9CD208B8D4670DA9984D5A05AE008E00
                        SHA1:99CFE5945C3AB601460B083F61A237E5ECC9BF97
                        SHA-256:8E2B06BC23226F0819031A9FB7CE418A3BABF447164286D58FCD291ADD0E6DEF
                        SHA-512:6A87B9EE407EA4494AFB5267B829859319DBC7C557A64F9BBA6C2BBF836AB3A687A8E2AEDA431943F89686FE64A9A50FC71AEDA4E6484CBD5E1D80E14406826F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10882" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10881" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):820
                        Entropy (8bit):5.074444213126179
                        Encrypted:false
                        SSDEEP:
                        MD5:45A992255B5F03F0CE41DCEC8CE960D9
                        SHA1:074615840424803A0F703D4459D7D64948C2B824
                        SHA-256:AA190D2453B55A1428AEB31BD89A3D2C0553CAC9541902CCEDF5AA3E726B28E9
                        SHA-512:FFC0D353FC56AA2919948E77D6A6FE8D8D26187402F0ABFBB679A0A05B01C5DFFE5970E7DEBA7F82A34CA151A2D33AF3AC21C09F3C9060D95C45D19423A0EF09
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10891" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.WriteAutoDiscoverDataResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3781" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3782" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="I32" I="0" O="false" N="HResult">.. <S T="2" F="HResult" />.. </C>.. <C T="U32" I="1" O="false" N="TotalWriteTime">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3929
                        Entropy (8bit):3.7501724045260145
                        Encrypted:false
                        SSDEEP:
                        MD5:33AEFA9BD440EC07CB4E96B198B57FE4
                        SHA1:4EFD098E990A4CE8664222F6BC69179FD56E4263
                        SHA-256:2857C56AFA3022DFD51A46D8C2AB1230B15FB8F503580CEBCBC8C439D6656F6A
                        SHA-512:3A2940060F865EAB84E366BADA1AB0A232500327F15A9D4CA44651C56429282B68A53E1FC0909DED96D927CD7E9F3A5EE497CA0FAFD52BB11791AD33BD6CC680
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10892" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.WriteAutoDiscoverDataTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10891" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="50" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6204
                        Entropy (8bit):4.17420265539919
                        Encrypted:false
                        SSDEEP:
                        MD5:919C09AB54D28E65A531FA089373418C
                        SHA1:084A7D4563376931CCBBFE2F43C5001AD678368C
                        SHA-256:2A109199232490F60855DCB384B16285371C068D21BEB0A2B457339C3CCA074C
                        SHA-512:16C5FC091162BBAFCCBB3942FFCC03405AAEE17075E5FC09E8B8E50BD9108D12302B8F84AA183DD4419DA990D051F67B9F6F6C6909F91615CB90D410D0A6E02D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10893" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.ReplyActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="360" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6317
                        Entropy (8bit):4.210749911883675
                        Encrypted:false
                        SSDEEP:
                        MD5:91EFB1362FFDCC8D0FA4D7EE08AE0242
                        SHA1:90AF5EC31F16D598CB6D87AC49737D056C4104A8
                        SHA-256:272BB90CD416423C462A0760EF2FF3165ED3E5D4A95A3A911476C16D46A45C8E
                        SHA-512:CDAF60B2FC5A8EFB423BF1B37168829E680423BDC3BEFF6058C67E1966EDF817905C8203AA02B2B43BDAF517C003D499859CD304F21F18358A608F2703535F10
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10894" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.ForwardActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="25" DL="B" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="361" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1942
                        Entropy (8bit):4.392957633399417
                        Encrypted:false
                        SSDEEP:
                        MD5:1788792A021ECD72DD00F6420AE78925
                        SHA1:04F4D5E83DC73194148BEB9C72BB950525EFF7D9
                        SHA-256:BCFEE5A1EF936AD9149B99EF8E179F4491B10957A98341279CC47D962A147C03
                        SHA-512:A2AF4D1B51EDDB8B9564C31F5F861E1A92DD106BF64F987F46FAA443EAF998AB95B86C7E2DF39CA4CDEC27F9E849013F393591F8D8ABFA5EB6868C0FADC234D3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10895" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.CallActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DL="B" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="362" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1885
                        Entropy (8bit):4.326159243020675
                        Encrypted:false
                        SSDEEP:
                        MD5:F7E52F658C1EB673E356AB0D878BBF55
                        SHA1:698A7DAE1B6F6BB443B389DD1ED6FD4C4160108E
                        SHA-256:DF01598ACA84ABA01DECCDC2FE078DD00CC491038F10177906D43E660DD1C05A
                        SHA-512:82DD3E1BB869F2650FF024FFC2AE2923105AEF6853167439E68CD39EE43B5E9A03F2857464458A413554CD58A05F6454A9EEF02B6086E8B7E258F394112FFA8F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10896" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.DialActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="363" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2096
                        Entropy (8bit):4.393976266815697
                        Encrypted:false
                        SSDEEP:
                        MD5:D01A35D03F86073E8121C7D00BF8F5FB
                        SHA1:0167D6F1053612D140285F245647368A91D6CA19
                        SHA-256:9F03BC33E1A226C9F37BCAB7DDD6B486D400329FF08E145EA3DDF2A74A979270
                        SHA-512:BDE2D53A186DBB46A9B3717587960BD130CDAB7FB8751A4FB194CBA2AA7BDF184A54C9F12289110177809721A4E8602A965616784B2DC2577FBB3DAF9AD2F605
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10897" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.GalContDialActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="364" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3889
                        Entropy (8bit):4.290086920856266
                        Encrypted:false
                        SSDEEP:
                        MD5:60E5125166216451E82793B1C438056F
                        SHA1:B8D9452E3D1B01AEF6EF06C5FF64395F2CFFCE58
                        SHA-256:91FDD4808565FE9197B4D18FA5E47F6FC2D706430EF4423DEC22CE6A281D2042
                        SHA-512:20C27B460F12654603367C16F3CA4227DB825E32A3E831F1DA4862AB8EF39A00D8210CAE7EC9636A0F3977955E11D041FBB0F4DD4BEEA0FF9C3F7FDA5E530191
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10898" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.ForwardOcrSerActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="365" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="5" F="IsForwardSeries" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1080
                        Entropy (8bit):5.070464270382312
                        Encrypted:false
                        SSDEEP:
                        MD5:5897BA24F7A84704E1578791374B304E
                        SHA1:574C853EF0AA209703FB68591C075134F6DBF8E5
                        SHA-256:D8C9E32B86FB1AD02DE9D849E751BB4A6B8FB6D32D31DB270D8EE52DBDD8BFA0
                        SHA-512:995675B0774516BACB780EC3BB18083AE16C5DB3F0A85C77167AC2C061F2142D43F53B9BECC412F65A512124F76B1EFB4FC80AC3C1E224C5736E4C7BAE5758B4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10899" V="0" DC="SM" EN="Office.Outlook.Desktop.TXPUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="105" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="101" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="104" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="6" E="107" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <C T="U32" I="0" O="false" N="TXPParseEventCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="TXPIndividualCardParseCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TXPCardAddedToFlexCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="TXPCardParseExceptionCount">.. <C>.. <S T="6" />.. </C>.. </C>.. <T>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):708
                        Entropy (8bit):5.097047229171639
                        Encrypted:false
                        SSDEEP:
                        MD5:B713DA663859968261BB406FF3C1D5D0
                        SHA1:E02F4C64E6643B42AAFF29BA8198F093C6772928
                        SHA-256:1F3DAA0C1B756DD4DB7D712B61BCAACC1579E738AB73A11B15EFD3BA303838C5
                        SHA-512:2C5AC1ED6DDBA22159E60BD05828472CB49F67DFD07E4EFB5E4BFEBF2749581D7BA904A578CDCFA7B61999EBFFD9A91BFCF896332ADCE2255F36571A41B1E133
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10900" V="0" DC="SM" EN="Office.Outlook.Desktop.TXPParseActivityBreakdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="104" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <G>.. <S T="3">.. <F N="Type" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="TXPActivityType">.. <S T="3" F="Type" />.. </C>.. <C T="U32" I="1" O="false" N="TXPActivityCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):723
                        Entropy (8bit):5.101960741262951
                        Encrypted:false
                        SSDEEP:
                        MD5:5FE8DD40F214DC4EC444A6588A11896F
                        SHA1:84E04000C5A94C60DF14D68BE8E107E8AD95F735
                        SHA-256:440A0C63788189E3094E60972BE0926F4DBC4E71B19410F5AC6A6D11FD6223BC
                        SHA-512:CF734CCA2BBE33F0E4CDD13500FA49A05F42B86CCC01B15B953FD4E2468DB463F9992AB02D0466941796394233143A8180FCE375396DA7F1D73B2FAD91691C20
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10901" V="0" DC="SM" EN="Office.Outlook.Desktop.TXPUICardBreakdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="101" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <G>.. <S T="3">.. <F N="EntityType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="TXPCardEntityType">.. <S T="3" F="EntityType" />.. </C>.. <C T="U32" I="1" O="false" N="TXPCardEntityTypeCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):687
                        Entropy (8bit):5.154773160698925
                        Encrypted:false
                        SSDEEP:
                        MD5:FEAACA09FB62C5CFB917CAE5237FC877
                        SHA1:5FDE90894237354A828F6B1B74FD50D4BA4353F1
                        SHA-256:FD63052C95C11D915B143B48823E7DCB6313048BC7B0420EF791DA6190D266B0
                        SHA-512:1FD47C44C947D3D85DC3920831C4ACCA20AEF26995D920ACAB005CA04B927C9BC2D3663E2C4817580C8C1EB51D2B1F6CCFD50AC9EDD1ECFCD59916EC07756E7C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10902" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlook.Pst.BFillLevelNeeded.Invalid" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="481" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="PageSize" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="PageSize">.. <S T="1" F="PageSize" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfFailures">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1700
                        Entropy (8bit):4.862082336706875
                        Encrypted:false
                        SSDEEP:
                        MD5:6F7CB4DA9824B12F3E0892FA4B923C1E
                        SHA1:F0DAD9754A35F22B9E0D719F600EAFCB339A895A
                        SHA-256:3E47CB19289689F6359D38617EF1D7208AB8CC29B82064DB547675AAE2698235
                        SHA-512:EFBB3277E47A7BDAA57435805863F60C5D0E30BE192C3998B028FAF3645A03080326F99CF8595F68F4FCBD8A660A349B936FAD60635D0531A7F430E2D98E3B68
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10903" V="0" DC="SM" EN="Office.Outlook.Desktop.RecoverDeletedItemsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9051" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="9052" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonShown" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="1" F="HResultShowButton" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="DeletedItemsFolderSelectedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):981
                        Entropy (8bit):4.69715613136981
                        Encrypted:false
                        SSDEEP:
                        MD5:944D8A618C775CCC109E0B1F7D1A2AE2
                        SHA1:622A0A9AE9DCE54421A637F777FB19599BD80841
                        SHA-256:1DC4FA81F39E11267A2B90884942205400E011EA7DE72068792461E39AA0D7FE
                        SHA-512:9505A6CF8348FFAFCCC2871D8AFF76009C3181266009A9EDD5913926EF25FA591D02B46ADA77ECA7CCBD99AA5216B2F731CBDE6C32B2CE64334DFBA12EDCAD38
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10904" V="0" DC="SM" EN="Office.Outlook.Desktop.SafeOpenDialogHasIDispatch" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4252" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Has IDispatch" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountHasIDispatch">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountNoIDispatch">.. <O T="SUB">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <C>.. <S T="4" />.. </C>.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1064
                        Entropy (8bit):5.0762674365907134
                        Encrypted:false
                        SSDEEP:
                        MD5:0C98E8F4582E20A6CD3615D3BB144989
                        SHA1:2F05EA2B3862AA41C02C0883AB229F313054A190
                        SHA-256:DF43FD7E80C4416BBA49E6D58BD1B38A23FAE380B75DD8C008E930ACAFE73CE6
                        SHA-512:CE8D69FE375909D49608ED5C44CEB269770D4465B488ABED1445134FEA1BD19C471EC710C244336DA2C0D29B1047895C7AC09D6C66BC2706E2FA3C7217EB0C41
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10906" V="1" DC="SM" EN="Office.Outlook.Desktop.NDBCorruptStore.Warning" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="397" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="U32" I="2" O="false" N="NdbType">.. <S T="1" F="NdbType" />.. </C>.. <C T="U32" I="3" O="false" N="Version">.. <S T="1" F="Version" />.. </C>.. <C T="W" I="4" O="false" N="ProcessName">.. <S T="1" F="ProcessName" />.. </C>.. <C T="W" I="5" O="false" N="PstVersion">.. <S T="1" F="PstVersion" />.. </C>.. <C T="W" I="6" O="false" N="Details">.. <S T="1" F="Details" />.. </C>.. <C T="U32" I="7" O="true" N="CreatedWithVersion">.. <S T="1" F="CreatedWithVersio
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):603
                        Entropy (8bit):5.22423592707578
                        Encrypted:false
                        SSDEEP:
                        MD5:918EF7DF4CDE0AF53B2F7C803FFF103A
                        SHA1:CF97A237A7B69D714ED36B3755CD08EB8E576EA0
                        SHA-256:3A357011143D8ADB29D928C1F186AAF0E72FAAA6F4BD0C4069E639A1CCB644F9
                        SHA-512:55AB72E88E18C82B3490ED8FB6A3C38397ED929CCC293B4086E9A83146493920B89ECF33714A646204CD455EB05F29D2588A5B1D0F97A30D42687B793AFD1969
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="395" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="U32" I="0" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="W" I="1" O="false" N="ProcessName">.. <S T="1" F="ProcessName" />.. </C>.. <C T="W" I="2" O="false" N="Version">.. <S T="1" F="ProcessVersion" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8775
                        Entropy (8bit):4.250960369844161
                        Encrypted:false
                        SSDEEP:
                        MD5:8306324D2691D1B4944871DC08B0A67F
                        SHA1:989A08BDCD2141BA98D7DA36297B1BB699E12A18
                        SHA-256:112BC9595B68E4EDF46762B62DF73334542562C21714618118F55CE6D92439CC
                        SHA-512:D4B2152DF6DE73059145565415B27063DBE8CD1BB50DF44EC44929EC877A91BB77815AEC60465B3B8DCD7F8F947CA37EB2DCAE4F8E168D2320C6B14FE2910E00
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10911" V="0" DC="SM" EN="Office.Outlook.Desktop.CalendarVTPApptMeetingActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="600" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="601" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ApptMeetAction" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ApptMeetAction" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ApptMeetAction" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="8"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2440
                        Entropy (8bit):4.995886413020794
                        Encrypted:false
                        SSDEEP:
                        MD5:4F28E9FBF9B04B3E4D1679E882821CA0
                        SHA1:FCBA62E5FAC59B7F9205127F0BD3C832592B5C8D
                        SHA-256:24E84E12B5B4B8528FED4E9861E28A46E5ADEA9752B9D9A4FCDE31083875221F
                        SHA-512:7CD69E53F4A5BD00380A3E47B82B133B1AE1897EB77F7D9F9F960BDB7DEF5DC446894C23F7CE6F532E798F668D965928AAEEB7618571B430FE9AFE417B3D96E6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10917" V="1" DC="SM" EN="Office.Outlook.Desktop.AutodiscoverV2Info" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="610" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="611" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="612" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="613" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="614" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="615" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="EmailAddress" />.. </S>.. <S T="2">.. <F N="EmailAddress" />.. </S>.. <S T="3">.. <F N="EmailAddress" />.. </S>.. <S T="4">.. <F N="EmailAddress" />.. </S>.. <S T="5">.. <F N="EmailAddress" />.. </S>.. <S T="6">.. <F N="EmailAddress" />.. </S>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):719
                        Entropy (8bit):5.062023756744965
                        Encrypted:false
                        SSDEEP:
                        MD5:CD6A3796AB237DAC37A0D6249C04BFFE
                        SHA1:E1B283274CFEBB48EC5244BEA31C5A1E83A783D0
                        SHA-256:178D2D3D2EBD9D494500CE582ACE831B2008FAFD0026C3CABEA4819AF570125A
                        SHA-512:335531C4A6E86D1CB05658BE68A2B6D7092028E30EB62F96E7AF8B61FC94FA33921AF54B4B43EDD912E203251DC5BCEFBA07317359B698939DC5F91775E8D63C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10922" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsAttachAsCopy" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4263" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="1" O="false" N="ResponseCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2195
                        Entropy (8bit):4.543003914440266
                        Encrypted:false
                        SSDEEP:
                        MD5:7C81A89E09C1CC5BAA7096A03F275EAC
                        SHA1:ECF560CF20E24A73C61E6F73F51701E1BCA9B0AC
                        SHA-256:AEF478CB5C451C23B8B3265C91E04570A87D4A746B1F4F8F4E67E8002964ECDC
                        SHA-512:BF0DF6483D2F1AF229F87D1BF7453F8D18C6916A4956C90BAE4077FBE980B98A41D1B0E1A6C8F325413E86A47E35DA0A8AE36A7A7FF5506BF12720D6BB332B43
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10923" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSharePointOnPremShouldAttemptConnectionResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4264" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Result" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):557
                        Entropy (8bit):5.186702507368891
                        Encrypted:false
                        SSDEEP:
                        MD5:4B8072735030B28C33E36E2EFEE4C9D1
                        SHA1:552DF1D720F6E3BCAADAB492B869A8A1E273100C
                        SHA-256:97E70ABD7A17256B70074373AECD5E90095D469B172EA0E8CD4C12AC238BBC37
                        SHA-512:6C9B535453688390A4F0728B2567E30D48240D9F5BF3EDB56B53EEEBC176D4E92FFB8C0739C21492483F23D385800134C537FDCCF89686ED6A53B8D2CB549BDE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10924" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchStartingUsingZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjynu" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfPeopleSearchStartingUsingZeroInput">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):715
                        Entropy (8bit):5.0661969034328775
                        Encrypted:false
                        SSDEEP:
                        MD5:C4CEA076980DEB12C0991D7B101110C9
                        SHA1:E2A238F706EA93CFFF0889EF57FCCEB48DE5B725
                        SHA-256:46CB0F703C967BC7F9E8FBD425A6EE75C880B5F01A1AE3C160663A1525324CEF
                        SHA-512:6F97BE0F973DB7F7F2C6D5382D2AE4114C05B4BC96970B935AA47BA20CCAA876F0B4406A773B7C85BF7B654257E7D5A161B285CA290F62E4384C188901AD7A19
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10925" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchSelectionUsingZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjyn0" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SelectedIndex" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="SelectedIndex" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfPeopleSearchSelectionUsingZeroInput">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):575
                        Entropy (8bit):5.209495134611662
                        Encrypted:false
                        SSDEEP:
                        MD5:C28087E5EE2D13E15FB4856CF61B1AA2
                        SHA1:6F2E97B3975C2B8920CEA9C067343BD27D089125
                        SHA-256:DB0762199DFB81B19E34818CF7100AA34D15CAE124D29747C045DD4A437F6DD4
                        SHA-512:CCCD837BEDFBF2F8586B772CD71AF245AE3F0EE4374D9F21BAB1533A335319EE1BC9190ED51490B5F3E01AF71B0B6F5AFC7D19EB905515E9D26A98E4B369A9F9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10926" V="0" DC="SM" EN="Office.Outlook.Desktop.WriteSharePointUrlsToCacheFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="340" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="FailedWritingToCache">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2848
                        Entropy (8bit):4.453500762587206
                        Encrypted:false
                        SSDEEP:
                        MD5:84D67A3ED7A805E3F665A788EF5350C2
                        SHA1:40BD9449EE165F01AA2154C27D57A3F04E15909A
                        SHA-256:84E130B8D9B48D2D573CB628F7CC646A180899BB362AADAEA1E47A95A0038A01
                        SHA-512:5563A56367FCBF5B93C9677CCA234D4B225792E8AD5CDE097A576510872AD990DBB03106C5A34BD77C00F709A85F0FFB8CC4C30FAA736EA0753D6CA7F152AE17
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10927" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchMCRPConvSource" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7092" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="LoadConversationFromCache" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="LoadConversationFromCache" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="HResultLoadFromOnline" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):856
                        Entropy (8bit):4.959871810940435
                        Encrypted:false
                        SSDEEP:
                        MD5:3CA27CA1541687046DCF868EF8522AEE
                        SHA1:7C9A61E00266BE5288BF6618D7CA8516014D2169
                        SHA-256:B609B8128D03222158AE66683F509EE6D08291BAA6BF6C948178619E5FFAB064
                        SHA-512:DABD6236B986AA367A73B5298AA6ADD61E181FD6C2F724A4F1D6FAFA8FD8537BF0FFA7FDB49139FC5BFFACD20AB6C93A2D7B6B6B71B19A67EFB9EB405D241F0B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10928" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportFileAndFolderParsing" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjaje" />.. <UTS T="2" Id="bjajf" />.. <UTS T="3" Id="bjai6" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CouldNotDetermineFolderName">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CouldNotDetermineFolderPath">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CouldNotDetermineFileName">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):690
                        Entropy (8bit):5.057508655522115
                        Encrypted:false
                        SSDEEP:
                        MD5:876144B7A0C2E3F970E81464E14BA8CB
                        SHA1:CA2611FB6A256E9A4DFD460489731EA34B26DCCA
                        SHA-256:D8DE7B3D7B3B20D53EB59118FA71B9145B8674F3A8040227B999C44B9D4AE6AD
                        SHA-512:964114A024B98796B333AC587B95724644E213B0358BF416D1333657C49E0B1F0005DAEDE1160A7769067DA92506B722A94CFCCD039E9CF3CCC2DADA40F90DFB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10929" V="1" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportJsonParsing" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhzqp" />.. <UTS T="2" Id="bhzqq" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="MissingOrInvalidJsonCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MissingOrInvalidJson2Count">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):706
                        Entropy (8bit):5.067582940614538
                        Encrypted:false
                        SSDEEP:
                        MD5:4DB5E2A2D57B6C8756EB654C1474752B
                        SHA1:A40BD8D776E2784EC14EAC55B775BEC1C1D1C8AB
                        SHA-256:1E71C68FE8F672C95669517916CA8CD52D8048CC26D227ED54873B6D7F56AF0D
                        SHA-512:32074B3F7D125871B89F7CA99856935D0A90DA5814971348AE98D5929FB51D24E92EDC98CF70F2DDE289CF64BD3C6FAB3C69F33EF8C62B49E1BF7F819FB9EB1A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10931" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetDocumentAndPlaceInfoFromServer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjnkq" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TransportResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="TransportResult" />.. </C>.. <C T="U32" I="1" O="false" N="CountForResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):708
                        Entropy (8bit):5.0612072696667685
                        Encrypted:false
                        SSDEEP:
                        MD5:FEB3B5BA422B59B8A92EF532D677309A
                        SHA1:6EDF0E1B01BBDBAD2F708BB74AB92AA2AF098402
                        SHA-256:9539DC21D8BDECF0F9E1C8706C4E2B0ACD44AC5B0779E4C44BD6B103CDA59E01
                        SHA-512:6B21784908B666EC59DD73E112EA34A6ABC5C3067F2C9969A1064976BCB4AF24E680AE9AAFBEFC957554855EB185F5E4FE3D7CE4C721FBB07961A6541A612051
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10932" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetPersonalUploadLocationFromServer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmo2" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TransportResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="TransportResult" />.. </C>.. <C T="U32" I="1" O="false" N="CountForResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):682
                        Entropy (8bit):5.012009004579065
                        Encrypted:false
                        SSDEEP:
                        MD5:AFAEC3D4F55AE7E3E9CC569DF5A3009F
                        SHA1:EEE729FBAFD64A69F4284FCE448E819403FF660B
                        SHA-256:02FB26A6532D9AA632653E37FC6507397212917E8ED5BCEE17124CAE65CBCF0F
                        SHA-512:BFC15FD1BAC47DCB432851E5CEC27194A3E51E4BE357D6C9AD8104C90FE22E4491F0F15E246740A2576448CF4DEB7B98F86C78AA07A801DFBC1415ABA2A5E853
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10933" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetDigest" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmo1" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TransportResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="TransportResult" />.. </C>.. <C T="U32" I="1" O="false" N="CountForResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):681
                        Entropy (8bit):5.029278739629518
                        Encrypted:false
                        SSDEEP:
                        MD5:AE9C4FC5FA46E0BC1F3E71C9DDD3FD57
                        SHA1:ECAEE9C32A1DD7C150B969A83269C16C5ED66905
                        SHA-256:BFA91C40C0B32B93B1D3AF459881F21B19D72A9D73EE9A5E71FB36F7E3B16371
                        SHA-512:6CE41E75831C3A4882E59CA8538923C648C8EBEFA8C63F20C97B9600EFB5AF6F3D7F057AE173469440B0F0AAEA841B3277D60CD470771A895357AD78B4602F3E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10934" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportMruItems" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjaja" />.. <UTS T="2" Id="bjajb" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfHavingMruItems">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountOfNotHavingMruItems">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):593
                        Entropy (8bit):5.261598261749258
                        Encrypted:false
                        SSDEEP:
                        MD5:F5BAAB5AA4B1B25CBAB3BB44CA5F6B3D
                        SHA1:05613FDA1A874B5495357EE2B4F2DEE1D9C2B809
                        SHA-256:4BAAEDC67B47B9B4ABAD921BB637A263722E8E37C406B9AAD88C3E30CBCE0D4F
                        SHA-512:497D2D96164225CCD77CF1843C867E4AF1F7D4DAFEC33B7890216E91C76CD6949BA9E3234AD4140619226EE206C32714C27034C638BA6C4FD464051F01C0F64A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10935" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.BigWebExtPaddingError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8221" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountBigWebExtPaddingError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):551
                        Entropy (8bit):5.183233007684959
                        Encrypted:false
                        SSDEEP:
                        MD5:20B506C4E954324503FC29A917134690
                        SHA1:11C22010AB256A96E145C879D85261AB50AE80D0
                        SHA-256:69D015A975443A6CECCF863EA9FF6ECA053D463F8F94FF288C61C381071DFC33
                        SHA-512:2DDD90CFFFDB5574D719599143E8F0FD5147F66847BC3AA224E76F6B0333F2E6923C1814B7D65899FBFE5625C6583635FEDBC490C109988D631618A0D0786321
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10940" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchErrorUsingZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjynx" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfPeopleSearchErrorUsingZeroInput">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):797
                        Entropy (8bit):4.692658451750095
                        Encrypted:false
                        SSDEEP:
                        MD5:31DB8902BB579E102BA2A2D3E9669F9B
                        SHA1:3324ED8C0845F3616CB10A112ACF1E4E73B6ADF7
                        SHA-256:A65B6C352BF9DE871B18C26BF7D58780A31CA918E368E46637C73B06E69BDF1B
                        SHA-512:72E4EAF7CF9B6C06CA81AA7BB236728425D4D7B37057F4B016C4AAE2DA6C8C7F8AE662D4A43DBF8E39377B10CC3A6FCC610BFB535960C03BC58B6EE76C503D6D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10941" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3783" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3784" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="Function" />.. </S>.. <S T="2">.. <F N="FunctionName" />.. </S>.. </G>.. <C T="W" I="0" O="false">.. <S T="2" F="FunctionName" />.. </C>.. <C T="I64" I="1" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1560
                        Entropy (8bit):4.215153378750664
                        Encrypted:false
                        SSDEEP:
                        MD5:934E257FFE05CB5103C449217187FDD3
                        SHA1:B0B2DD907B04919736B2D2898B92838653210CCB
                        SHA-256:913DAF004FFB2CFC4D90443C8EBC67E82FA87B37F55D151D7DBF58E4DE373704
                        SHA-512:459A822D7249B1A8CB0107818F625A4BE6A756B2C26429DE82B74E27F3003C251008A3C128849AE9E8E95D4589B0FF3087C93FA6466A0A68BE310483F5BBA1DE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10942" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemFileCollectionSuccessPerfRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10941" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="-2147024846" T="I64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1212
                        Entropy (8bit):4.373047821440982
                        Encrypted:false
                        SSDEEP:
                        MD5:7817DBC828FBF11F91AE65B293F4F620
                        SHA1:7F57406F0C8C88082F1934B6B9547C739A9A4386
                        SHA-256:4B579D67D4E5152B6E465584C2F5061E91C47E58F57269C53C52AF8332FFAE84
                        SHA-512:508E0DD57AD455F0EAB7601D5D5BE0C9747DB8D86C8EF48182D04B620D714A42E0DCB7265BFF9897A7A40C2D3E541F5C8F8D17AE51AF140231E8EB971F9D415D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10943" V="3" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemFileCollectionFailureHRESULTRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10941" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="-2147024846" T="I64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="W" I="0" O="true" N="FunctionName">.. <S T="4" F="0" />.. </C>.. <C T="I64" I="1
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):829
                        Entropy (8bit):5.113178696233751
                        Encrypted:false
                        SSDEEP:
                        MD5:C0163A9EA76FC3401B84CB59EE04C19A
                        SHA1:40D5779D9ECFD0961D15CAC4DBE60DAFBCAA026D
                        SHA-256:C9416F422C2EED02EAF3C48BA1C0F2D5EEF4FA0A97036914F93C79C297374791
                        SHA-512:F18A0AFF20B26003A8D06F36BCB2724F471F4E0589A430DACA3FD6059EDE8B54D3FED3A47C1934E970388456C71A6B4D296B215D07877D354AF9D7427B509449
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10944" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemFileUploadSuccessFailureRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3780" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="FileUploadType" />.. <F N="ResultStatus" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="FileType">.. <S T="1" F="FileUploadType" />.. </C>.. <C T="U32" I="1" O="false" N="ResultStatus">.. <S T="1" F="ResultStatus" />.. </C>.. <C T="U16" I="2" O="false" N="CountPerHResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):793
                        Entropy (8bit):5.111349636543579
                        Encrypted:false
                        SSDEEP:
                        MD5:B7843CBD337E7BA7F8F819F6A5BE893C
                        SHA1:B96F55A81666F29B1EDF042211420A141AAD1C87
                        SHA-256:5B9DE00DB52D4D8719A7F8A91C5466C9172C58C15805A1F97512B9BB39B24860
                        SHA-512:70BDB7031272DE194317C67EBD58E77C5CFF159E0FF406980622C7F2568E8F57DAC27CE3208868A8CA2DC6D141BB9A531604449A5943AAD1986E2701B7D80A5E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10946" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsActionResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. <F N="GroupAction" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="GroupAction">.. <S T="1" F="GroupAction" />.. </C>.. <C T="I32" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountGroupsActionResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1670
                        Entropy (8bit):4.499108503976622
                        Encrypted:false
                        SSDEEP:
                        MD5:46EBC33C0B8AD7289C0955D12CB3069C
                        SHA1:BFBC76BC956AF42B10277AFAF53E2E81B1A30C29
                        SHA-256:9A797CA2D656CCC23A86C1C766A846DB4F3D7445A7E545615836502C4EDF7735
                        SHA-512:6C3B2650E73B698510062AC23603B99B9AB1E1DF49E571DDD0C9D98F63ED5D732CD07DDAE905B4EEFB2F04B28B475AD2D978F85CDF3C9D63DC6C81DD1920BF1E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10947" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3117" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="18050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="18000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="3726" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="19001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="19002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <US T="8">.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. <S T="7" />.. </US>.. <F T="9">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="2" F="GroupAction" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):959
                        Entropy (8bit):4.860146495849858
                        Encrypted:false
                        SSDEEP:
                        MD5:E3CFF4B2AD5A5D56CF16B8408472EE03
                        SHA1:A97BE5A11111946DF52664DB5AF8817D849D0CAE
                        SHA-256:E6947546E0286D8799466ECA739DA4D861A5B6DFEF83D011E6C3ED863F62B142
                        SHA-512:B03B03BE1339197C7166FE563A8877B6D9E72B95335434062FE4241B08F2B69D5EE068FAFDA9D082D85AC62F2FF3F26271718D13EE1B93C782382FA3E4445D86
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10948" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsNavigateToNonjoined" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10947" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="EntryPoint">.. <S T="1" F="0" />.. </C>.. <C T="B" I="1" O="false" N="NonjoinedGroupCreated">.. <S T="1" F="1" />.. </C>.. <C T="I32" I="2" O="false" N="HResult">.. <S T="1" F="2" />.. </C>.. <C T="U32" I="3" O="false" N="GroupAction">.. <S T="1" F="3" />.. </C>.. <C T="U32" I="4" O="false" N="NavigateToNonjoinedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):694
                        Entropy (8bit):5.042230748420477
                        Encrypted:false
                        SSDEEP:
                        MD5:FC81BC677F5DB285B3D7C1BC9D8FAAE9
                        SHA1:366A4F8A0756523D817A39B9946D3CDCDC2BB7DC
                        SHA-256:AED314B6CCA9865E7FFC9681C2BE374E3DB61F1B3C9A5EC9F2298B911981A7EB
                        SHA-512:64D429F872173C46EC2001BAE253BAC6841EDF5B299BD694BD385C334E455B86CE4D358EFAB78ED98C243DF586F66179B68FA2A2AC13D0C9B44C9E5B47EEE534
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10949" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportMissingMruItemInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bjai7" />.. <UTS T="2" Id="bjai8" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMissingFilePath">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountMissingTimeStamp">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8195
                        Entropy (8bit):4.2929142187390035
                        Encrypted:false
                        SSDEEP:
                        MD5:BAF641B9B63941B3F96C99BD4A2423FD
                        SHA1:F925E3A3E0FF6A906D2E773539BE93025A6883D1
                        SHA-256:2C06DC5B4079E454F5B306E1207447E3901C378BC3A795B7A5132D202AA3309C
                        SHA-512:344CE2775D17BCD42A2BADEED3934B44A83E33866E5CACC34C264FCC112A481185D844F10CBD7942C4371A697F2F313BBE8B979A0B53634C3E062F192D7BE732
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10952" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCardHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="bleln" />.. <UTS T="5" Id="blelo" />.. <UTS T="6" Id="blelp" />.. <UTS T="7" Id="blelu" />.. <UTS T="8" Id="blelv" />.. <UTS T="9" Id="blelw" />.. <F T="10">.. <O T="EQ">.. <L>.. <S T="3" F="ValidPersona" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="11">.. <O T="EQ">.. <L>.. <S T="3" F="ValidManager" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="12">.. <O T="EQ">.. <L>.. <S T="4" F="ValidPersona" />.. </L>.. <R>.. <V V="fals
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):908
                        Entropy (8bit):4.828833887989631
                        Encrypted:false
                        SSDEEP:
                        MD5:28C43C4D594BE12A1FF9A9C398BB2C9A
                        SHA1:15B9FC017F3B34BDE6031DE15EF13C5F9217B96D
                        SHA-256:20D07A2C04BB1CAAF99EA9B654CE309A478C4CEAE5ECA928258EA86D02FB1DF0
                        SHA-512:C1755AA647CE28BE61BEC1057F501CBACB1236CDD1362756A7D9AE84B1A23196BF9D39AB8A142C8F6D273BD51AB734B6E424EAB4CD159F8E111D6DD596305FC3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10955" V="0" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompleteZeroInputSelection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ber0h" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Length" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="Index" />.. </S>.. <S T="1">.. <F N="Index" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="SelectedIndexResult">.. <S T="1" F="Index" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfRecipientAutoCompleteZeroInputSelection">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1061
                        Entropy (8bit):4.9087672588253195
                        Encrypted:false
                        SSDEEP:
                        MD5:AFECB76211EEE08FBEDFABC2C76DFD95
                        SHA1:E9C62DA6519DFF690A002E763658B8E95C70A16D
                        SHA-256:59831A155747F1025D1AF8C30D9905CDD2CA542BD6D9D1F8C76AEE2E453C4FDE
                        SHA-512:688EF61638A554C558453B2A46C789AA28004E6343074F0B28B73B6EE0F7A0405BBADCBC7C7E971A4595713BAB28E0E23E042BD818337558CE10880664F151DF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10956" V="1" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.FunctionResults.Global" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" E="false" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="407" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <R T="2" R="10956" />.. <R T="3" R="11010" />.. </S>.. <C T="U32" I="0" O="false" N="AccountConfigType">.. <O T="COALESCE">.. <L>.. <S T="3" F="0" />.. </L>.. <R>.. <S T="2" F="0" />.. </R>.. </O>.. </C>.. <C T="W" I="1" O="false" N="Function">.. <S T="1" F="Function" />.. </C>.. <C T="I64" I="2" O="false" N="HResult">.. <S T="1" F="hrReturn" />.. </C>.. <C T="U32" I="3" O="false" N="AccountStartThreadId">.. <O T="COALESCE">.. <L>.. <S T="3" F="1" />.. </L>.. <R>.. <S T="2" F="3" />.. </R>.. </O>.. </C>.. <C T="U32" I="4" O="false" N="ThreadId">.. <S T="1" F=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1668
                        Entropy (8bit):4.588149256087889
                        Encrypted:false
                        SSDEEP:
                        MD5:6C57EF83269ACAB356662A22F54ECEAA
                        SHA1:EFAAE40303A2EA677C4D81A3E62291EB430D71DD
                        SHA-256:041674DBFF75C382EBBBABFF8B0EFC946258440A38C638EF24ABA184BEEB1B82
                        SHA-512:A1583A309D80170F668B9E375DCBAFA0222E8542D25B94F12FCBDAE2B382F25D292DE21DE9E3465387E23A97E30BBC30594FE3F2EEF12FED8AB3E6A504FA7346
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10957" V="1" DC="SM" EN="Office.Outlook.Desktop.RopResponse.AuxBufferExceptionInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4204" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="fEmptyExceptionInfo" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="fEmptyExceptionInfo" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="fExistingExceptionInfo" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1269
                        Entropy (8bit):4.105362142610501
                        Encrypted:false
                        SSDEEP:
                        MD5:B73C15A2BFBFB5DB3C2574B4A481D803
                        SHA1:82AF9ED18F557EB45AA7F7A532DB2DB3664D0C84
                        SHA-256:21D7A9375AF4D1E338C6CBA9A4770B4F8B62C323100374CF46A3D336EEA77EA6
                        SHA-512:E1DCD944CB06FF254E6D525D76DC259A2ADAC25E66C7B23E8B3EA393426180757F145786CB99FFCC7772B5D00738D7EEA3943A19BE9F4B604D6183C293E05E06
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10958" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="307" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="309" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="310" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="SUB">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="TickCount" />.. </L>.. <R>.. <S T="2" F="TickCount" />.. </R>.. </O>.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="4" F="TickCount" />.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </L>.. <R>.. <O T="COALESCE">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):498
                        Entropy (8bit):4.803488958944331
                        Encrypted:false
                        SSDEEP:
                        MD5:D62680C9D72B6C803ACF4D8E2EF9ED1E
                        SHA1:6B17DA714AAE5E035FE1F45804118CD0F6C074EC
                        SHA-256:D9F69753C214A2662AA38D0AB0E61AEFA8F0D8A02428ADE1CEF70D50976CFF64
                        SHA-512:FFD328AE1120FBE976499000266811B6745B9974181DEA393BC1CF65A2B22D0CAFF236AF3AC04D6867C40A49039A04A6F88A51B6E097A00269FCCA9DAB8AF30D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10959" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="307" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="310" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="COALESCE">.. <L>.. <S T="2" F="TickCount" />.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1121
                        Entropy (8bit):4.1972326312380295
                        Encrypted:false
                        SSDEEP:
                        MD5:549545BBB01FF07EB1512913AC93BA5C
                        SHA1:3FD69194EF21A2F97C06683288D54CF84671AD9D
                        SHA-256:519375F0EA1E7C6333CA816C1EA73821EB5C24BC13448BCD88434FBBE3839E70
                        SHA-512:189AB9C7F3851A609E03BE45B2D3B1029F6AF83D650A9BB57367508BBAA2C8C483FA1B07F48C63E1F1E23A25F561F01C3648B2CDB26BA3EFD975C76ED4983E15
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10960" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="302" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="309" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <R T="4" R="10959" />.. <R T="5" R="10960" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="SUB">.. <L>.. <S T="1" F="TickCount" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <S T="5" F="1" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="U64" I="1" O="true">.. <O T="COALESCE">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <S T="5" F="1"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1908
                        Entropy (8bit):4.540049361664802
                        Encrypted:false
                        SSDEEP:
                        MD5:62694C10D903DAA9E317ED935B691B3A
                        SHA1:1A9C41C711E9BE1231518D5701A23DA3FF077398
                        SHA-256:7C0B3F86D26E0950368C6B2C87F05174A81C71F506C52C73EBC5249AC9891831
                        SHA-512:29196642CD3747014EE3599B37746C49993C9F6CB26B20671F37F102F4FBB5AEE4932918F552F25C96FA2A86E0770CE8267AB3769C3DB229B76F4F3EFC611821
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10961" V="1" DC="SM" EN="Office.Outlook.Desktop.HangReportingStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="301" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="302" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="307" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="310" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <R T="6" R="10958" />.. <R T="7" R="10960" />.. <A T="8" E="TelemetryShutdown" />.. <TI T="9" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="HangCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U64" I="1" O="false" N="AverageHang">.. <O T="COALESCE">.. <L>.. <A T="AVG">.. <S T="2" F="Duration" />.. </A>.. </L>.. <R>.. <V V="0" T="U64" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1261
                        Entropy (8bit):4.941047325928528
                        Encrypted:false
                        SSDEEP:
                        MD5:2E7B2C1598860EF32C2D722FB7DA346A
                        SHA1:FAF499599CD64D550E9EC82B99DCA45B16330722
                        SHA-256:0A0F9203B760E0FDBA8E1237279F1DC4F5448D0356BC5341931736222C106841
                        SHA-512:3EBC0B871A4118596AB727DE62554502F5FD97123A64A05D9D06B60A14751AF1067A49C08150D188D767C9B5A554468DE03982C0C165081BF3015971BA87DA6D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10962" V="0" DC="SM" EN="Office.Outlook.Desktop.HangReportingScopes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="303" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="ScopeId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="ScopeId">.. <S T="1" F="ScopeId" />.. </C>.. <C T="U32" I="1" O="false" N="ScopeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U64" I="2" O="false" N="AverageHang">.. <A T="AVG">.. <S T="1" F="ElapsedHanging" />.. </A>.. </C>.. <C T="U64" I="3" O="false" N="AverageDuration">.. <A T="AVG">.. <S T="1" F="ElapsedTotal" />.. </A>.. </C>.. <C T="U64" I="4" O="false" N="TotalHang">.. <A T="SUM">.. <S T="1" F="Ela
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):543
                        Entropy (8bit):4.743442176023748
                        Encrypted:false
                        SSDEEP:
                        MD5:AF1D8BCDDDE9B560EE4BBDF9125B9E62
                        SHA1:676DFC27A5D62E3B235DE4756D4C7DE6D883D448
                        SHA-256:84A53F64BE3FF339B84EFBFE586D44B98BC942A2A97BB008A8C1138A7907136F
                        SHA-512:7EC84362FCD477E1A1FD026DC8F8D9E1FDB6FDEEB0783D9B9C35AE1C09FDCA01F8CFD5635C7DAD56E8506130EFE4BE73AA6DB78BC55101AF38CFD58C10DE6910
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10964" V="0" DC="SM" T="Subrule" S="1" DCa="PSP" xmlns="">.. <S>.. <SS T="1" G="{56e6a7c9-845f-48bc-9098-50c70719d01b}" />.. <UTS T="2" Id="a4pqn" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="providerId" />.. </L>.. <R>.. <V V="{56e6a7c9-845f-48bc-9098-50c70719d01b}" T="G" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false">.. <S T="1" F="HangReportingEnabled" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):538
                        Entropy (8bit):5.196338237033586
                        Encrypted:false
                        SSDEEP:
                        MD5:C59CCF2C743F650F270989ED47B760F4
                        SHA1:776AE64F2E4239307085C6E0A29AFE3C380DE06B
                        SHA-256:9CACDE110DCDBF4635FD4D92739579B283472C59E9F96A5381C092739EF2A0F1
                        SHA-512:E7EAED238921177B3038E38CFDB0ABF106ED6A58FA7791431867D88BB78DC531BF24115F34665164FB5904EC982CC0CBD8D41EF03DAD5775BC4F5839092EDEEF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10966" V="0" DC="SM" EN="Office.Outlook.Desktop.ModernViewUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CurrentView">.. <S T="1" F="View" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1846
                        Entropy (8bit):4.988317676855807
                        Encrypted:false
                        SSDEEP:
                        MD5:4F40AC7E2BECE07E4A8107F274EB2797
                        SHA1:582CB7F52A559B1F22CAF1D3A9D62A02A55D3D1B
                        SHA-256:65DE72DD6AF39DC1F60D7B4340104E33F02EC4A50C26A7D6D5DE998E3E9CBBAD
                        SHA-512:765E50B29DE113EAA0041589FCF7B8AD3FCB4FC651AB8281EA0FE850A964863842D221B940DA1367DD1F881320319AE8674FF0CA9E36FB1C2D393F42CAB6CC3C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10968" V="0" DC="SM" EN="Office.Outlook.Desktop.SortGridAccessibilityUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15003" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="15006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="15007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="15008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="15009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="9" E="TelemetryShutdown" />.. <TI T="10" I="Daily" />.. </S>.. <C T="B" I="0" O="false" N="IsUiaProvider">.. <S T="1" F="IsUiaProvider" />.. </C>.. <C T="U32" I="1" O="fals
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):576
                        Entropy (8bit):5.242594598324056
                        Encrypted:false
                        SSDEEP:
                        MD5:21325FB2539337FF04F049FB3A7EA5AB
                        SHA1:210CE013EB54FD35C9DC75BBD76C023C1F6FD976
                        SHA-256:3BF44159C54A87FD502C2305403B7F35D4D0BA20662D595EE649B1F8924367D8
                        SHA-512:2D825295F59069266A4B0EB1655B2639AAC990433EECBAA6DCB8F33EFD324CA04FBBBB3071512E9F31EC45F657829F8A4CCF183C62867B69ABFC8D6ED7124CED
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10969" V="0" DC="SM" EN="Office.Outlook.Desktop.ModernViewStartupVsShutdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <R T="3" R="10970" />.. </S>.. <C T="U32" I="0" O="true" N="StartupView">.. <S T="3" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="ShutdownView">.. <S T="1" F="View" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):390
                        Entropy (8bit):4.9196546795863405
                        Encrypted:false
                        SSDEEP:
                        MD5:5FDC1D1EC6C8308332F7BAF6C7748D5E
                        SHA1:9AB9E34AAAB2E44FBAE87FF631025A3A7409BEEB
                        SHA-256:7AEA3B8FD68659B076640A192B7D689601F38708A6723CF85CD27E04381EA72D
                        SHA-512:84EE9DE2B029BCAA2E8C5C60DA6BB321AC3246B19304AF463B0B1EAD68320C2D1DC591C3C082B68E5532A4D8CA25D310583E300D4ACC40BFEA5A6E01B874A0A5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10970" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="13008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryStartup" />.. <TO T="3" I="30s">.. <S T="2" />.. </TO>.. </S>.. <C T="U32" I="0" O="falseNoError">.. <S T="1" F="View" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1234
                        Entropy (8bit):5.013255461969232
                        Encrypted:false
                        SSDEEP:
                        MD5:E379D33C062F012EB59117BC83E3B0A1
                        SHA1:A0426E8F4F2B71C2103F00FB0231FA24D48D4AFC
                        SHA-256:74C26DB64DBA38DA36894449693F81D12EFBDE50C556672EE4BF074016077FF2
                        SHA-512:8F598B19926788C9C29105AA1B1A8A2897124A4E9887C85B22634F0D176AF8BB4A122C49F6BA83D237407BE9183BB95B79006AF555BD0E4D59D33D2E5A9EC734
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10973" V="1" DC="SM" EN="Office.Outlook.Desktop.EditGroupActionData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp2a5" />.. <UTS T="2" Id="bp2a7" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="B" I="1" O="true" N="AccessTypeChange">.. <S T="1" F="AccessTypeChange" />.. </C>.. <C T="B" I="2" O="true" N="NameChange">.. <S T="1" F="NameChange" />.. </C>.. <C T="B" I="3" O="true" N="DescriptionChange">.. <S T="1" F="DescriptionChange" />.. </C>.. <C T="B" I="4" O="true" N="AutoSubscribeChange">.. <S T="1" F="AutoSubscribeChange" />.. </C>.. <C T="B" I="5" O="true" N="LanguageChange">.. <S T="1" F="LanguageChange" />.. </C>.. <C T="B" I="6" O="true"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1212
                        Entropy (8bit):4.416511931086647
                        Encrypted:false
                        SSDEEP:
                        MD5:5C9485637D1C6201B46F2D25715BEF33
                        SHA1:B64AC64955D30E99CDDD2D55237606191BE429EF
                        SHA-256:D74B3215355CF7B4DA70AC52202CA8D00714168A1B4F35A4452B6CA449F0C97C
                        SHA-512:A882AFD77CCE68DBB5AE6E182454E646AA1B7B681EEA7352C8EE61184C3A242D46E1C74969FA6FA1C3B387FF13944C237CE2B4E0099137BB150F62F12FC2A97B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10974" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleViewCirclePhotosHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="7" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl8vt" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ErrorCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="ErrorCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <TH T="6">.. <O T="GE">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </TH>.. </S>.. <C T="U32" I="0" O="false" N="PeopleViewSuccessCount">.. <C>.. <S T="4" />.. </C>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2021
                        Entropy (8bit):4.670695306961675
                        Encrypted:false
                        SSDEEP:
                        MD5:17FBFA4082399BF1C55C5B4F5F83AC0F
                        SHA1:0DF5C3B0A2922A10F71AA32DBA7E96D1DFF40292
                        SHA-256:EA8D22743DF3EFB6AFC7F597FDF2573FEB63902DD3B9EBA2300D5CC1D383D61F
                        SHA-512:687A749B210E7C3D4DAF72D54D172F09C96036C05A080CAB88C5CE85C33FBEAC702D51441C18359D4B89ED72CF341F80693B2BAF2EED046E9B7E47269A4CBCCA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10980" V="0" DC="SM" EN="Office.Outlook.Desktop.FastServerResponses" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7089" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7098" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Hourly" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="6" T="U32" />.. </R>.. </O>.. </F>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):822
                        Entropy (8bit):4.914465399096125
                        Encrypted:false
                        SSDEEP:
                        MD5:DDC1C972077B4B1841FAEE605C934491
                        SHA1:B8B79CC5F11FA427BBADAE52A247716B933C723A
                        SHA-256:1BFECF65F973188CA994F99A27F16AF381AC70C6B167A27390F5AC90FB4D1886
                        SHA-512:A18012D4F10889F9756DBF1B92DAC01DDBF2AE05F0E0EB4D81B388E5F564E7EFAE3E6BD6D1B53A19E96244106D1CE2DE4FF2CA70120B35E490AA2740B8426BF9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10984" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupsGuestAccess" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <R T="3" R="10996" />.. <R T="4" R="10997" />.. <R T="5" R="10998" />.. </S>.. <C T="U32" I="0" O="false" N="CountOutllibGuestElementUsed">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountMsoGuestElementUsed">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountDetailsWithGuests">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>.. <ST>.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1230
                        Entropy (8bit):5.204255427328799
                        Encrypted:false
                        SSDEEP:
                        MD5:876DEC9A45702AB47980543DD1A9C8CB
                        SHA1:5DC72E5F8B91748813942992F221F5C70ED26607
                        SHA-256:19BF089EDA006A1CC3E683E5EB098D0668638B0546DB82BD21AB979DE01D5598
                        SHA-512:D586A0DCB2B62A8A8E7B7C2DA3CC70879E03C02E1DF144C8299762BCA1071FB88E6C4150FDBD964041F62FCB4F9CE74C7A884FC82C1A55C7C39113CD080E0270
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10987" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticSystem.ContactSupportResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3774" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="20731" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I64" I="0" O="true" N="HelpShiftTicketHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="W" I="1" O="true" N="SARATicket">.. <S T="1" F="DiagnosticTicket" />.. </C>.. <C T="I32" I="2" O="true" N="SARATicketThreadId">.. <S T="1" F="ThreadId" />.. </C>.. <C T="FT" I="3" O="true" N="SARATicketTriggerTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="I64" I="4" O="false" N="ContactSupportHRESULT">.. <S T="2" F="HRESULT" />.. </C>.. <C T="I32" I="5" O="false" N="OpenSupportTicketAttempted">.. <S T="2" F="OpenSupportTicketAttempted" />.. </C>.. <C T="I32"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1155
                        Entropy (8bit):3.4875646633932904
                        Encrypted:false
                        SSDEEP:
                        MD5:EFE488D2D1E3E69C2A72D907A4806117
                        SHA1:C92CEB7C42179E5ECAAFFE08760497A2CDC1D9A2
                        SHA-256:6A57CBB36D3AA761042EBC67BBFF8EA885483F15C26FC26FE9B98A45F5D77CE2
                        SHA-512:098AD4AF7D5CDF6949BF75F3FFA798348677AC874A0A0388DB9BA67B8742ACD0BAFCFF42FA71A2CC1F65FFA5DB387F66924A9F0727C68447CD724AEF64062A17
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10996" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19022" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Element" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Element" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Element" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1141
                        Entropy (8bit):3.4139933389862867
                        Encrypted:false
                        SSDEEP:
                        MD5:A8D5A8856E3BCE71E0ED8425D6FE9CA8
                        SHA1:42FCB7A625F42240E7258B150DA77216418B4B94
                        SHA-256:69228F60A5A0139D3A061551A3FE6E8678F6DA23F026BFEA93084E06795CCC3B
                        SHA-512:782C2539EA1EB760045CECEC988201B8704A1A280E578C1EE52866268909BD33F7AF90B2432899E439DEBC57AEB5F3CF7074BDD873C9C8AC17E2C2B1111F1C75
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10997" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl6lt" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Groups Element" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Groups Element" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Groups Element" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):508
                        Entropy (8bit):4.493490823496701
                        Encrypted:false
                        SSDEEP:
                        MD5:8F9C0830D5B864110176DE22CB34BC5D
                        SHA1:492FAE6836BD974EEEAF8DEA07E9BA59FA5FEEF4
                        SHA-256:2483197D7CEA4BC24F75E37D255A83D19571BD5499D37CF9253B8F729159DBC4
                        SHA-512:A6D3A9FDA1396AA5AB0908FC5270EE899050114FB08AC6D65661A835E26A2E40B6F445EA3F66BA49B8EB5D3684DEA984ABBCA91C68107EB12B5A64ECAE9A7A31
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10998" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3250" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="GuestCount" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false">.. <S T="2" F="GuestCount" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):918
                        Entropy (8bit):5.100535823253302
                        Encrypted:false
                        SSDEEP:
                        MD5:20702307608C35156CC3A442FD0F7B9B
                        SHA1:7E36BA9191F75C52AC20DF38544CD9F3DD36FF78
                        SHA-256:86579E04C4A4D45CCD51979B89CC7559A6E5DB81B10A8B902BE9DA1AD544B87C
                        SHA-512:C70A81F3270BC8F74040E382A1B063528371B45A7DE907B0FEB2C3C7F578EB29907931F4F637DD67D9E9CE400624801ADEA015E2622115D4027F8F0F9754A89C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11000" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSafeLinks" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4268" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4269" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="4270" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="SafeLinkRedirectStarted">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SafeLinkRedirectSuccess">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SafeLinkRedirectFailure">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2338
                        Entropy (8bit):4.4535493624422315
                        Encrypted:false
                        SSDEEP:
                        MD5:22D8769EBC75F2485D2AF66C5413B85D
                        SHA1:96C4B0A472902318532FFF4F3C28B134E276B2DF
                        SHA-256:AE6811FC65EC22D7F2E1249505F0445982FBD66EAD7E2753B863B6562ACF3C24
                        SHA-512:671AB0D38F16E8296303DC7CA2BE63851BAABDD0C5914860CE194F5089ECEF3C3BAD8C5012CD6569FB99A73BD3981D9D868026EA701C02CE1BCEC63322955D67
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11002" V="1" DC="SM" EN="Office.Outlook.Desktop.LegacyWizardHelpLaunched" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="436" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="413" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="LaunchedFromButton" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="WhichPage" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="WhichPage" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="WhichPage" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4459
                        Entropy (8bit):4.365076894108927
                        Encrypted:false
                        SSDEEP:
                        MD5:73D11D66E73EC499924C062567B82DE7
                        SHA1:5D97C6120345EEF2615F352B2D8710A22348ADAF
                        SHA-256:38F29D5056F9FB96430D446C4D7CC07F7B3D76546C728F116101484970C8BCCE
                        SHA-512:C47AA8B3478B3EF2EA816ADE3BD3B9CDE54D55BC73623B484565DB2893989656D1194D12FB8BC18A39143360B571163CC3E7586828AF73B06FE2AD3784869F89
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11008" V="0" DC="SM" EN="Office.Outlook.Desktop.FindPeoplePersonaDataHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bm9b0" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiEntryId" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiEntryId" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiSearchKey" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiSearchKey" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):382
                        Entropy (8bit):4.948563324130314
                        Encrypted:false
                        SSDEEP:
                        MD5:D2984D72A2359F6D8B10B8C7AB6D2D45
                        SHA1:AE05ACF16AA63149D85D2029909711EDAC71DC02
                        SHA-256:02502153E7696B677AA5D8C952D2C87ADD2C3F75B79CD30C1C56B0B10E7390E8
                        SHA-512:B3DF6A6658F34C0461D1F993511FEF19B2C93F74A3107AA7CF96EB744BC9C191423FA1C26DFB944836BE07CED32528BCCB27954A6783ABAD8806088B5E663FED
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11010" V="0" DC="SM" T="Subrule" ER="10956" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="412" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U32" I="0" O="false">.. <S T="1" F="AccountConfigType" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="ThreadId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):235
                        Entropy (8bit):5.0040849397162575
                        Encrypted:false
                        SSDEEP:
                        MD5:45772E4F4866FF8DB7A4D0FA846C2364
                        SHA1:0B45C9982E3CC7C888092D26AA63296EC37B8183
                        SHA-256:A0056D12DCD4082A145FBCABADBF4AC6C7ED14FD147980907B48DABE6331BF90
                        SHA-512:4668C56F5490122F4A56D34A3AC1899861D0D746D053409DBAD9150E893FCCE980EB36CBD4775A0C5BEB8BC6429C9402FC830FD45A31879087296CF1D3755C03
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11011" V="0" DC="SM" T="Subrule" DR="10956" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="413" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):561
                        Entropy (8bit):5.366665078031525
                        Encrypted:false
                        SSDEEP:
                        MD5:BFBAAF75F2BA07B929E7889616359F9E
                        SHA1:BEAFD560A963641E3D4A8C0165472790B1CC2CA3
                        SHA-256:00C581A38A38664E6FC4C033FB6F2863210C641BAAEB16B44F7C504693534EA2
                        SHA-512:32226CF81C2993FB5F396958A0F4E46284A26004A1F50C93136137DFF6EDCB7FD2DBB8B9037A86E5EDE625A9A599B09FBD1FC2E4CF39F0F93DB53806D66DC7F2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11012" V="0" DC="SM" EN="Office.Outlook.Desktop.Autodiscover_NoTempFile" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="619" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="U32" I="0" O="false" N="AutoDiscoverTaskID">.. <S T="1" F="AutoDiscoverTaskID" />.. </C>.. <C T="B" I="1" O="false" N="AllowFlight_NoTempFile">.. <S T="1" F="AllowFlight_NoTempFile" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):992
                        Entropy (8bit):4.855844164652946
                        Encrypted:false
                        SSDEEP:
                        MD5:34EC88E5B676E0650D38EDBFA7C04955
                        SHA1:B62262E64C718A87C5A50ECB421836FF8751993F
                        SHA-256:B80B706216ACB2DD7E34596238DC978279C0796D54431CF54D003F17A7B11C85
                        SHA-512:46759729196D3DBB032F9EF0F85AC7EE54DC1DB5F61F37C4D5CA6C15513A15A5DB2D4A0714696ED11810BEBDEA2B0818BBE4E4333998D88BD348EC3F2CA3D55E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11013" V="0" DC="SM" EN="Office.Outlook.Desktop.IMAP.SpecialFolderPicker" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="617" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="618" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="LT">.. <L>.. <S T="2" F="HResult" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="InitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SelectCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SelectFailedCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):574
                        Entropy (8bit):5.176974635862576
                        Encrypted:false
                        SSDEEP:
                        MD5:B58DA17B3DD0D5FA34DAA0EB642A6359
                        SHA1:53B19F096DC9368A1F521E52B32A60AA844CC2BE
                        SHA-256:70B325B60105E07F5DFD5D7675912D412DFC391C7293CB529E3F6A42D24C879A
                        SHA-512:CDB41EB53CE5339275BE06EF5501878438B24F51904AADB12D36F384D8E003809611192639DAB6E3D29C7E1D5F5BD8339236925277075D3E470BA31FF3DAE4D2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11015" V="0" DC="SM" EN="Office.Outlook.Desktop.CalendarModulePeekCounts.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="700" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CalendarModulePeekCounts">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):663
                        Entropy (8bit):5.172331117371198
                        Encrypted:false
                        SSDEEP:
                        MD5:B149253D7EE4902CF04B8FA6CDDFFB50
                        SHA1:F94DD8E737337D9933E28A5D1D618C0695EEE3BA
                        SHA-256:CBE1A375AB76E37F7853E94F8FE2D4150AE56F83DB0CAD039DBDBBADDD5B1966
                        SHA-512:A2CBE985C834000DFD84499575A151CACE3215965AF4D8E1613457DB897311A153F8F4EBFDE6E946A070E62E36D07171CB6548FBB5E37444EF83BFEC055EAD30
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110228" V="0" DC="SM" EN="Office.Word.Word.AtMentionAddedViaNotificationList" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="348" G="{bb00e856-a12f-4ab7-b2c8-4e80caea5b07}" />.. </S>.. <C T="U32" I="0" O="false" N="TotalNotifications">.. <S T="1" F="Total Notifications" />.. </C>.. <C T="U32" I="1" O="false" N="AddedNotifications">.. <S T="1" F="Added Notifications" />.. </C>.. <C T="U32" I="2" O="false" N="RemovedNotifications">.. <S T="1" F="Removed Notifications" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1842
                        Entropy (8bit):4.620023242248927
                        Encrypted:false
                        SSDEEP:
                        MD5:20D8F2DC2639C6D65CB8EE01FD349D19
                        SHA1:675A17504BEC4EADAC019669F99B56AE6258048E
                        SHA-256:D6BBF50CC8B715A6E78AB7A079662419F0A313CF837B1A8C6FFD6328E2ECCFA0
                        SHA-512:F1BD6383E8EAE3D624098407188A66953294F2A5E08246B9FFDAF4740C6AD3F9371ED0DAF7FB7AF8A2EB3E82EBC061F5637FD04ED4AD95E8407E9888C88D7FDF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11022" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.MeetingAttendeeViewTrackingBasicUsage.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="371" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="372" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsOrganizer" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsReceived" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="Mode" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2075
                        Entropy (8bit):4.847162304138458
                        Encrypted:false
                        SSDEEP:
                        MD5:449BCAA66D7B71CC37B3FC1DE7E72AA9
                        SHA1:A566A3AA39466983C8E93A4708EDAF5021127431
                        SHA-256:B275B0276B3F2AEFF91144915174F22AA391825CE632FFBACCA0D25F92572FD2
                        SHA-512:FC2800A7E9D13456253A910E050671DA92FC353EC340B1F653B953B99E436DFDAA4E03BE5CE7E837AAABDC761580C4061932AF2CAA843A7B3E40FAFD41F0932B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110233" V="14" DC="SM" EN="Office.Word.Word.TypingTimeSampling" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1627" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. <R T="2" R="118916" />.. </S>.. <C T="U64" I="0" O="false" N="SampleDurationInMilliseconds">.. <S T="2" F="0" />.. </C>.. <C T="U64" I="1" O="false" N="MessagePostDelayMs">.. <S T="2" F="1" />.. </C>.. <C T="U64" I="2" O="false" N="TypedCharTimeMs">.. <S T="2" F="2" />.. </C>.. <C T="U64" I="3" O="false" N="DisplayTimeMs">.. <S T="2" F="3" />.. </C>.. <C T="U64" I="4" O="false" N="DocumentId">.. <S T="2" F="4" />.. </C>.. <C T="G" I="5" O="false" N="SqmDocId">.. <S T="2" F="5" />.. </C>.. <C T="W" I="6" O="false" N="DocKind">.. <S T="2" F="6" />.. </C>.. <C T="W" I="7" O="true" N="SrcDocKind">.. <S T="2" F="7" M="Ignore" />.. </C>.. <C T="B" I="8" O="fals
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1901
                        Entropy (8bit):4.627241851078075
                        Encrypted:false
                        SSDEEP:
                        MD5:E3743BC92F783380E1E6500C116A25C7
                        SHA1:6ECD9C6E99D551B92B615207321509A08D6388B4
                        SHA-256:57B99C85D6E02FE331A26A5F69AD9C645187D8C3BA286CCA36A99F99AF8C05B7
                        SHA-512:254F6AA2F24C1B5D9D2BE85146CAD099CCE5B85FFC6DBE6F3A98107F5E9261C640B4DD949553F5164FC548A47B2062C6185EAD9C65C9D0C43CC7A2B45F4AE6E9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110234" V="12" DC="SM" T="Subrule" xmlns="">.. <S>.. <Etw T="1" E="1627" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. <TH T="2">.. <O T="EQ">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <V V="13" T="U32" />.. </R>.. </O>.. </TH>.. </S>.. <C T="U64" I="0" O="false">.. <S T="2" F="dmsecTypingTime" />.. </C>.. <C T="U64" I="1" O="false">.. <S T="2" F="dmsecMessagePostDelay" />.. </C>.. <C T="U64" I="2" O="false">.. <S T="2" F="dmsecTypedChar" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="2" F="dmsecAirspaceRender" />.. </C>.. <C T="U64" I="4" O="false">.. <S T="2" F="DocumentId" />.. </C>.. <C T="G" I="5" O="false">.. <S T="2" F="SqmDocId" />.. </C>.. <C T="W" I="6" O="false">.. <S T="2" F="DocKind" />.. </C>.. <C T="W" I="7" O="true">.. <S T="2" F="SrcDocKind" M="Ignore" />.. </C>.. <C T="B" I="8" O="false"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4546
                        Entropy (8bit):4.1621296359435584
                        Encrypted:false
                        SSDEEP:
                        MD5:7E7FCFD9667EF114350837EF6859C34E
                        SHA1:99BD45C8DBFD2A2C5B34C3D409AEBC2989716D84
                        SHA-256:5AB0FD3A07238488E2BEB29FEB2D2DEFA06F3BFEC3D8E522CE1D1C63C1FD6CC8
                        SHA-512:CDCB614B486E7EC7D576A77E42CF1F319A965C5387DB1FCED459299ED7F0263FA5880AB59ABF99E7586FD53BDD55025910E18A800CE2E2082C0CB3061B1621FE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11023" V="2" DC="SM" EN="Office.Outlook.Desktop.Http.TransportFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10665" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="7" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="7" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="7" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="7" />.. </L>.. <R>.. <V V="7" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):382
                        Entropy (8bit):5.399602338062679
                        Encrypted:false
                        SSDEEP:
                        MD5:EC11257F68B0A7E223AB2F2948319B3A
                        SHA1:3101C84FBB3CED0709A9C2CD6CFDEF862AB3C712
                        SHA-256:EE1949F30104FFB0249B4D59AB9ECA32752A5D76F7716399C7161A780A404541
                        SHA-512:C7B432BFE86C6B85830F5AD4E095CC9B94B5BD1CF60C8FDC0D95A120148F8EA8ACEB4FD1D1DF552C0CE040B29E8F8BE7007A73BD5C80D8741F9FB4FEB05336D9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11030" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.PersistentTaskPaneSessionStart" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8224" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1397
                        Entropy (8bit):4.730302279138911
                        Encrypted:false
                        SSDEEP:
                        MD5:267A4D5CCDE3F3C244C83BB711E218B1
                        SHA1:69099B37A210690D6B4CF50D394F14D85C8BFA58
                        SHA-256:E4C1B61C2C9CA5F4D1F4CFFF0A55FC734E8D68B384B01C643BC2E53346158E8B
                        SHA-512:BADFD884942F1DF0CDCC5CD77A321D66F99BD9026A97F32ED94776B710BCD8881A52309E498F33E4FAAF6A8AC002D32C1FA17DEB79E19839627A7A374A34E733
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11031" V="1" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.PersistentTaskPaneFlightOn" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8225" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonActionType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonActionType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonActionType" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="ShowTaskPaneWit
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):746
                        Entropy (8bit):5.089387027562114
                        Encrypted:false
                        SSDEEP:
                        MD5:0FFD79AAF3CCF46CF7837A22D1711EAA
                        SHA1:F97E10344D57932CD8C78996EFA982A5C0C521A2
                        SHA-256:04A9AEDF7AA827A7FC1B5E27F7480FEA4B7D24127BA7CBB332C34534435FB300
                        SHA-512:26AD65075ADD30D1E2666C69EB5D29FBC6D1A8386FC48F56714E06A790C8C2CC4D31468E123BAEB77FE99544B8CBAA50F29967CFD15D9FB744C0F44A715719D5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110336" V="2" DC="SM" EN="Office.Word.Display.DrawE2o" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Hourly" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. <Etw T="4" E="224" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <G>.. <S T="4">.. <F N="wkWwd" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FAccessibilityRunning">.. <S T="4" F="fAccessibilityRunning" />.. </C>.. <C T="U32" I="1" O="false" N="WkWwd">.. <S T="4" F="wkWwd" />.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="4" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):563
                        Entropy (8bit):5.271599786390993
                        Encrypted:false
                        SSDEEP:
                        MD5:59ADDCAFFF7BFD058AA2A6AFF6A73AB6
                        SHA1:3A98AD7C3D4400E115389E22F86911E22E523695
                        SHA-256:C27912CF53D071DA73131EF25161758492877E6E0E017E11987826F149FA6AB5
                        SHA-512:E84BA0FB05857392F22696BE86F545DE7DC8D01BD6D10BDF0CFD5C787740FE518F828058B940963E639FE81DAD58C85D20F5703431D9CD69E791CF74AD424ED3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110337" V="2" DC="SM" EN="Office.Word.Display.ElaboratePrE2oViewTreatment" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="351" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <C T="B" I="0" O="false" N="FAccessibilityRunning">.. <S T="1" F="fAccessibilityRunning" />.. </C>.. <C T="U32" I="1" O="false" N="WkWwd">.. <S T="1" F="wkWwd" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):829
                        Entropy (8bit):5.048582156772682
                        Encrypted:false
                        SSDEEP:
                        MD5:C1DB076E3691F2431F6BB6663C3878C4
                        SHA1:D89141D5D7CDD9360188C0A48F40F464DA142D2C
                        SHA-256:5AE22392C0A7EB97C234F70490950E63BCBE0C0310C560CA3AF23B4E78BAA2D2
                        SHA-512:F2C7901C5ACCFD542C2FA9DCCF407AE1B4B1C26B03C8DBA710995986244A2F60C88C5E3DC025D3170EBC04C339F8250246F147DCB624EBA71DC7D839BCDEDCB0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11033" V="1" DC="SM" EN="Office.Outlook.Desktop.EidtGroupMember" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp2a6" />.. <UTS T="2" Id="bp2a8" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="W" I="1" O="false" N="OperationType">.. <S T="2" F="OperationType" />.. </C>.. <C T="U32" I="2" O="false" N="TotalChangedMemberCount">.. <S T="1" F="TotalChangedMemberCount" />.. </C>.. <C T="U32" I="3" O="false" N="GuestCount">.. <S T="1" F="GuestCount" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):913
                        Entropy (8bit):4.769412538377476
                        Encrypted:false
                        SSDEEP:
                        MD5:EAA20B3BD8511F6DCFFF54057588209A
                        SHA1:B54EC0D3C501FC142C09478BF46C143EB7FB05BD
                        SHA-256:166BCDC82D142BABDF62AF1249AB59723739259F16FA3D61F86F5C96BA35A1A9
                        SHA-512:8F289A958E9EC62ACB8BEC30D6EABEC2C39A5D0134393E2B6BBFDD463E511FF6BF618D125AF6E3D394470A4510940E96E234B8A1CE7D75E484534AA17ACB927E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11034" V="1" DC="SM" EN="Office.Outlook.Desktop.AddGroupMemberEmailValidation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bqdxe" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ActionSucceed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="GuestCount">.. <A T="SUM">.. <S T="1" F="GuestCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="FailureCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1511
                        Entropy (8bit):4.346273725761616
                        Encrypted:false
                        SSDEEP:
                        MD5:B818F4D618CF210BC56C3CD8D25DEA51
                        SHA1:047DB3FFB96202BFEF8ED90A7B58F55801F133B4
                        SHA-256:60AD626E6D5D38E35F46BFA292F2808EB066ADF2D070CE87C88D32A6C8F19872
                        SHA-512:3F31763E9282DB0C3A9D9B7E169238A27ADC5F24008EFBBF6E17DE65F4281697517FD7C7D410464FB2F85C42E0910CDE4979D6289EA6F03A56A3B2C1CAE7DA37
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110360" V="0" DC="SM" EN="Office.Word.Logging.Warnings" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="110361" />.. <R T="2" R="110362" />.. <R T="3" R="110363" />.. <R T="4" R="110364" />.. <TI T="5" I="10min" />.. <A T="6" E="TelemetrySuspend" />.. <A T="7" E="TelemetryShutdown" />.. <US T="8">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </US>.. </S>.. <G>.. <S T="8">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="1">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="2">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="3">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="4">.. <F N="0" />.. <F N="1"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3033
                        Entropy (8bit):4.598852864816991
                        Encrypted:false
                        SSDEEP:
                        MD5:70EBA2AD5C51F891DEB12BBD1DF84A12
                        SHA1:F50A5920EA4A210781F7CCB29B4FB19FE6D0C508
                        SHA-256:52EF8D83C6BC9A42E8F85F4FD9F818E26C93DE274B9B5E2BA8C8F9D57279F343
                        SHA-512:A65E3287A585936616E91073EEB57DBBB96E03CA09C53150B972EF732870894DFD43954A383DC7BE2DF047177FB75CC3600C83E063CA80D2E7CBBD2052123D7D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110361" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word Accessibility" S="Monitorable" />.. <UCSS T="2" C="Word Activation" S="Monitorable" />.. <UCSS T="3" C="Word Acronyms" S="Monitorable" />.. <UCSS T="4" C="Word Addin Monitor" S="Monitorable" />.. <UCSS T="5" C="Word Animation" S="Monitorable" />.. <UCSS T="6" C="Word Async CoAuthoring" S="Monitorable" />.. <UCSS T="7" C="Word Async Edit" S="Monitorable" />.. <UCSS T="8" C="Word At Mentions" S="Monitorable" />.. <UCSS T="9" C="Word Authoring Assistant" S="Monitorable" />.. <UCSS T="10" C="Word Bib Cit" S="Monitorable" />.. <UCSS T="11" C="Word Boot" S="Monitorable" />.. <UCSS T="12" C="Word Bullets Numbering" S="Monitorable" />.. <UCSS T="13" C="Word Clipboard" S="Monitorable" />.. <UCSS T="14" C="Word CoAuthoring" S="Monitorable" />.. <UCSS T="15" C="Word Coauth Undo" S="Monitorable" />.. <UCSS T="16" C="Word C
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3030
                        Entropy (8bit):4.602277665025217
                        Encrypted:false
                        SSDEEP:
                        MD5:A06D984D927F1C26DD11E6A59142BFB5
                        SHA1:5E9D7A2FECF8B4813911640596DE550C7C938EAC
                        SHA-256:A5ACA7CDD3817FD6ED6ECCD73F27D571AC8A636BD4C1EF7DD77916CFBE70044D
                        SHA-512:4C1134CDF1BE1D35F038A0C253843FCB880BEF1BD29FFC7EAB0642B17A78CDD4ABE83D352DB4F17235EA8191106C801F7CCFD407610189D57F9B7689E5D103EF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110362" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word File New" S="Monitorable" />.. <UCSS T="2" C="Word File Open" S="Monitorable" />.. <UCSS T="3" C="Word Find Replace" S="Monitorable" />.. <UCSS T="4" C="Word Flash Edits" S="Monitorable" />.. <UCSS T="5" C="Word Focus Mode" S="Monitorable" />.. <UCSS T="6" C="Word Font" S="Monitorable" />.. <UCSS T="7" C="Word Format Consistency Checker" S="Monitorable" />.. <UCSS T="8" C="Word Forms" S="Monitorable" />.. <UCSS T="9" C="Word Global Generic" S="Monitorable" />.. <UCSS T="10" C="Word Global State" S="Monitorable" />.. <UCSS T="11" C="Word Glyph" S="Monitorable" />.. <UCSS T="12" C="Word Graphics" S="Monitorable" />.. <UCSS T="13" C="Word Hashtags" S="Monitorable" />.. <UCSS T="14" C="WordHistory" S="Monitorable" />.. <UCSS T="15" C="Word HrLog" S="Monitorable" />.. <UCSS T="16" C="Word Idle" S="Monitorable" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3026
                        Entropy (8bit):4.592907301316505
                        Encrypted:false
                        SSDEEP:
                        MD5:79C0FC0168678F244AC219C593F2F3F2
                        SHA1:08472136EF19A47AA68438E915E783CAE80A0A5E
                        SHA-256:8C4D2DDE926DD6CEEF7E4A26376ADD88F0773BEEE0608FE9A45443E0E8C6FAB1
                        SHA-512:65EE90B53D77A2D9D05F360DE26220A04D950281073F5E82E6345A640A4BCBD2F84CAD61D34C279857CCD311A57B6BBB6758CB0C49203AA2361D375459505F23
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110363" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word My Local Changes" S="Monitorable" />.. <UCSS T="2" C="Word None" S="Monitorable" />.. <UCSS T="3" C="Word Object Model" S="Monitorable" />.. <UCSS T="4" C="Word OCSB" S="Monitorable" />.. <UCSS T="5" C="Word Office Solution Framework" S="Monitorable" />.. <UCSS T="6" C="Word OLE" S="Monitorable" />.. <UCSS T="7" C="Word OTCoauth" S="Monitorable" />.. <UCSS T="8" C="Word Paragraph IDs" S="Monitorable" />.. <UCSS T="9" C="Word Performance" S="Monitorable" />.. <UCSS T="10" C="Word Power" S="Monitorable" />.. <UCSS T="11" C="Word Print" S="Monitorable" />.. <UCSS T="12" C="Word Print Layout" S="Monitorable" />.. <UCSS T="13" C="Word Programmability" S="Monitorable" />.. <UCSS T="14" C="Word Proofing" S="Monitorable" />.. <UCSS T="15" C="Word Property Formatting" S="Monitorable" />.. <UCSS T="16" C="Word Rasterizat
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1566
                        Entropy (8bit):4.6157843925532855
                        Encrypted:false
                        SSDEEP:
                        MD5:91506AFF576071246FA9DA8D5DD73BFE
                        SHA1:790D4FB3CBF13998242D915479D95E489F911F21
                        SHA-256:598DB0697B62FECCE0D66EEF851D345E0D30957895D6F01F95172B4B5ECA698D
                        SHA-512:DC4F4E8CBB8E5A01E54BC4C28A6916BEA123FA915C7236F02BA5E1A20ADE86F869F090D3438C12060144EBA2212C740049A6C884B08724FD0E824C093A804141
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110364" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word Three Way Merge" S="Monitorable" />.. <UCSS T="2" C="Word Touch" S="Monitorable" />.. <UCSS T="3" C="Word Track Changes" S="Monitorable" />.. <UCSS T="4" C="Word UIM" S="Monitorable" />.. <UCSS T="5" C="Word Unit Test" S="Monitorable" />.. <UCSS T="6" C="Word View" S="Monitorable" />.. <UCSS T="7" C="WordWebSuserngView" S="Monitorable" />.. <UCSS T="8" C="WordWordMail" S="Monitorable" />.. <UCSS T="9" C="Word Zoom Scroll" S="Monitorable" />.. <UCSS T="10" C="Word Text Prediction" S="Monitorable" />.. <UCSS T="11" C="Word Augmentation Loop" S="Monitorable" />.. <UCSS T="12" C="Word User Operation" S="Monitorable" />.. <UCSS T="13" C="Word Document Recovery" S="Monitorable" />.. <UCSS T="14" C="Word Intelligence" S="Monitorable" />.. <US T="15">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):369
                        Entropy (8bit):5.402515312863235
                        Encrypted:false
                        SSDEEP:
                        MD5:579AB8EF4C8636D2CCCEEF1EFDD39F4B
                        SHA1:A1396E024E1B01BA2CA67ABBA6EA0284A41E009B
                        SHA-256:CFBD718A7A532BDA4158746C10C6AE78CE5E7F015C1037E9BD9BF61BF4F22377
                        SHA-512:B36DB1FCD8E9ED2BFA131831C9EB95D49C1F1F712690E87A2E602E6B428AE0E102D3F298740D9C108BC51322A9D59459666C5A5DC04EDDF2940DB093EDC75D69
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11060" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTFirstRunCompleted" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):375
                        Entropy (8bit):5.427725638236379
                        Encrypted:false
                        SSDEEP:
                        MD5:63BD5A0CC8EA591D0590D28853A3ECDE
                        SHA1:2EF7B9EEB36604F98242B8595AA16914CA2E0AAF
                        SHA-256:551748A8F9E83F44CA1FBE63FFC7CF2CF1C6C4E3B36DFBCB6AB55582E07C8632
                        SHA-512:F17CDE12639761EBAFFEE601A285C0F5AD00AF858BAC0C7BAC3E05BDE58E12D2640DB6ABB2F040D1EF593DDDF7C6C10075FF6CA87DBD10360E4E7C456CE44090
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11061" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTRequestServerCapability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9018" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):601
                        Entropy (8bit):5.346626833186174
                        Encrypted:false
                        SSDEEP:
                        MD5:04A133A6F35B8848CA6B7123AA9686D2
                        SHA1:F17B8C0757C21D534EB6D1F89DFFDF269EE15A4B
                        SHA-256:F0B393595642789F4E8DAB0C5BD6688D290C9C964B92B0BB9BB198DF3860B4DC
                        SHA-512:506FF9B8E1860491CB9A1D67B9D57631433C11AAFF5C78B19A9893A57BCE2733B0BD99BE03346F2EA4420EF2532CEAE19226A9F24ED8150BE9A1BFE227B5835D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11062" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTClientStateUpdated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="ClientIsFocusedInboxOn">.. <S T="1" F="IsFocusedInboxOn" />.. </C>.. <C T="W" I="1" O="true" N="ClientIsFocusedInboxOnLastUpdateTime">.. <S T="1" F="IsFocusedInboxOnLastUpdateTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):365
                        Entropy (8bit):5.401066347662183
                        Encrypted:false
                        SSDEEP:
                        MD5:CCAABBDFB44C64FFCFF0E05DE59277F7
                        SHA1:6667609322541C2E21E7C1AC36FDB1A49F9F5E38
                        SHA-256:9B99C068A5C22532D67E16A56D32B481FBEFAECCCE1D98FC9B21E905B2FEAC9C
                        SHA-512:1FDE477968B2F8C20E1E4BDDFE2A1D60B867B2ADE89239CC7BED3AAEAD02FCF240FE75336AF062639A6F599DC2CA7A118099CB85B839D9CDC1F88CD942642CC4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11063" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTAdminOverride" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1305
                        Entropy (8bit):4.887740661859413
                        Encrypted:false
                        SSDEEP:
                        MD5:822F5E1937C8EF7949B1D5557495E6D9
                        SHA1:AFA78A0B4D0F8251BDF921A60907BD12576BA0A7
                        SHA-256:919B3DC86FAEE9051F3C425805E8FFBD089CD4C41EE341B0D986F487CCE95D37
                        SHA-512:AF1E716655D0B566367E9948A79F5685C4DD2AFE3EEDBCE9EF2A360A1775C717A8CE21C47AC664BD7F743E2FF070B920D781A5D640C112CFBC6B4182E78D679C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11064" V="0" DC="SM" EN="Office.Outlook.Desktop.MOTWUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4271" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4272" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4273" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4230" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="6" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="MarkSetOnClipboardCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MarkSetOnPasteCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="MarkSetO
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1107
                        Entropy (8bit):5.128191074932314
                        Encrypted:false
                        SSDEEP:
                        MD5:DDC684FB8C20913F731479CD7667DFF6
                        SHA1:A00B6BA5DD2D56235FC285E2C4E9B356A36B1AD1
                        SHA-256:2AC4C84BDBE7BF1F9280E2B0749952836CE372A4AD22A8CE0A92437A98644E83
                        SHA-512:E27527CA91DCB915E8B45DDFBF8EF52CA6E5797763D10E5C853AF3BF8A03C4548DBE9F59C9D8D3FA48BAC45E3A9BEFDC4A1246D6AD12C908C7DC463899100A51
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11065" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchSuggestionRetrievalTimes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7106" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="B" I="0" O="false" N="IsQF">.. <S T="1" F="IsQF" />.. </C>.. <C T="I32" I="1" O="false" N="HttpStatusCode">.. <S T="1" F="HTTPStatusCode" />.. </C>.. <C T="U32" I="2" O="false" N="NetworkTimeTicks">.. <S T="1" F="NetworkTimeTicks" />.. </C>.. <C T="U32" I="3" O="false" N="DeserializationTimeTicks">.. <S T="1" F="DeserializationTimeTicks" />.. </C>.. <C T="W" I="4" O="false" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="G" I="5" O="true" N="SearchSessionID">.. <S T="1" F="SearchSessionID" M="Ignore" />.. </C>.. <C T="G" I="6" O="true" N="QueryGroupID">.. <S T="1" F="QueryGroupID" M="Ignore" />.. </C>.. <C T="G" I="7" O=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1165
                        Entropy (8bit):5.058229823280203
                        Encrypted:false
                        SSDEEP:
                        MD5:EE9034B7303351B07158F3B3AA46997A
                        SHA1:49035AD2012B6A7935375B9FF7BDF868FAC92340
                        SHA-256:737C6E22FEE2F3BC99DDF39D17D7A506D70552B90A4F7392F3DA466691FDE882
                        SHA-512:76D32402D8387C0368825C2316E6154F540846A8F6C8FA2AFCF92B7C9A5D7A8B7343BAC832C6E8B8EF0290206D39979B7E9F736453DBCA5A4207B710C0790812
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11067" V="2" DC="SM" EN="Office.Outlook.Desktop.LogSearchModule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7000" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7002" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <G>.. <S T="1">.. <F N="Search Session ID" />.. <F N="SearchSessionId" />.. </S>.. <S T="2">.. <F N="Search Session ID" />.. <F N="SearchSessionId" />.. </S>.. <S T="3">.. <F N="Search Session ID" />.. <F N="SearchSessionId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SearchSessionID">.. <S T="1" F="Search Session ID" />.. </C>.. <C T="U32" I="1" O="falseNoError" N="CurrentModule">.. <S T="3" F="CurrentModule" />.. </C>.. <C T="G" I="2" O="true" N="SearchSessionGUID">.. <S T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):753
                        Entropy (8bit):5.184211737684641
                        Encrypted:false
                        SSDEEP:
                        MD5:34EDA7930D6A634D47411A42FDC8A68E
                        SHA1:DF2D1658B841AD7A272277B6122C7031D878AD05
                        SHA-256:BE89580DE13ACB66F55AFAE9EF89F5657833B193D43F8C52173D9E0FF973EB03
                        SHA-512:79A4B8F246A957E58819AAB0E70DF191E6EC7E4C48FA99A75997F86DC9E15A7D41D2A9459DE797DF0D1BE4A3B17A70F47C6243988BE273478CF5E0DDE0C0F2AF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11068" V="2" DC="SM" EN="Office.Outlook.Desktop.GroupEmailReadsInMeSpace" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18033" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountOfGroupMailsReadInMeSpace">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="BIN" I="1" O="false" N="UserSmtpAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="SmtpAddress" />.. </U>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1709
                        Entropy (8bit):4.971976501981704
                        Encrypted:false
                        SSDEEP:
                        MD5:5BDADD40D817C98E16EBAE63F431DC33
                        SHA1:344373C7858A9F53BEA71E620EAFF40E4261A2AE
                        SHA-256:D07CE100719347089543E330E072C52970D897952258F096DCCEE0805B5257D8
                        SHA-512:3750496EC107A473D14E329A564480F44DC1F17A05F1319939BF2B4BB1716EF54099CD79DB7F5546AADA06F28CB876575E4AB117C9D20C2B70C3DCB13A49405C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11075" V="4" DC="SM" EN="Office.Outlook.Desktop.WatsonBuckets" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="1" DL="B" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="500" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <SS T="2" G="{dd5250a9-3404-43b0-9b7a-6f4eaea6497d}" />.. </S>.. <C T="W" I="0" O="false" N="DateTimeStamp">.. <S T="1" F="DateTime" />.. </C>.. <C T="W" I="1" O="false" N="OfficeBuild">.. <S T="1" F="OfficeBuild" />.. </C>.. <C T="W" I="2" O="false" N="WatsonBucket">.. <S T="1" F="WatsonBucket" />.. </C>.. <C T="W" I="3" O="false" N="BucketType">.. <S T="1" F="BucketType" />.. </C>.. <C T="W" I="4" O="false" N="BucketName">.. <S T="1" F="BucketName" />.. </C>.. <C T="W" I="5" O="false" N="Response">.. <S T="1" F="Response" />.. </C>.. <C T="W" I="6" O="false" N="CabId">.. <S T="1" F="CabId" />.. </C>.. <C T="W" I="7" O="false" N=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):553
                        Entropy (8bit):5.324337528685985
                        Encrypted:false
                        SSDEEP:
                        MD5:EAC9B8A2D589F60DC906010BE28B0943
                        SHA1:C71A606EE1260399918EF9E4B36FB478225AABB1
                        SHA-256:909E16EB1A1472781F46F99206D75B833AB32ACF747DD9CAEBE8BC3307F13F0D
                        SHA-512:6B7B9158828899F2C0800572E8FBC9C3BB35C0296B093AE2D3C779823522BD41A884BD0A6066EE37D3E3D31CE3F40FF27229BA92E7142CF1297D1FDF5C0F2803
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11079" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxTeachingUIDisplayed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="TeachingCalloutID">.. <S T="1" F="TeachingCalloutID" />.. </C>.. <C T="B" I="1" O="false" N="IsFocusedInboxOn">.. <S T="1" F="IsFocusedInboxOn" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):369
                        Entropy (8bit):5.429846498860565
                        Encrypted:false
                        SSDEEP:
                        MD5:F61DBC3B4B650703BA58AF33A5A2D98D
                        SHA1:8CDB84CA05D24F38BCC444619148DAE26E08B44B
                        SHA-256:309E04D028BFA631BAA26CCCAE79D1E9D188DB823F45CF86A56B6CC6D4A0B319
                        SHA-512:A97B1CCE4731268785A07B20AD0DD941DC491CD91F76D1968A721B55C79D92D1F533048981DD700F84D8A942E96222EFD7F0E016AA0B2F7E66C1606F4E62C7CF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11080" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxTeachingUITryItButtonClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9021" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):372
                        Entropy (8bit):5.427727701600106
                        Encrypted:false
                        SSDEEP:
                        MD5:2ED8EDF07B15ED59BAB21FFC7AC7FA4A
                        SHA1:EEA6A7E867E0419552C7A2832080EE373DCE304C
                        SHA-256:492FC74DFB62F68D4F48C51A2ED654BF049CC627F81543BF6254B097A0D34EE0
                        SHA-512:056CAD512BAC786B1705092C54C7EAE1B7E257F40607D7D7105C631880B48BEFA4C602F9614FAE604B76D4908A90698730634C8BD64675CF6EBAE287A27F89DD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11081" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxTeachingUINoThanksButtonClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9022" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):464
                        Entropy (8bit):5.3970230136065895
                        Encrypted:false
                        SSDEEP:
                        MD5:F51CF198381787821864100E488050C0
                        SHA1:D5E2C0AA01B78444233F9313E9AC4CF045546664
                        SHA-256:29D3FC01640FBEAA3B5BE1F06AA8869E503B14352FD6DF6EB9A73DD0B791F454
                        SHA-512:1597B777E9FCFD7EDF77603059028DD1D1BB876753BF8BCAEE15C1ECEDA2E6601908BABBAF98658AC7EE102131862E1069077D0B81E9A34DFB8DAB83BCC4F194
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11082" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxNotificationBarDisplayed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9023" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="FShowTurnOnButton">.. <S T="1" F="FShowTurnOnButton" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):370
                        Entropy (8bit):5.408783212821898
                        Encrypted:false
                        SSDEEP:
                        MD5:DA4F6A57B35EB06825AC412CFF62E735
                        SHA1:386C79A047117954967D72212333B1901D72FA18
                        SHA-256:8E4694735A7B1E581FF5A7195A5E04623791D5D471C7AAE5EBEB795FD22C31A0
                        SHA-512:AC193D06A4A131F00C553394C4C996D0D270A4A898CBC06F23CD5DEDBDF86ABE7C615721AEC06DAB10024BEC54DBF4F66385093C3E3F661CE36DA21CF5CFDC77
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11083" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxNotificationBarTurnOnClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9024" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):531
                        Entropy (8bit):5.071960786336559
                        Encrypted:false
                        SSDEEP:
                        MD5:7409FEEB0D6B0A8A42F05CED4BFACACE
                        SHA1:937E335B522B92C78741B184372AF43EF1ACAC39
                        SHA-256:1DF5F8135061CFEC3FADD63BAAFC75A340B5A3BEDC58B091BA1211E365E80A83
                        SHA-512:D476703EF03BA611689BA4EDA668CBC5249D2A0405A822E4F76D56562E2E6B7AED1E6BF05E5E78C93B89B71297247F59CFC7662D49AB19143FD9F33025C8B3F2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110846" V="0" DC="SM" EN="Office.Word.Translator.SelectionTranslationTextTooLong" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9updo" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="TextTooLongCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):949
                        Entropy (8bit):4.980051564356851
                        Encrypted:false
                        SSDEEP:
                        MD5:A86CF21A17F77D4E021AA33FEDC11E42
                        SHA1:FFBCCBFF5EB12C6E44E9DBDFC6A4BBA1EEF41EF9
                        SHA-256:A73BA682ACC3F14A89ACAFC60DFF22023997EF98EEFE79A227C7F0E042C9EAE8
                        SHA-512:7BE911A7F4ECF0D8234D9BB8AB4B27FD1811EB8B45EF060FECED4E53492F763DF62494A2D0F81AFDA573E80ECA5B736266488CE9B57D16D4D6FB2BBD64BC9BDE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110849" V="0" DC="SM" EN="Office.Word.Fluid.ScanFluidLink" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetrySuspend" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <UTS T="4" Id="4ybng" />.. </S>.. <G>.. <S T="4">.. <F N="ScanResult" />.. <F N="LoopStyleType" />.. <F N="ReasonNotHydrated" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ScanResult">.. <S T="4" F="ScanResult" />.. </C>.. <C T="I32" I="1" O="false" N="LoopStyleType">.. <S T="4" F="LoopStyleType" />.. </C>.. <C T="I32" I="2" O="false" N="ReasonNotHydrated">.. <S T="4" F="ReasonNotHydrated" />.. </C>.. <C T="U32" I="3" O="false" N="Count_FluidLinkScanResult">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):371
                        Entropy (8bit):5.408234267240474
                        Encrypted:false
                        SSDEEP:
                        MD5:DDD223FE72590EF5D3DE037E487EF758
                        SHA1:80CA227F059C5EBA62363BC8054BF9E940869B45
                        SHA-256:D7BCCD15F9DE20CE18E47F378799C1078BB820F54DE3CF740074791DF5BC1107
                        SHA-512:773E32D85542F83DE8F080F1F08DBFDE5F025660DC74E58C97517BC57E1E8342CBD14DB94274BED1060360CD27A2B81AF1330ACE508086111F8FB876846684F4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11084" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxNotificationBarTurnOffClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9025" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1343
                        Entropy (8bit):4.635724426944962
                        Encrypted:false
                        SSDEEP:
                        MD5:1F001BA1AA96E45C3FF9BC44DBFC8963
                        SHA1:5D245E6B52F4AA7B7C4E1C3FE6625AB2DB85F20E
                        SHA-256:AD972993EA84933A03079A9F3E112C6019DB6FFB26409C80A56D8C2295413D3E
                        SHA-512:EBBEF5B847EDB5AC00EBE15383F4B01EE8E3471E0C8B6BD4ACACDBE17C95358842169E536493FFB85A35C4A813276F00BA97F13B48561AD618A16A45B98C1476
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11085" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarFocusedInboxEnabled" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsRESTFlowFlighted" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsRESTFlowFlighted" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="FServerSupport" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="EnabledCount_RESTFlow">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1347
                        Entropy (8bit):4.646097144260109
                        Encrypted:false
                        SSDEEP:
                        MD5:84CBC47CF82A47330A784AE9957CC64D
                        SHA1:8F07A2F2ACA323A4AC189F290F935FA6AD271AB7
                        SHA-256:7A8CCC8A370D387A6264BC7EF805A6CE2BA201D7B493EB88744CD1CEBA5FBBA3
                        SHA-512:95EF3A3244FF5F8564166826F364796105420996DE3FEF3F36250080D85C8FDF02D1B9E4949031EA62787BA0BE38215AA342316F7BBF977E66D7F1F616D56355
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11086" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarFocusedInboxDisabled" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsRESTFlowFlighted" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsRESTFlowFlighted" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="FServerSupport" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="DisabledCount_RESTFlow">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1035
                        Entropy (8bit):4.937939971966017
                        Encrypted:false
                        SSDEEP:
                        MD5:BEDC7D76D3EB584E6CDE0219E3D646A0
                        SHA1:E69D3EC713B6DBF12E84BF139418228E48CE7AEF
                        SHA-256:3B27F44566A1640FF356A6B4A1EFF727D6AE4E6156B14F3ABF8B2780BA8C8CD4
                        SHA-512:9BD9B3CC08379FCB481E2A933AC02573A9A2672EA9DA4893E3F749FF4F935CD50202E07A6EFD9CC7E72338FE0705E949EE2EB4F6A1364795FAAA8BC72750589C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11087" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxRESTCall" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9026" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9027" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsRESTFlowFlighted" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountError_RESTFlowFlightOff">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_RESTCallStart">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_RESTCallComplete">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1145
                        Entropy (8bit):5.228908555028965
                        Encrypted:false
                        SSDEEP:
                        MD5:330E39159E0C041A21BF19886C28B3EB
                        SHA1:40F8562B018C980404E432164CDA22894DC3B9F0
                        SHA-256:55AF5363274D38F622013575DFB152BAB70B2DE62748D9637039482AE5295709
                        SHA-512:EB87E63EB123A9E2A3F6AB386DC358E0682D459408DDEFE16940D892CD6363C715A80F290986BEA0A3F38C69B173E1280814424D4153835CEA220F9E402B0E82
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11088" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxRESTCallComplete" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9027" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="IsRESTFlowFlighted">.. <S T="1" F="IsRESTFlowFlighted" />.. </C>.. <C T="BIN" I="1" O="true" N="HashEmailAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="ProfileEmailAddress" />.. </U>.. </C>.. <C T="B" I="2" O="false" N="HasException">.. <S T="1" F="HasException" />.. </C>.. <C T="B" I="3" O="false" N="IsServerStatesLoaded">.. <S T="1" F="IsServerStatesLoaded" />.. </C>.. <C T="B" I="4" O="false" N="IsServerFocusedInboxSupported">.. <S T="1" F="IsFocusedInboxSupported" />.. </C>.. <C T="B" I="5" O="false" N="IsServerFocusedInboxOn">.. <S T="1" F="IsFocusedInboxOn" />.. </C>.. <C T="W" I="6" O="tr
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):663
                        Entropy (8bit):5.268319180309695
                        Encrypted:false
                        SSDEEP:
                        MD5:C673EB904FDF1D48E031797B7886DDE3
                        SHA1:8622FD7804540BB6C66E4D4693B840DA9134B8E8
                        SHA-256:F55002EE1BA7B90A4CFFFFDF0C1D1F079F887183C16D39BA705BD729AAEBDECF
                        SHA-512:67A3CEFCD7A6F9DB49374AD50A58AC420103525E3B2123877B4DC5BE77108F67E3EBE4FB028ACE72273A8616D7AF398B63DC8A4E8C9C776640A35B32D9837735
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11089" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxFailedToGetSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9028" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ProfileEmailAddress" />.. </S>.. </G>.. <C T="BIN" I="0" O="true" N="HashEmailAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="ProfileEmailAddress" />.. </U>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):565
                        Entropy (8bit):5.347294381060564
                        Encrypted:false
                        SSDEEP:
                        MD5:6C2C5FFB8D44DE4B6CE4B16CBF1D30CF
                        SHA1:CED3A42A6C9AE2FFED8C27E5BF3B7BE164467347
                        SHA-256:0C21D37C4A134658E830A1C006A0712242324BD0792E56319C9153345D1143F4
                        SHA-512:8859A3AB916D198C1EBEB47710C4C8F29E37ADC9CE18757A11C29E10560B1980AF387E127DDDA6061DF51E0096064B2FE9524F08A6FBE222CFF611BD704BB9F1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11090" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxFlightOn" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9029" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="IsRESTFlowFlighted">.. <S T="1" F="IsRESTFlowFlighted" />.. </C>.. <C T="B" I="1" O="false" N="IsPersistentRollupFlighted">.. <S T="1" F="IsPersistentRollupFlighted" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):656
                        Entropy (8bit):5.266694121763147
                        Encrypted:false
                        SSDEEP:
                        MD5:16857CF79774453BE038844C2613322B
                        SHA1:757DD1FFBB252529AEFF2A9598E1255C158DD982
                        SHA-256:9F2C981E892DBB15AE220338A719710E0DEB52BA10BDC90FDC058B6599DE353E
                        SHA-512:90A1EE78FDE0B68E0F325024DEAADFC348C6D06A026DD50032641D1A969D085237A811D95A47A448A86B8B7898A4D71F847DD40137FECB47B3184CA13AB25FD4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11091" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxNotSupported" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ProfileEmailAddress" />.. </S>.. </G>.. <C T="BIN" I="0" O="true" N="HashEmailAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="ProfileEmailAddress" />.. </U>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):532
                        Entropy (8bit):5.290779593040958
                        Encrypted:false
                        SSDEEP:
                        MD5:57BDF25EA9F3B5B82A954E6EDA5B0FF1
                        SHA1:40734CB9BDB9BDC9BD6A0841F75964F15F5073F2
                        SHA-256:2EFD6D1837169B242A5611CC42A17F93E9516158D53FF0A03F7A025BA38A04F4
                        SHA-512:900728477D4C6A2680AF65367B6C6FA8C3B8B5E6701E8D123E33AE21339CB839F6B91785CBFD1A17E7FD198BB5F69B6B0EEFF4EF598DFAB0A9FCED8C921853FE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11092" V="0" DC="SM" EN="Office.Outlook.Desktop.LogSearchRibbonClick" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9050" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="U32" I="0" O="false" N="CurrentModule">.. <S T="1" F="CurrentModule" />.. </C>.. <C T="U32" I="1" O="false" N="RibbonButton">.. <S T="1" F="RibbonButton" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):749
                        Entropy (8bit):5.077488936487919
                        Encrypted:false
                        SSDEEP:
                        MD5:018A633544DD3ABB859B1A1029CA020D
                        SHA1:08229C708F1B379CB0578530DE4F4A6C31AED00E
                        SHA-256:6557156A98DF573542B3A1B23420EDC320A2EEEAAC95F9358CFD67EF4529319F
                        SHA-512:A3D9494CBBE763D9B3D0AC1E69AF3CC615E8795F226AD254BE346CF9BD3665B2CFC157B12E0F7D90C15C4BAE0EA02D9926467EB7F77E0F91B540FF95389EF991
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11096" V="1" DC="SM" EN="Office.Outlook.Desktop.CreateGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp2a9" />.. <UTS T="2" Id="bp2ba" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ShowDialogSucceed">.. <S T="1" F="ShowDialogSucceed" />.. </C>.. <C T="B" I="1" O="true" N="ShowClassification">.. <S T="2" F="ShowClassification" />.. </C>.. <C T="U64" I="2" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):913
                        Entropy (8bit):5.026023989924222
                        Encrypted:false
                        SSDEEP:
                        MD5:434B92AC6B88E71B6CB59359154FAC58
                        SHA1:27E65831C9BEEE91FBBC717C8BE63EF4199FD9CA
                        SHA-256:38BFC1204F278539642546B7A220969675B78FF07A45B6AF64139565D9A7EA1A
                        SHA-512:274387D0465816B340E93421F42B139B1603ED2968EF72FB9EAFA364C680456EEEBEC58E11DF004DA53DF29C8F86DD7C5C774D4B4D448CC4AD4C6D3B0411589E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11102" V="0" DC="SM" EN="Office.Outlook.Desktop.EditGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp2a2" />.. <UTS T="2" Id="bp2a3" />.. <UTS T="3" Id="bp2a1" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. <S T="3">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ShowDialogSucceed">.. <S T="1" F="ShowDialogSucceed" />.. </C>.. <C T="W" I="1" O="false" N="DialogType">.. <S T="1" F="DialogType" />.. </C>.. <C T="B" I="2" O="true" N="ShowEditPrivacy">.. <S T="2" F="ShowEditPrivacy" />.. </C>.. <C T="B" I="3" O="true" N="ShowClassification">.. <S T="3" F="ShowClassification" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1395
                        Entropy (8bit):5.072738988798792
                        Encrypted:false
                        SSDEEP:
                        MD5:EA569CBA4DB954E20894495C4BDCFDE4
                        SHA1:561B85EFB7E1A9B27DBC6FA8E3E434952B3D0511
                        SHA-256:35E439EA2569A2BA5A09FC08A97DBCDE37F9ACCF58163B73354FE2603BB3929D
                        SHA-512:CFA98B30861616ECC0E37DFBF415C4ADF908BA4A2F7EF4380E97D912E4B766FFBDC67503E0843A43161CCD461760789909F77DD6C660CB2A01BBCC344BF97C91
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11104" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentShareFileOptionCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4274" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4275" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4276" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4277" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="4278" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ShareFileDialogAttachAsCopyCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ShareFileDialogAttachAsWebCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="ShareFileDialogCancelCount">.. <C>.. <S T="5" />.. </C>.. </C>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1982
                        Entropy (8bit):4.648057580910169
                        Encrypted:false
                        SSDEEP:
                        MD5:CB6EB639CFDF57AA1354E0AD4E581957
                        SHA1:4C91C427EBAFFAB4479A2F5E6664252B55EB15D8
                        SHA-256:6F42248A034638CCE76674F3ACDF22F19DDB2901E1670B7D4C57BC9A2E44E256
                        SHA-512:14CC4EE1798597B2AF62AAAC210AA38469C634BBAAC3FFDE59206E89A1A262CD68B80422E433E3DFA13301FA1A7C453ACB6982E938E6747C7BA00E73FC9FB55C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11106" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupMessageSendMailInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="isNewMsg" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="isRepliedMsg" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="isForwardedMsg" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. <F N="hasGroupRecipient"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):538
                        Entropy (8bit):5.338092620719237
                        Encrypted:false
                        SSDEEP:
                        MD5:E7534020B03BA0562F7DCFB8DD5538B7
                        SHA1:91FFD1732E0FB8D6A2A7300B241EA87941AF9C5D
                        SHA-256:DDFB07E10F24E21CD30732DF0E090C3F8F4C5975C77BD4BF10C2B6EB1FD9B374
                        SHA-512:395EBA0B34C646ED338D7B52BE1F90E478EDD4F0E9AF3B758205C06CB479C48E3391D2E174536E3399F0C33DDB2A22FD1CB12A89C4FF079567F11462A2675A16
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11107" V="0" DC="SM" EN="Office.Outlook.Desktop.OutllibCreateGroupInfoEntrypoints" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18035" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="EntryPoint_col">.. <S T="1" F="EntryPoint" />.. </C>.. <C T="I64" I="1" O="false" N="HRESULT_col">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2282
                        Entropy (8bit):4.409524457203998
                        Encrypted:false
                        SSDEEP:
                        MD5:F3064FE3D49A826086BE8CCD950EF8BC
                        SHA1:9FBEF51FEBF1DE8B441E475AD57A45FCE94B869F
                        SHA-256:4C4166AD9AB54A32A408A8F86A44F7B9F534BC6E661EA7CD6DF27946E582C0C8
                        SHA-512:F624F4FD9B2CF695AC72B7F3F1E548FB6AB9A4EAFAF631B2BBD4BDF0603A3807F9639461641D42FAEBA3C9575B4B063DC5E582774DFF245E6B1B20F9AA3DC423
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11119" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxUsageOfMapiForEwsUrl" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bpfyo" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Found Urls" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="GetSession" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="OpenProfileSection" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="1" F="GetExchangeProps" />.. </L>.. <R>.. <V V
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1028
                        Entropy (8bit):4.926041018320489
                        Encrypted:false
                        SSDEEP:
                        MD5:86CD69D0904A1205493FFCD522675CC8
                        SHA1:06BCDDBE3333B916AC2301744CD8475217CFCF0D
                        SHA-256:E941CC8E6BDFCB9BC5EC7B0D7812EBB238369CB0BFFD74CF98E081755DB46BB4
                        SHA-512:3DAC9FFBC74A491F106A7C29110AE0C72A2B52BA561AAB63FC1666D3C2192B761FB3E210802BAD117C858CEBF88A424D1C5D3D1F8EA9E8B4D2B4C0ACC0E35B4A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11124" V="0" DC="SM" EN="Office.Outlook.Desktop.MOTWErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4272" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4273" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="3">.. <F N="Response Code" />.. </S>.. <S T="4">.. <F N="Response Code" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ResponseCode">.. <O T="COALESCE">.. <L>.. <S T="3" F="Response Code" />.. </L>.. <R>.. <S T="4" F="Response Code" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="MarkSetOnPasteCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="MarkSetOnSaveCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="1" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):959
                        Entropy (8bit):5.100543856970387
                        Encrypted:false
                        SSDEEP:
                        MD5:487DEA9021FE4B6251A7861483702EF9
                        SHA1:71F81B29374656F49B95AC4275C07C70D1D01E42
                        SHA-256:EA3E2D1DDC9E49B8BCB676FF4BC66CB5C0400F310815D78CD04D76FBD43BA27C
                        SHA-512:A8A76A593CCCAA1FC2A893A53B50B320C40CB742D90B2939E7154D8B80CC1969D487F903035003EC3CFB725007E8BE5077A22AC37CF696ACDB462A71B1B0FD86
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11125" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSharingLinksResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4280" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. <F N="UserPermissions" />.. <F N="CloudProviderType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CloudProviderType">.. <S T="1" F="CloudProviderType" />.. </C>.. <C T="U32" I="1" O="false" N="UserPermissions">.. <S T="1" F="UserPermissions" />.. </C>.. <C T="U32" I="2" O="false" N="Result">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="3" O="false" N="UpdatePermissionsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):850
                        Entropy (8bit):5.154756037432071
                        Encrypted:false
                        SSDEEP:
                        MD5:90D628F2EA0A71FA980A247C31B4F812
                        SHA1:DEE7FAB3F3BAB336DFC3BBAF3D899CC97CE0719D
                        SHA-256:0A90B22D6684EE935E796F616325CD8A7A52C2BEF02F9CFA5BBA876D68ECD670
                        SHA-512:15506FB8422AA44E468EFBF131E819ACFEB1C361D0751177B191F9E8BF6FA56F2EA676DDE1045B9B2F9D6300E035390226DCC55331645FC6BF92DCB8214F0DF2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11126" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSharingLinksOperations" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4279" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="UserPermissions" />.. <F N="CloudProviderType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CloudProviderType">.. <S T="1" F="CloudProviderType" />.. </C>.. <C T="U32" I="1" O="false" N="UserPermissions">.. <S T="1" F="UserPermissions" />.. </C>.. <C T="U32" I="2" O="false" N="UpdatePermissionsClicked">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):834
                        Entropy (8bit):5.153122491280767
                        Encrypted:false
                        SSDEEP:
                        MD5:AAA8DD780F5A47A8BCA512F230780E2C
                        SHA1:A434B2FC83BDCEBE12E98952132F65AF59736163
                        SHA-256:2FCB148A3E28BA1C798CFB11813186FF52286BDA4091EE3D2342B566ED16A191
                        SHA-512:C4D0FF257583720AA56AC5B97A370E2A9D0BCBC4367D16C28EA15F818D9554E62BCFA6C56CD8F4EDE76DA272A2D16DE5F1E4099FD971EA92EA88B7986CAFAA6F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11127" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSharingLinksDownloads" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4281" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. <F N="CloudProviderType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CloudProviderType">.. <S T="1" F="CloudProviderType" />.. </C>.. <C T="U32" I="1" O="false" N="Result">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="2" O="false" N="SharingLinkDownloadCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):630
                        Entropy (8bit):5.192677545053228
                        Encrypted:false
                        SSDEEP:
                        MD5:AE3F7F32C3F00C4F6668B8CCAACF60F1
                        SHA1:EB578727380E6F78B8B35B9F671E1F1AA0438C99
                        SHA-256:E0744BE090D2F698C51AB106EF592A71E430C18E0973648FA7BB3F0444902462
                        SHA-512:3246C68E5A2DB841CF7036283A140CDFA33B8129A5330F7BA172BB21E63625C4BCDF55ECD1A921BB85EBE16C55F8728D59F3901715714656A677BFC86227E345
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11130" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupDeleteConversations" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19023" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="TotalDeleteCount">.. <S T="1" F="TotalCount" />.. </C>.. <C T="U32" I="1" O="false" N="SucceedDeleteCount">.. <S T="1" F="SucceedCount" />.. </C>.. <C T="U64" I="2" O="false" N="OperationResult">.. <S T="1" F="Result" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):593
                        Entropy (8bit):5.235519951612897
                        Encrypted:false
                        SSDEEP:
                        MD5:6516C5DBA9DBB502515682865A8D3F32
                        SHA1:0B2485795B2387954DD520EB822E3FCB4E4D89EC
                        SHA-256:D2B8B5C01BA76B96858610F9B673C887D77C66BEC6DC9D2E02BC5FAEDFFE202E
                        SHA-512:5AA4DA98FC3BC0E2E876D827F1C324586CA68E5196464EDC20D1146C249CC48ECAFE49CBA5DFDA9596D6180E482F0E125895483728A5BAA854DFC82C0DDCD998
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11131" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxUnseenMailHintUpdateFailed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9035" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="UnseenMailHintUpdateFailed_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):824
                        Entropy (8bit):5.142376140104951
                        Encrypted:false
                        SSDEEP:
                        MD5:F85461A042961806E055FD3FEE57ECF0
                        SHA1:C55958451361185733907D5730B31A2E20B989F5
                        SHA-256:51DDEFCC83443CA7EBC23B7200EE942A423749AB98C7909CF2B73EED3474A40A
                        SHA-512:204DBE944443DC7CFA570D49099C01BA144F20DDD866A433DFAD192880032F9DE9F79CEFBF1D0F7B646E769B66E6D15E634ABF0B9211F737C018A737F3EBA64C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11132" V="0" DC="SM" EN="Office.Outlook.Desktop.NonFocusedMailLastSeenTimeUpdated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="PivotSwitched" />.. <F N="AcctID" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="PivotSwitched">.. <S T="1" F="PivotSwitched" />.. </C>.. <C T="U32" I="1" O="false" N="AcctID">.. <S T="1" F="AcctID" />.. </C>.. <C T="U32" I="2" O="false" N="NonFocusedMailLastSeenTimeUpdated_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):952
                        Entropy (8bit):5.1117438109037545
                        Encrypted:false
                        SSDEEP:
                        MD5:595CC4F8BE73A12FE75C8A806D1EDBF6
                        SHA1:AFDCD9D3A18F2C0BD7A712CADE612797D85BBE09
                        SHA-256:24D7FC00CE2CFC47CCA33CCE3E10932F879001DB6035BB046DE5B2206276252F
                        SHA-512:6C400FAFD6394EE1B98772204AD9554F3675FF340A4AF00FE512EC758A6E1DA91547CE43587F2E047F0BBCC6F499C23B066A46A412950BE46DB81CDEF08F0875
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11133" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxNewMailDeleted" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9033" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="PersistentFlighted" />.. <F N="NotifyFolderBar" />.. <F N="AcctID" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="PersistentFlighted">.. <S T="1" F="PersistentFlighted" />.. </C>.. <C T="B" I="1" O="false" N="NotifyFolderBar">.. <S T="1" F="NotifyFolderBar" />.. </C>.. <C T="U32" I="2" O="false" N="AcctID">.. <S T="1" F="AcctID" />.. </C>.. <C T="U32" I="3" O="false" N="FocusedInboxNewMailDeleted_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1114
                        Entropy (8bit):5.120273076186503
                        Encrypted:false
                        SSDEEP:
                        MD5:8A8C5F25D544093337E42EB0E387F977
                        SHA1:541A2F2C9E39A3735DF3B30F9BF3CFAD56B4B70F
                        SHA-256:4A405E335E983AC00337ABAC09DFF8246450083EE8EAE72B45EE692022FFB6F8
                        SHA-512:CEBE824BD7F2B7A445CA3F4A3E72EFCC9224485ADEB983D5BCA9118D9CEB15DC3F012BAE69B63347F395C871B31F00736B9B4437509C008E922111D8E45D984B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11134" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxNewMailReceived" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9032" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="PersistentFlighted" />.. <F N="FocusedOtherPivotsBothActive" />.. <F N="IsFocusedMail" />.. <F N="AcctID" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="PersistentFlighted">.. <S T="1" F="PersistentFlighted" />.. </C>.. <C T="B" I="1" O="false" N="FocusedOtherPivotsBothActive">.. <S T="1" F="FocusedOtherPivotsBothActive" />.. </C>.. <C T="B" I="2" O="false" N="IsFocusedMail">.. <S T="1" F="IsFocusedMail" />.. </C>.. <C T="U32" I="3" O="false" N="AcctID">.. <S T="1" F="AcctID" />.. </C>.. <C T="U32" I="4" O="false" N="FocusedInboxNewMailRecei
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1323
                        Entropy (8bit):5.029645583635853
                        Encrypted:false
                        SSDEEP:
                        MD5:F9D54A9BC63E2B5565F18226BCDD007E
                        SHA1:061224F66767F8CA3FEFCC3882BF516DA7558AB9
                        SHA-256:0B47D82F87628644363A248A5E9E23F1522C4304D0773DA5FDFADBE2F6C9079D
                        SHA-512:C64A04019B768F61F58C344B08AFFCD29A82010B49F2532444DF0F84563CF7FF05013FFA9F06D8303CB87F65739A4908C8631969075201D201DEB6473BA979D5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11135" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxUnseenMailHintUpdated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="PersistentFlighted" />.. <F N="PivotStateChanged" />.. <F N="IsUnseenOther" />.. <F N="AcctID" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="PersistentFlighted">.. <S T="1" F="PersistentFlighted" />.. </C>.. <C T="B" I="1" O="false" N="PivotStateChanged">.. <S T="1" F="PivotStateChanged" />.. </C>.. <C T="B" I="2" O="false" N="IsUnseenOther">.. <S T="1" F="IsUnseenOther" />.. </C>.. <C T="U32" I="3" O="false" N="AcctID">.. <S T="1" F="AcctID" />.. </C>.. <C T="U64" I="4" O="false" N="FromCount_Sum">.. <A T="SUM">.. <S T="1" F=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1397
                        Entropy (8bit):4.195903641436885
                        Encrypted:false
                        SSDEEP:
                        MD5:A7A57E426AD19A469010B949C97041C6
                        SHA1:48AFDE6DB9943EA3D02FE5B8825153C842222390
                        SHA-256:6AD48E6E1CFB811DCC296D566166457E13654D95CFDF4AB754069DF7F9B02280
                        SHA-512:9DBB8F36F1032BD09A099A9E3B7F9F8E99F822B53505FD88718D7C55CAEFFC9B1398E3386B924420A4C9499FC36CAC63433320002DD47872BCCB59B81A466045
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11148" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="5001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="5002" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="5003" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="HResult" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="ECode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="MessageID" />.. </S>.. <S T="2">.. <F N="MessageID" />.. </S>.. <S T="3">.. <F N="MessageID" />.. </S>.. </G>.. <C T="U32" I="0" O
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7129
                        Entropy (8bit):3.522339906281867
                        Encrypted:false
                        SSDEEP:
                        MD5:FF1264033DF0F31BD4C5DE4D8005E5F5
                        SHA1:44B5AFDDC8AD7FFA6FB0128A519B65103045AC45
                        SHA-256:0AADB50C7A5F8B1338714175F9F7919CA38E906BD3E4F5BA75CE621D5E8B1055
                        SHA-512:753CCE25B9EE50F0B1DE05A366BD52996EE807BD339461A5D16215A83178975C2DAAB1B517497D86A2AEACAD2B09B3F1A506F592D5D822F7C52A9B9394C838F3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11149" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageSubmissionTimeBySize" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11148" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LE">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <V V="32000" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <V V="32000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="4" F="0" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):851
                        Entropy (8bit):5.004292807629403
                        Encrypted:false
                        SSDEEP:
                        MD5:EB35D36DAEE1084DEC8E571B7F0E1323
                        SHA1:C25FCFC9DC9ED572DAC19A84A3A92FCC73767DFA
                        SHA-256:10DE6C430C3C6AA6586659FFF4AC370DA02E94886FDBB42E273FF8851F2CAD06
                        SHA-512:4F412CD23FFAF44AB105E264607616CD3C68301F8B427EB6ABF1DFBD099596F149F2B0320AF0FE7541BB478FC8CB105BD27DCD224F47856B796085E7323738CD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11150" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCardUpdateFunctionErrorStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="brj1a" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="callName" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="CallName">.. <S T="1" F="callName" />.. </C>.. <C T="I32" I="1" O="false" N="ErrorCode">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="ResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U64" I="3" O="false" N="CardVersion">.. <S T="1" F="CardVersion" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6339
                        Entropy (8bit):4.309149130319048
                        Encrypted:false
                        SSDEEP:
                        MD5:1FDAC24EF74A224774ED57F3BE2091D7
                        SHA1:F471BBE0FB6EB3A480CF04B9DADABBFE7A20D129
                        SHA-256:7ADB414D0169FD0D44080B0064D52018C16275D47EC195A871DBB54712F7C21B
                        SHA-512:DADF8D729E2DDFEE9A866A93C35EE5B0F2E683375783524552DBC48CDD45F51F356AA4C82C9736A16F7A0C6321261DF337C201DD6F7EF801364B343296D05D53
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11152" V="5" DC="SM" EN="Office.Outlook.Desktop.SearchSessionDiagnoseData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7095" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7111" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7112" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="Notification Type" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="Notification Type" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GT">.. <L>.. <S T="3" F="Count" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):848
                        Entropy (8bit):5.216788041675516
                        Encrypted:false
                        SSDEEP:
                        MD5:33C81A29A14B55C0DCA63A4E26901587
                        SHA1:68A8E8416E825B6980A38F22D6B5CB4BAFE9CF13
                        SHA-256:AF1C61DD2A5D36635F83E98A7390A76DBE9281247F5A7BB6AFCD92DBFAAC0A10
                        SHA-512:E93D68D7B0D85C4DB117E04C2B5F87382A0F9AEB1CCE8AFB99FBD358C96C1D6923E9C199C8F5A406094CCFBFA9D029856B302897D2F7C6EFC7E4C1DF698A2CFB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11153" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentFlexibleWidths" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4283" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfAttachments">.. <S T="1" F="CountOfAttachments" />.. </C>.. <C T="U32" I="1" O="false" N="MinimumAttachmentWidth">.. <S T="1" F="MinimumAttachmentWidth" />.. </C>.. <C T="U32" I="2" O="false" N="AttachmentWidth">.. <S T="1" F="AttachmentWidth" />.. </C>.. <C T="U32" I="3" O="false" N="AttachmentWellWidth">.. <S T="1" F="ViewerWidth" />.. </C>.. <C T="B" I="4" O="false" N="DidEllipsify">.. <S T="1" F="DidEllipsify" />.. </C>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):739
                        Entropy (8bit):5.056249384079234
                        Encrypted:false
                        SSDEEP:
                        MD5:538857315D6B1EC91EF9D56A7005623F
                        SHA1:2199F2660C4C527C1CF69582A0408559CAA5EE13
                        SHA-256:E41E45745B00A33EB0C399A33E26D69B069B4515C7A308D279585A677EF49F2F
                        SHA-512:DA0F16BB6C90DC1C36FACA35BA5A5050A25BCA7D691B59EB0986E90C1B7EB758D2969C1F70176EFDC3ADDF3E8231568B4DD838436BB743735696A3B04EC3DB70
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11154" V="0" DC="SM" EN="Office.Outlook.Desktop.PCXDataMode" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bq4zg" />.. </S>.. <C T="B" I="0" O="false" N="IsLdap">.. <S T="1" F="IsLdap" />.. </C>.. <C T="B" I="1" O="false" N="IsMapi">.. <S T="1" F="IsMapi" />.. </C>.. <C T="B" I="2" O="false" N="IsInOutlook">.. <S T="1" F="IsInOutlook" />.. </C>.. <C T="B" I="3" O="false" N="IsOutlookInstalled">.. <S T="1" F="IsOutlookInstalled" />.. </C>.. <C T="B" I="4" O="false" N="IsOutlookConfigured">.. <S T="1" F="IsOutlookConfigured" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1074
                        Entropy (8bit):4.958384324853739
                        Encrypted:false
                        SSDEEP:
                        MD5:3AA553A5E9E406922EBA18E22A13DAD9
                        SHA1:8399FC68DB51EAD7D94063ED8DBD539304F88D5D
                        SHA-256:543BB15CE9323286034183A4654003E40E2695330155EEFC7D2A3CF67B7FF064
                        SHA-512:516B809B3A817357537E115195941870476381B3BAA144CF40E7AF88183BEACE77BE62EC6E4C54A1552B02DEDD2A694546698E4F8A2D477B4B7D9431DFF63BDD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11156" V="1" DC="SM" EN="Office.Outlook.Desktop.PCXQueryPerfMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bq4zq" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="PersonaQueryStart" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="QueryType">.. <S T="1" F="PersonaQueryStart" />.. </C>.. <C T="U32" I="1" O="false" N="CountQueries">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="I32" I="2" O="false" N="MinMilliseconds">.. <A T="MIN">.. <S T="1" F="MillisecondsSinceStart" />.. </A>.. </C>.. <C T="F" I="3" O="false" N="AvgMilliseconds">.. <A T="AVG">.. <S T="1" F="MillisecondsSinceStart" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="MaxMilliseconds">.. <A T="MAX">.. <S T="1" F="MillisecondsSinceStart" />.. </A>.. </C>.. <T>.. <S T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1163
                        Entropy (8bit):5.045711084228782
                        Encrypted:false
                        SSDEEP:
                        MD5:CCA7C41188FC9A1AC5342B5228D07EC1
                        SHA1:A23ACFFFB1632A72B1D84D3E90F0B39EE12A46E3
                        SHA-256:13708C2187251CE813DEA2EC42AEF5792F66870E1328D63501A7305B60FED0D9
                        SHA-512:1350E3E069D69FF46E4949540188EFAF710B6C922B6B7415C60221211D9606E7A75C8DF0DE535DC465E9A04CC69D6596DBF2C39EB9C08BF7F25B339A0759563F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11158" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSharingTips" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4284" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4285" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="4286" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="SharingTipType" />.. </S>.. <S T="2">.. <F N="SharingTipType" />.. </S>.. <S T="3">.. <F N="SharingTipType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SharingTipShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SharingTipHandledCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SharingTipDismissedCount">.. <C>.. <S T="3" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2953
                        Entropy (8bit):4.792625981125227
                        Encrypted:false
                        SSDEEP:
                        MD5:4B93D5493004BA2F0F53E90019519B4B
                        SHA1:861F07ADFDF813A75C8F39937AB132F1759C6BE2
                        SHA-256:42243DFC319543719B0F94C3655D67DE3109834133A61ACEF80673BDD7102D1A
                        SHA-512:8BADCC90145FB6E3A3537A83D51DF3F80F5A4BE3F26EF3BF73F71ABA65BB911759E863C418F8083C1B6F321938A93EF82B9510B71321B617EAF329830CCC06D1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11162" V="0" DC="SM" EN="Office.Outlook.Desktop.MOCOLoadingPerformanceAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20063" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TotalLoadAndPaintTime" />.. </L>.. <R>.. <V V="60000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GT">.. <L>.. <S T="1" F="TotalLoadAndPaintTime" />.. </L>.. <R>.. <V V="60000" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="IsValid" />.. <F N="GroupsStore" />.. <F N="ClientSideBFLCalculated" />.. <F N="ThreadHistoryCalculated" />.. </S>.. <S T="4">.. <F N="IsValid" />.. <F N="GroupsSto
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1701
                        Entropy (8bit):4.224682186988357
                        Encrypted:false
                        SSDEEP:
                        MD5:9770B9C5943FC8F4DCA23F615FD0292D
                        SHA1:7C4D31950595F68ED2696F8BE5F1271A3B4327A4
                        SHA-256:13A2DB5BAD137FFEEF88F50A1EE689B38197C141EA7E2B065B317E09B6134F89
                        SHA-512:DD37B2AF11E746894352CA69FF54A40B67572804480D4DDCFD07556AEE68464717D53C1CA57339A3F743C0C83ED78BD4C8ECB111782E0CCD872E448625BB57CD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11163" V="0" DC="SM" EN="Office.Outlook.Desktop.PCXPersonaPhotoTypeCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbo5v" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="photoType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="photoType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="photoType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="photoType" />.. </L>.. <R>.. <V V="3" T="U3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):701
                        Entropy (8bit):5.135260171695497
                        Encrypted:false
                        SSDEEP:
                        MD5:A18B082A340DF776F833D417B0922F87
                        SHA1:F4E05A987351A211FB1DD8DEE6D2511FA11A7AF2
                        SHA-256:328A473B6ABE3FB3C7025A7EDDF1F1692C3F0712CD8F708DE603E623C8DE4667
                        SHA-512:809B34479D125F7520D96EBE8BFE8900CA6E691A4657F0398C56BAB98B367D7550AF332D72EB9BC351F79C3DD6301ACC5E9AE95D4AE2C8DDCAF2C346AB596C8A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11164" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSafeLinksFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4270" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Response Code" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SafeLinkRedirectFailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Status">.. <S T="1" F="Response Code" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3372
                        Entropy (8bit):4.675396383546389
                        Encrypted:false
                        SSDEEP:
                        MD5:959F727C4220C3CC69F60AD4CB01B073
                        SHA1:197EE910D2253B2E4FF13530CE5C7D6C35AC4F2D
                        SHA-256:EB1F6DA83D628E91CD802CAAD414C7CC6D7EAC016FC5FBFA5C13C31CD2C589F5
                        SHA-512:A3F95C7C1040E81EDDD8F41A4C50218BE0427A4EB5AFBBD8FB24EA01DEAB170DF7E22F59751FD81E10E4E14B381FC91AA15E412DBED2110CE634D18147ACB3BF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11165" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemWatsonDataUploadToSARA" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3752" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3751" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="396" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="Function" />.. </L>.. <R>.. <V V="WatsonCrashLogReader" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="FunctionName" />.. </L>.. <R>.. <V V="WatsonCrashLogReader" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="Function" />.. </L>.. <R>.. <V V="DiagnosticsEngine::HrE
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1238
                        Entropy (8bit):4.98505666113289
                        Encrypted:false
                        SSDEEP:
                        MD5:24CAB8EF1EC531060025B7E7F7AFBBCD
                        SHA1:CCB4808088860C248D760703B4D48E7C25B41319
                        SHA-256:D8784873681DFC28A2350F8C4F115A476649950FB6FA7E85DA041CB25557EC4B
                        SHA-512:AF18475EC9E096D863549FEB2380F76E62CF3E4978EB77FF52349BA08C63B94D0EA1F5BD9C37C4E747E4ABE055168C0639EE8E9827D59D0194BCD5474334CB56
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11166" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupDiscoverDialogActionCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="18054" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18055" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="18030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="18016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="18020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="18019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ViewGroupCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SearchGroupCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="JoinGroupCount">.. <O T="ADD">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):4.935772465051499
                        Encrypted:false
                        SSDEEP:
                        MD5:5D83411D643AFE6E56C6D58F4DC37261
                        SHA1:101C3111D64368E5BCF18EE6B3F1CDD2FDE98F8D
                        SHA-256:D6523A85C81AE6FC64FFD6B2BD0C22DEED1A9DD477E7DC16ADCCB0BCFA972D34
                        SHA-512:1A5BA95124F3604C783B5B47DE138D03BE8903D06D5566AF8AA9EA859A02F5B2EBF3CA7319F6BC054D7255A0D650CD37420D3DCCCB2AEC26D333CD0CFF96BA56
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11167" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3500" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="3541" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <S T="1" F="Folder" />.. </C>.. <C T="B" I="1" O="false">.. <S T="2" F="fIsGroupFavorite" />.. </C>.. <C T="B" I="2" O="false">.. <S T="2" F="fIsPrankieEnabled" />.. </C>.. <C T="U32" I="3" O="false">.. <S T="1" F="Position" />.. </C>.. <C T="U32" I="4" O="true">.. <S T="2" F="wunderbarModule" M="Ignore" />.. </C>.. <C T="B" I="5" O="true">.. <S T="2" F="fIsShowAllGroupsInCalendarEnabled" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2014
                        Entropy (8bit):4.321463372728563
                        Encrypted:false
                        SSDEEP:
                        MD5:DE886F445652EA33C62478208ABAA0E7
                        SHA1:3D6E0B69D01C5865EA036E493849D6B7A50F1013
                        SHA-256:6959B688F7F440A2F75093FFDEC21FDC1EA5EB5BC831140FBDE4A49026CA6A92
                        SHA-512:F9DF25165B2226C755178B909842ED28C86B01B3880EE9D1E4D1E20A9CEB58000B2C2DE29F04D47D45D8E95DB11D9C70D489901186B9BA3FA11373301AA66DF7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11168" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupsWunderbarNavigation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11167" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="3" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <O T="GT">.. <L>.. <S T="1" F="3" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="0"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):731
                        Entropy (8bit):5.253364580347691
                        Encrypted:false
                        SSDEEP:
                        MD5:0D5C5A2484123BB2F44013F5A652AD8F
                        SHA1:3A6CE5FDC54B9725B608762392129273351F04AF
                        SHA-256:6DEBDAF09FCF98C97C8289B0654FF9C1D147FA1070A0EF3C91E41D8988B9CF7A
                        SHA-512:6D7154128D219D2944D46E6F3D1D271B25C1CF1AC1E9E045ACEBF1A8471D9D8A991783629EDE2DFF3A4FE3F74FB5CC3D4ADF1A3887A55170366F46BA5C07A1B2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11169" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupDiscoverViewGroupInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="PositionIndex">.. <S T="1" F="PositionIndex" />.. </C>.. <C T="B" I="1" O="false" N="IsJoinedGroup">.. <S T="1" F="fIsJoinedGroup" />.. </C>.. <C T="B" I="2" O="false" N="IsSuggestedGroup">.. <S T="1" F="fSuggestedWindow" />.. </C>.. <C T="B" I="3" O="false" N="IsSearchResult">.. <S T="1" F="fIsSearchResults" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):459
                        Entropy (8bit):5.354125551481706
                        Encrypted:false
                        SSDEEP:
                        MD5:CF5E88511F776771DA7A4678EC350DEE
                        SHA1:531B92E28344965192911304313342F4365B4B1D
                        SHA-256:50030509C930D96729E533F2710AE145C1E144EDDB57406A1E356C654835B461
                        SHA-512:46F6449D3C36263611AB8CBCB7A7E7215052FC0A7DC971D2953FB4FB2F9A71BD4E9E1E36D81607C57C6E03DB226105161CAB1223B467291A822056266E0D5340
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11170" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupDiscoverJoinSuggestedGroupInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="PositionIndex">.. <S T="1" F="PositionIndex" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):556
                        Entropy (8bit):5.327714710979507
                        Encrypted:false
                        SSDEEP:
                        MD5:8613B868FB96672F81818BAC7A382752
                        SHA1:E44907281CAFA8A891284B8E83012BE6C11C362C
                        SHA-256:7FFF01238BDCFAC5E62010041E23AA93522BD2214E7EF0CF812C7FE42BE71B7F
                        SHA-512:BF1642017D5662685791042A043C8C44CFAADE4A2F18D5769445BC7D3E92AB876C33CE64A8E27C1011ECD3C250846D6EAC0A19C22F37BA9532A564A82FAA9F1F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11171" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupDiscoverJoinNonSuggestedGroupInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="PositionIndex">.. <S T="1" F="PositionIndex" />.. </C>.. <C T="B" I="1" O="false" N="IsSearchResult">.. <S T="1" F="fIsSearchResults" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.7171029065635155
                        Encrypted:false
                        SSDEEP:
                        MD5:21E74C6504E1E8E129B3609C36B65706
                        SHA1:83E6BEB150FF7519ED0664F1F5A4D4E0E30D0E2B
                        SHA-256:088DE418B0458309EBA01A3FE3031ADA485ABCF19F4E0018861AFC63ADF1D3DC
                        SHA-512:6E8C2E2C6006E7162CEBCF517A83B3EC46E9E354E7AAD8EF5BBFAD5F2D191BB15C48C36FD3C2500A080E7A60F4DBB54115F81D3BF55714BECD6580F202F62A7F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11177" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="22620" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22629" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1209
                        Entropy (8bit):5.0385539832174215
                        Encrypted:false
                        SSDEEP:
                        MD5:71602D96702503BFDA677FAA957169F4
                        SHA1:7F6DFD2E46AD8E5AE1D763ADD83A132B5C3FC5A3
                        SHA-256:6EABCE57C0FC2EDF575053D3A82EC20DB789D7572588DBFE9EB159A29B852DF2
                        SHA-512:84C8E4ECC6683A783ABFED4C2FDC9D0C71FDDA56AD79F0523682DBAD6BA1562396E10B7EAEEC7C3E082FBD7D03D883D439CAC448CE8D98F22B5DD02D9D6BF993
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11178" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGalleryPerfAllRule_Time" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11177" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <Etw T="4" E="22620" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="22622" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="F" I="0" O="true" N="ShareCalendarGalleryTime_All_Avg">.. <A T="AVG">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U64" I="1" O="true" N="ShareCalendarGalleryTime_All_Min">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U64" I="2" O="true" N="ShareCalendarGalleryTime_All_Max">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="NoOfShareGalleryDropdowns">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.718284747739852
                        Encrypted:false
                        SSDEEP:
                        MD5:FAD177F52A52BA28526C1A1B0F708379
                        SHA1:2F096D0B804554B6EB81A0FFEF64BBAF7A1F6E44
                        SHA-256:F3A8E6B146C45BBC195A1A5B16FF6D6634ABD25A0FFB98A0196AAEF27AFF561C
                        SHA-512:09EC76C180C6D51BD09268B41FBB86297B65417AFECA985AA3989060D25C6C732BC0379F798E36D9F477FD3A2E562850D6733A896C7D46EB8B196726EBBF14F2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11179" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="22618" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22619" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):841
                        Entropy (8bit):5.08231939940028
                        Encrypted:false
                        SSDEEP:
                        MD5:C13A512B12E84F3DE8387E26E6B464A3
                        SHA1:57436B26E8FF5F3059271AD5FD8F5857F04078BF
                        SHA-256:BC19C825A271AE76BBCBD6CD062D2DAD5B402C2E2CF27D02983602EB79A3EEE1
                        SHA-512:037FF6FE7B3BA93F20D9F2DFF12ED8BB0E6D2AF2BB65CD159DCC4E5946AFB30769F16CEF85D146245643B14E548494D3D0E0B7B3F1487D5F18198BF05BE9583A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11180" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGalleryPerfPopulateRule_Time" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11179" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="F" I="0" O="true" N="ShareCalendarGalleryTime_Populate_Avg">.. <A T="AVG">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U64" I="1" O="true" N="ShareCalendarGalleryTime_Populate_Min">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U64" I="2" O="true" N="ShareCalendarGalleryTime_Populate_Max">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1761
                        Entropy (8bit):4.795238375030368
                        Encrypted:false
                        SSDEEP:
                        MD5:0F59D632A1A5A32AE3D6830A4F866EC0
                        SHA1:7DCC980B2B0622CCF2B5BC3E72FF16B6B099F02F
                        SHA-256:5F0648A8AD7359BCCD47D77B36C988588307BCCD3E2F8D103DC82C8E45E7C4B1
                        SHA-512:408DFEDBC64C9AF2E24EB1B83A9898867FCABF4D59568368B0CA29D4C629E80B281B13A7A55AB13D011E6AD0FA163CECCD6ABAAF7B83015502D08E7919A19855
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11181" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGalleryUsagePopulateRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22618" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22626" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="22619" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="22638" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="ErrorType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="ErrorType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="ErrorType" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):592
                        Entropy (8bit):5.221211242017178
                        Encrypted:false
                        SSDEEP:
                        MD5:00728B3E8A0D4F85A6D9D75E51D0C6F0
                        SHA1:5ACB90147954EA5356EC7981F5EF88298E4DC8B5
                        SHA-256:A2EF19F894AAE95FF9E646178E2E1EC1A388C92AD1D6B43C3BC8D7F725C2A10F
                        SHA-512:5B823D962337DC7A53A33F602008467F8B37E0A2F4993C407164CFC5FCD6AC56AE7635504FE8CBCFDB3A85DD2B73E6922ED2AC1884FB36D7550C2F2E3E87AA06
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11182" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.SharingPermissionsContextMenu" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="22628" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="SharingPermissionsClickedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):582
                        Entropy (8bit):5.179539717725845
                        Encrypted:false
                        SSDEEP:
                        MD5:49AD03FA6C9BDA94A4ED4C0BC2B6F808
                        SHA1:08B8EFD1D698A044FC49665B0366DC7D8AD08D83
                        SHA-256:37A38010B0E39E6AE7C1A9198A934AD0E54B5BADD99D96F6F045405F7C669F7F
                        SHA-512:30ED6C9C8231E0CDCC44C88CFC6092C8056E6D8DF88FEEDEBAC10B8EFD0016858D42306AE5ACD96C73F8A19F15E7A838FED1F1A578E3FCF315D03FD2AA97812D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11183" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGalleryUsageClosed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="22621" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="GalleryClosedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):844
                        Entropy (8bit):4.7506536562732915
                        Encrypted:false
                        SSDEEP:
                        MD5:78E29476E918C60B35296D7BBF24C955
                        SHA1:29527D8A43CC8C09F03103B14FA671066C3E33EE
                        SHA-256:39EA74880D0F2EABCD7ADC0605C6290A57F1834E60702A5C5423DE46795A8A55
                        SHA-512:C11DCB70ED4EBC903A1B32ECD79B609E8026056484E4A7A76BD6F271ECC8AE75981BA14C301A12CD2025678C76508DCC12AFABFB1F0447C23227E85AD748AF34
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11184" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGallery_CreateError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22617" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):846
                        Entropy (8bit):4.766383567503629
                        Encrypted:false
                        SSDEEP:
                        MD5:D3F12A73B0B01208D67EB239B0E843B4
                        SHA1:136814E874CE97D1B08FB64DEEA17C5A1FFC9B00
                        SHA-256:8C6B5D5EB83C244DE86FC63A47A36640A08BBF0DF5AC6F4561219B34B812BB0F
                        SHA-512:45535CA8130FD4C36A3B7EC48A545077879FC744C274D2331A7B30FE3889AF7AA13B25E365482918D31C86B48382DEB5FB4BB7540E210F0DF720898F95336A7C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11185" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGallery_PopulateError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22619" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):847
                        Entropy (8bit):4.7584787728084565
                        Encrypted:false
                        SSDEEP:
                        MD5:FC4D725C61FF17E147FC481029C36871
                        SHA1:410205C2B87CCDE48EAA4FC483B62ADB3FB6D518
                        SHA-256:15B3A680546F04871DF61919EE07C8C2A0BC0A89C7D8E1AE059CACD2F847ECC2
                        SHA-512:26E58E6FB1EB87CC39B328EE4DA0DFA861E77929A8AF083519C3BC16EE7EE015DCA6590E2195A9BC18C82CE215738977375B0B5C7B05ED81F91F39E2CB9CE532
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11186" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShareCalendarGallery_SelectionError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22623" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2898
                        Entropy (8bit):3.9988192284177058
                        Encrypted:false
                        SSDEEP:
                        MD5:170AA116B280C3DF602EC0681280EB46
                        SHA1:8B7816C2E86DA5584400C0EC2DE0326A825EF74D
                        SHA-256:0F05DE3ECAAA1B75BF4347E8A0C8E284074F2839436EAE720BDBB27BCC8B045C
                        SHA-512:49C362E4DC2B83347A3F8A6FF0C29C22DED96624E81FE6DDFD82B62537203BA64A909430DBA931885261C4F8E0B315117348DCBB359D420AAE4288AE48628B5C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11187" V="1" DC="SM" EN="Office.Outlook.Desktop.PhotoCache.InvalidHrInFTryEDPProtectFile" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="bpfyz" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <S T="3" F="FIsEdpEnabled" />.. </L>.. <R>.. <S T="3" F="FIsEdpIdentityManaged" />.. </R>.. </O>.. </L>.. <R>.. <S T="3" F="FIsItemContextAvailable" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="18446744071562526807" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="HRESULT" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):897
                        Entropy (8bit):4.931596634161031
                        Encrypted:false
                        SSDEEP:
                        MD5:549F50B18ABDFD6A5EB6E8F708F5652E
                        SHA1:46689288627A7BC3E486DCAC4DA3342D1E2424B0
                        SHA-256:0718460CF8B77112DDF1E6D4B154AED22E4214BDB6672C2E48B8943D28DD6746
                        SHA-512:F18AC65D4D8468D34D5733AE7FDE782AE1D78EA37471EF594E25AC55B8F42B92985EF8ED7226DB1FC5021A7E02CFFA8636F1EB9AB6850D6822812EAEF2F106A3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11190" V="0" DC="SM" EN="Office.Outlook.Desktop.PhotoCache.SizeOfPhotos" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="bpfy1" />.. <F T="4">.. <O T="GT">.. <L>.. <S T="3" F="PhotoSizeInBytes" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U64" I="0" O="true" N="AverageSizeOfADownloadedPhotoInBytes">.. <A T="AVG">.. <S T="4" F="PhotoSizeInBytes" />.. </A>.. </C>.. <C T="U64" I="1" O="true" N="TotalSizeOfDownloadedPhotosInBytes">.. <A T="SUM">.. <S T="4" F="PhotoSizeInBytes" />.. </A>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7233
                        Entropy (8bit):4.246570086999572
                        Encrypted:false
                        SSDEEP:
                        MD5:FC1A0DD2909FCC19F5B4BB445EE04268
                        SHA1:054B5856CF093A7570FA9DBC2EFA2242907955A5
                        SHA-256:9C684FFF33FAF45CAC4B224939918C2FCF0C43EA325040B95181D81085AA46B3
                        SHA-512:08C6187CBF46F2F9C2B18ECAC909AE395B3A5BAA5325F136B504C181BB064D8C7A7B939C4F7EA17FCE7842AFE7B3B803859FFFE5FF6770794ADF867F02324226
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11195" V="1" DC="SM" EN="Office.Outlook.Desktop.PcxNUIPersonaHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="brj1b" />.. <UTS T="2" Id="brj1d" />.. <UTS T="3" Id="brj1e" />.. <UTS T="4" Id="brj1f" />.. <UTS T="5" Id="brj1g" />.. <UTS T="6" Id="brj1h" />.. <UTS T="7" Id="brj1i" />.. <UTS T="8" Id="brj1j" />.. <UTS T="9" Id="brj1k" />.. <UTS T="10" Id="brj1l" />.. <TI T="11" I="Daily" />.. <A T="12" E="TelemetryShutdown" />.. <F T="13">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="14">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="15">.. <O T="EQ">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1883
                        Entropy (8bit):4.810791216554072
                        Encrypted:false
                        SSDEEP:
                        MD5:76B17D85B13170A1214F949CA763DA8B
                        SHA1:40B2DC6DB532491769E4946CD577F8C6D39C21E0
                        SHA-256:2EF49ADADB7F53866B85FBB49A4CC6FCEDA91BFF7BD68910F6D189DF50981D59
                        SHA-512:6E17DC2566F2CA1C76CB8592749E915B0B50A459E1DBA1F5E5DA0D1BF24BFE568ABB85D6D06FBB8BEE5EF4322BDA084CEFE5F875C8B012AB083568AA5758CF14
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11202" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.GetInitialDataDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8227" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsCompose" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsCompose" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="D" I="0" O="true" N="ComposeGetInitialDataDurationAVG">.. <A T="AVG">.. <S T="4" F="Duration" />.. </A>.. </C>.. <C T="U32" I="1" O="true" N="ComposeGetInitialDataDurationMAX">.. <A T="MAX">.. <S T="4" F="Duration" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5475
                        Entropy (8bit):3.802439095704191
                        Encrypted:false
                        SSDEEP:
                        MD5:66AEA12356FC4AB5D4BD66F725B88B7D
                        SHA1:65F879D4F87FBB935F49114D85DB4496F64FCEC5
                        SHA-256:3D1308796D1E89A229D7C534BA1C2814F047C72C49E1D5127EEE02739D4530DD
                        SHA-512:946860A524CB1B6EE5E33967BA185E69BD34D8AEE0A36A62A8A57583370DFD6833663E6BB7FD2834BF34E61748B1E6AA7DB32B5647E688851EB5C52D0FA9E8A0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11203" V="2" DC="SM" EN="Office.Outlook.Desktop.CreateGroupDialogDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bxqpc" A="bs2ks" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5486
                        Entropy (8bit):3.809997648506293
                        Encrypted:false
                        SSDEEP:
                        MD5:123D49AED1A40771A4D3785B200C7AC7
                        SHA1:020DB5EDDB9C071984C4A335B1452C858032E125
                        SHA-256:D8CA1A827F5FF1067B7FB0B18DC9DA30F25B5E12C4B20E5A45897DB49772F435
                        SHA-512:5807CD89F3DC54534E328F3703E98A0B493A6437B3C8667182737B504C3995A5606EF8B80A7DC51FB68BB2633A87AB3C40AF05BE21F14F548AF93847AEA3B759
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11204" V="2" DC="SM" EN="Office.Outlook.Desktop.EditGroupAfterCreationDialogDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bxqpd" A="bs2kd" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8400
                        Entropy (8bit):3.6463175371539664
                        Encrypted:false
                        SSDEEP:
                        MD5:B4BAA7B2E237556D01199730B6513AFC
                        SHA1:C040EB985786A28A054C06BF6FDFC598689C2652
                        SHA-256:5BAE693ECE47DE542723C80BA689CEA71FA986258EFC75637FFAE3561F3C7FE2
                        SHA-512:16EEDAC7E77B39D8068FD9639620346E3BF46DF9D00319E496B21ED50EBA828CD56CE839E6505880AB1B7B8B1E5FB71B2362DCD17D71729D4E161A05AE0A403B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11205" V="2" DC="SM" EN="Office.Outlook.Desktop.CreateGroupTaskDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bxqpg" A="bs2kt" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TaskDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TaskDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TaskDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.. </O>.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8416
                        Entropy (8bit):3.6558960026087015
                        Encrypted:false
                        SSDEEP:
                        MD5:C04EAAC9309BBF43CE0A91E37B955CAF
                        SHA1:D03408C90664934BEFB6F450438F731F3582C408
                        SHA-256:5517E2240E2B611A6B605A072BD3D071C834E8AABEA36D6EE13126BDEF052A47
                        SHA-512:A98C83F6C176861A7F197AD9BECE1D2FCD8FA9180DA1E5C3355FD534F91E5A3BD9B03CE53BC2E6E0CCD548EA7AD322C575E7CE426C55378E3B019BE03AA749D3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11206" V="2" DC="SM" EN="Office.Outlook.Desktop.AfterGroupCreationAddMemberTaskDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bxqph" A="bs2kg" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TaskDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TaskDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TaskDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.. </O>.. </R
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):482
                        Entropy (8bit):5.151107386886573
                        Encrypted:false
                        SSDEEP:
                        MD5:061A4C6406AC78AE104F7B7D3D798DE5
                        SHA1:A98CA10363CAE6D6955C6FA0E18A8737A736CBE9
                        SHA-256:528E51C38F25C600E8CE341B73F6734247F225D74618D540F0FF91230B7FB1B0
                        SHA-512:F492BA1C321B359CD1436FBEC2D967495BBE230CC905C0B9AE6CCBF760FA57E679638BC761BE52A047FD27AE082C18926EAD13D51601C065B0DCD3330A27D928
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11208" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxPersonInfoInstances" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bsexq" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="PersonInfoInstanceCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1938
                        Entropy (8bit):4.473676804032258
                        Encrypted:false
                        SSDEEP:
                        MD5:F5251B9E8DD51CB106A9A6B2921AEDD6
                        SHA1:D8E840633ABB4508E1FE8BAB15A8F72B8544ACF9
                        SHA-256:B4B942B736993E909EA354566CA6B057BE5039D6C5ACFD6C1E535945EFB5FE52
                        SHA-512:3C4CA66943907B3B16CACD5197FE4B7F8B5FD69E150F182CC7543B6EE166FC751C34C8961AB4F5986659005DA42BA894A6C7149B1F8B0508A4DCA9F9AC47EF86
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11209" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxContactCardsOpen" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bsexl" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="TotalOpenCards" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="TotalOpenCards" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="TotalOpenCards" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="GT">.. <L>.. <S T="1" F="TotalOpenCards" />.. </L>.. <R>.. <V V="3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):977
                        Entropy (8bit):5.00369866162737
                        Encrypted:false
                        SSDEEP:
                        MD5:D681872ED46DDE631B20DCFF9D2E2ABA
                        SHA1:12DB7C20DABD06839BFFBC07F5512C9AD8EE0A04
                        SHA-256:E3EA7A7CE2E903F74CFC02146B7A4317EFC79F18921F3193DDB4B56DC66EB109
                        SHA-512:78B3C010978DCE85186E4E7DDEA493D3ABD0A8175EA8459AB1CA030744BA5E1DC8CC56D30C633AD6D559145F58F0798D79CB4DB04C2CC93789F7C38D0BF601AE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11210" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxTimeBetweenCardsOpened" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bsexm" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U64" I="0" O="false" N="MinSecondsBetweenCards">.. <A T="MIN">.. <S T="1" F="SecondsBetweenCards" />.. </A>.. </C>.. <C T="F" I="1" O="false" N="AvgSecondsBetweenCards">.. <A T="AVG">.. <S T="1" F="SecondsBetweenCards" />.. </A>.. </C>.. <C T="U64" I="2" O="false" N="MaxSecondsBetweenCards">.. <A T="MAX">.. <S T="1" F="SecondsBetweenCards" />.. </A>.. </C>.. <C T="U64" I="3" O="false" N="MinMillisecondsBetweenCards">.. <A T="MIN">.. <S T="1" F="MillisecondsBetweenCards" />.. </A>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7618
                        Entropy (8bit):4.388178723208054
                        Encrypted:false
                        SSDEEP:
                        MD5:9F456C555DF3F06658E718DC73E082B4
                        SHA1:EFB7CDCAC893546BE76C84DFC4EFD23E077AAF33
                        SHA-256:78FA2FC82E86FC57AAD5BCAED9FE38448729B922E03BBAC265FBAA347F0EC523
                        SHA-512:AA0E6E220CA02AEBE3CEC1838182B216CB229ECA97E891963AE7E025515ACBFD8B672EE667206D246185DD41FEF2B73EB896BD5B5E667393ED3474E3A7FA8585
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11217" V="0" DC="SM" EN="Office.Outlook.Desktop.NickNameCacheHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1002" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="2" E="1003" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="3" E="1004" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="4" E="1005" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="5" E="1006" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="6" E="1007" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="7" E="1008" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="8" E="1010" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="9" E="1011" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="10" E="1012" G="{96991e14-71db-4799-a66c-270004757fd8}" />.. <Etw T="11" E="1013" G="{96991e14-71db-4799-a66c-270004757fd
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1334
                        Entropy (8bit):5.1296919045028195
                        Encrypted:false
                        SSDEEP:
                        MD5:3F5B10112630CEC7B6DF2346553C77C4
                        SHA1:B194E6CD4BB5A41B5108C9481D6A06B204BAB99B
                        SHA-256:ACCE4078C01C38EE6993DA4F1984FAF389EAF23237FB65BFC44A159AD8E818AD
                        SHA-512:DC2467A1B510146FF38677F898E24918578AE64B63CC5DE719FAA559F33CB8CBFB68AA83863596ADA28E41523825ADED0C94A6CE70C12F306E667641B565F4E3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11218" V="4" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.CreateAccountResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="445" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="446" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="false" N="AccountType">.. <S T="1" F="AccountType" />.. </C>.. <C T="W" I="1" O="false" N="AccountCreationResult">.. <S T="2" F="AccountCreationResult" />.. </C>.. <C T="U32" I="2" O="false" N="AccountCreationTime">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="U32" I="3" O="false" N="AccountInfoSource">.. <S T="1" F="AccountInfoSource" />.. </C>.. <C T="B" I="4"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):677
                        Entropy (8bit):5.20777335119458
                        Encrypted:false
                        SSDEEP:
                        MD5:727F82E44700C2D53678D426DC7B7514
                        SHA1:218F5E2FA8E02595D0CC280D2ABD46A41DFF25D9
                        SHA-256:DE701EA7B8A4059376D719EB27B810819B6CB11ACA185168633B0BA26A24DCA1
                        SHA-512:B0F1EBC53317C165723015289DD3486FD6CE7234A9A7786E6DF6DD4E117FFE1EE63951CECD222533B3F6EEF8BAF4C8839372E7EAFA1DA20FB8A5DB94AB85D5E5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11219" V="0" DC="SM" EN="Office.Outlook.Desktop.ShowProfileDialogOnBootCaller" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="700" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="B" I="0" O="false" N="CommandLine">.. <S T="1" F="CommandLine" />.. </C>.. <C T="B" I="1" O="false" N="Registry">.. <S T="1" F="Registry" />.. </C>.. <C T="B" I="2" O="false" N="ShiftKey">.. <S T="1" F="ShiftKey" />.. </C>.. <C T="B" I="3" O="false" N="UIButton">.. <S T="1" F="UIButton" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):739
                        Entropy (8bit):5.160675149314942
                        Encrypted:false
                        SSDEEP:
                        MD5:2BA1EDF4EAA7E7F10F706649EED82972
                        SHA1:CFBB17CFA1C58D8001855C2E7F3EAC12A22D83D5
                        SHA-256:BA264C1467ED1C59B75D5B1D40A58FB4FB17141156315CCCCAEBA448FF2A5A2E
                        SHA-512:89BAA379223B4098AA0A99C35D63AE1EB4628394A8D4A7A8221862DC26253EB27D9AD8EC55B30C50D5A49FD8B6222DCD7821C55BE741A91CBB7EB1E7E56961E9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11250" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.Recurrence.PatternTypeUsageRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="159" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <G>.. <S T="3">.. <F N="RecurrencePattern" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="RecurrenceDialogPatternTypeCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="RecurrencePatternType">.. <S T="3" F="RecurrencePattern" />.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):789
                        Entropy (8bit):5.2049640177154055
                        Encrypted:false
                        SSDEEP:
                        MD5:2BC9EDCED4B2094C62836CA694FA4106
                        SHA1:C736C58AF7D94B04154A5F67F3AEBA7CFF83833D
                        SHA-256:6F145B841CF3A559B7A60D88111747FA41F8ABCFE413213B862D7480EEE642C4
                        SHA-512:6B7BD1CA3EEF211D034705D2DFD8D927E9D05E87CC663779FBDD5A518F6FBCD3E6C925DC988CE5A6B4949AB63345171C2C7465E54B30825717F79F57629AB8C8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11251" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.Recurrence.EndOfRangePatternTypeUsageRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="393" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <G>.. <S T="3">.. <F N="EndOfRangeRecurrencePattern" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="EndOfRangeRecurrenceDialogPatternTypeCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="EndOfRangeRecurrencePatternType">.. <S T="3" F="EndOfRangeRecurrencePattern" />.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):817
                        Entropy (8bit):5.177183006827267
                        Encrypted:false
                        SSDEEP:
                        MD5:450D9E91EBB3A94DD53698A6A48C97FF
                        SHA1:A48905E093476291CB7DB490CBDE48F79A5B239B
                        SHA-256:14BA69C4DB79E40DCEE1C7B0DCFEF2B7BBF75CB5284A20D692987D86B2344C12
                        SHA-512:8880173CF6C0FF62FD8101696AA1C7C76248EC6167DF83B2B11D31EF880EE35D76A4661719009B458029538DBEC396B20122F68C99A2C39035D967E3ED5F0237
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11252" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.Recurrence.DefaultUsageRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="391" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="4" E="392" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="RecurrencePatternChangedFromDefaultCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="RecurrenceEndOfRangePatternChangedFromDefaultCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. <S T="4" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):602
                        Entropy (8bit):5.209369041631309
                        Encrypted:false
                        SSDEEP:
                        MD5:A8E871C82CF0894CC2CECCB0BA0B322A
                        SHA1:23F691A611EDAE19D3DA8D83BA2E883A6CC5FB43
                        SHA-256:A76A04B981EDC0906BC146FC4323F43291E7D9A859E3C0D94A60F769D924AD6E
                        SHA-512:260784C30BD71FA764C0CE20891A77D4AFFDDB852CC73E8510B3D7ACB1413BDC2AD28A4E6C4A23DFEA604AFB25B18317A1546745388107904DA4F5508319C2BE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11253" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.Recurrence.CreationCancelledRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="389" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="RecurrenceCancelledWithoutCreatingCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3585
                        Entropy (8bit):4.216930963141534
                        Encrypted:false
                        SSDEEP:
                        MD5:8499FCEEB2EE77F9B9F34613D9376914
                        SHA1:DD599118823699A461BEA000286D639AB85FAC29
                        SHA-256:B88E99B4236977BF46F6E81D0DFB126185349B7C845DC6CA17ACEE943605AE26
                        SHA-512:1068CDEDDF2552C128E6ED6F7B021B6E0DF5C5E4E94C9A1D92F2877E9DCD94B0CB38AC582B804D623D7CC0A6D0E920C4844CAD016C9525352D1675D2AD799164
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11254" V="2" DC="SM" EN="Office.Outlook.Desktop.Groups.ApprovalButtonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19025" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19024" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="Position" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="Position" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="Enabled" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):592
                        Entropy (8bit):5.221185175699049
                        Encrypted:false
                        SSDEEP:
                        MD5:1280D1754CB70F412F87D3EE9090EEEF
                        SHA1:1C7008323F25C776B72453FA42D4ADD6A8C759F9
                        SHA-256:0BE6FBAC15A43B8CE86BEF12FF4C7E7D419EC8F254959746E1458FE4AEF1C2C9
                        SHA-512:E1DEB33D8EB2117A882C9DD45E7E63858BE67665E94E7A12DBDF4750C9DBD24149AAEE0B3B298DB4D9A6553B0241F900AE9EB2138FBBF19113C97037220D62BC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11255" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.OpenThisCalendarEventRule_Usage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="22630" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="OpenThisCalendarClickedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):573
                        Entropy (8bit):4.725747328551441
                        Encrypted:false
                        SSDEEP:
                        MD5:A2E7BC91CCE26D61C6EB52AEBA76031A
                        SHA1:DE9CF96A369918CE42FEEB5872195B3D43F1A3F0
                        SHA-256:957DB66F614402A678E991D39A2D04119A5D1A5254BA7EFE5EC4FAD3FE450EFF
                        SHA-512:3C86411E59E3CBDE972A74F09076ADE9B99CA9640BD0EAF9F11AFD919955AE7602A55DE115CBC78FA7FC1D452D3DA76E108E10E63BDA74490FFD135DC1760F3F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11256" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="22633" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22634" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):5.052772920282416
                        Encrypted:false
                        SSDEEP:
                        MD5:29C5A46BDA4362429C9405A9B07ADB68
                        SHA1:1EB2C5BC7A5BFC59889F47493D891783A3E9A434
                        SHA-256:A511645C9619D009DEAB312F5E420CCE21AF8180D5E87B50C9989767F1B0DD81
                        SHA-512:F877C031E056E8D2B23456C538BC03FC4A1968E093294029E0871177B0FDD52D03837AB29AD6661144C2A776C49ABAE7BE4F91E37AD6E73490B252D4BBE49B0E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11257" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.AcceptCalShareApiAllRule_Perf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11256" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="F" I="0" O="true" N="AcceptCalShareApiTime_All_Avg">.. <A T="AVG">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U64" I="1" O="true" N="ShareCalendarGalleryTime_All_Min">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U64" I="2" O="true" N="ShareCalendarGalleryTime_All_Max">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):628
                        Entropy (8bit):5.0354559619155825
                        Encrypted:false
                        SSDEEP:
                        MD5:EA14C41166D7388BCB42399BD65F4E04
                        SHA1:DBB1278381EBAECA06DF64A82109B5F2C97CA47A
                        SHA-256:5EA8B79FA3E73A0B284D46C3436A1CF66916F5802F34F1BF4F322DB5EB8232BD
                        SHA-512:795FB004BCB35F92035B1B7087C146B71B40EA28CDD531A6121807647DD2F5399FB39E6E6E595F3B552444AD0F52E7B83EC98177193E53E0707E6D56CB40D012
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11258" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.AcceptCalShareApi_Error" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="30" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22634" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):471
                        Entropy (8bit):5.422909967743418
                        Encrypted:false
                        SSDEEP:
                        MD5:33FE5BC029ED87E245C91EE678199F94
                        SHA1:E18A7C4564251D9433AD97EEA7A4AA471A88B74E
                        SHA-256:91E365B835788821182BFA5087557BBFA5246DF90DA3EB5E87A9BC6C0DD46E1D
                        SHA-512:46A0C35199F90D4E8AF37FC1FAEBC6C5511E6C77363C7325D28F0BD56F8899D96BF8A9A123C286630FA9F044DB0DC53EDF05F09EE6DACDA1DEDBB49F73E74285
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11259" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ErrorShownToTheUserInDialogBox_Error" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="40" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22631" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="FailedHResultSubmitted">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):627
                        Entropy (8bit):5.022904279822462
                        Encrypted:false
                        SSDEEP:
                        MD5:D47B388182E7520B9B792C1B15932D93
                        SHA1:272E25F757D12A5CCE8587E4D4FDE2E27DE829CA
                        SHA-256:C983249241E8A2399501D77EB9038BC92570D1A1E12CFAB78D4B6633707689D6
                        SHA-512:02A1F76CC2E8A874C54CB55454AE64A74F5268143D6BB7C180EF90963525469D6E83CC5C94FDB2B8B6F452D94BCD7F3A319610B2D78ADD33CA1BD3F1871F413D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11260" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.CalShareApiStore_Error" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22632" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):673
                        Entropy (8bit):5.097217822988432
                        Encrypted:false
                        SSDEEP:
                        MD5:E81A1F4636D4AC2324D5D65E93D4C415
                        SHA1:0BD284A7BC6659276E93DBD30CF147A535595E57
                        SHA-256:A6665C5FF8F7D914EDA28E987EDD71D4275D3C69798243FF5A98885452D49FA2
                        SHA-512:6BF876F17AAD5974FDEDBFE28F47A700FFA516E23CA7AA2FAFD02E0B4AF907A8EDB1C10FC65745ADED71450DF6A516EB713601BA70F7D1A2D77A042954297F07
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11261" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.AcceptCalShareNavigateToSharedFolder_Error" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="20" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22637" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="FailedCaseHResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):660
                        Entropy (8bit):4.626249114115278
                        Encrypted:false
                        SSDEEP:
                        MD5:D278C41268710E18A364565D96163EE7
                        SHA1:E270235296674B0D7501A5C0FF6C638972029657
                        SHA-256:423A7DDE013E34B6F42AF12403D32FF49F24F508465F6069E90DC7FA339A80BF
                        SHA-512:88B6E60EC07D04EC58DB5AD19128F2BAF5FD1E672F60004458B1274D1DBCF9AAD22D66F7AB882999CE3813E64E57F42C8048BB12894485D3D35EA436361AE9E0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11262" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22635" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22636" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TO T="3" I="5min">.. <S T="1" />.. </TO>.. </S>.. <C T="U64" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1133
                        Entropy (8bit):5.029097525435364
                        Encrypted:false
                        SSDEEP:
                        MD5:E71F81CDDFB15B32B25C08F1AAE4ABE0
                        SHA1:DDF68E86F385CB6BF90436ABAB627A7EC1A061A3
                        SHA-256:F7D524ADB77F68B4B201A35385FD7A082D195FA81AD27169D23A994D398CF577
                        SHA-512:71096833525D6063DCD7C23023DE21F5B0239B3803D84643E487210DF285D266F17B71CFDDB27D60A62295D93975E595F3E4AE9DD8FE56469FF26AF9D0626546
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11263" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.AcceptCalShareScenarioAllRule_Perf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="22635" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <R T="2" R="11262" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="F" I="0" O="true" N="AcceptCalendarShareTime_All_Avg">.. <A T="AVG">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U64" I="1" O="true" N="AcceptCalendarShareTime_All_Min">.. <A T="MIN">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U64" I="2" O="true" N="AcceptCalendarShareTime_All_Max">.. <A T="MAX">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="NoOfClicksToAcceptCalendar">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="4" O="false" N="NoOfTimesAcceptCalendarActionCompletes">.. <C>.. <S T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2838
                        Entropy (8bit):4.40265256019829
                        Encrypted:false
                        SSDEEP:
                        MD5:1475747C715C573242BBC0E81EF435D0
                        SHA1:6C1A6C7E42D6AED9614344E1F0F42835B8755B0B
                        SHA-256:D5829A4D9FCF20A62FE6D3DF6853B1E18B9401EF32E02B1540FB5262D549D6DA
                        SHA-512:2F350737EA5514B5C8AA5C4DA341F18905CE0CC6CD1C475A5963AB79019AC6BE8EB03CE83B3F76B9C975ED6EF0FF6EF37A2F62A0050D67B8AC0D86132AA8DB42
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11264" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxUnfinishedSearchElapsedTimeWhenSelectionIsMade" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdrut" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="didSourceFinish" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LT">.. <L>.. <S T="4" F="MillisecondsSinceStart" />.. </L>.. <R>.. <V V="200" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="LT">.. <L>.. <S T="4" F="MillisecondsSinceStart" />.. </L>.. <R>.. <V V="500" T="U64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="LT">.. <L>.. <S T="4" F="Millisecond
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1762
                        Entropy (8bit):4.348634924545833
                        Encrypted:false
                        SSDEEP:
                        MD5:69298A7654BBB32E5452168E560D93FC
                        SHA1:79D7EEAF933D57B30D3B9952FD6C4AEAFE0329F1
                        SHA-256:2C9BF7DD1612CBD01E93F7B62F536C15E6D03DD13222F02BCE44E56C15FD01E3
                        SHA-512:807E2D687554D8E9D075A05C605689AF886FF8A8DE519F9DC6BE31035BAA24C9DED4A5F11167A3FD5A07D088DF7C3FB882332F6A7F09DEDCB4A9FC076AF965A5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11265" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdrus" />.. </S>.. <C T="I32" I="0" O="false">.. <S T="1" F="searchSourceId" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="searchSourceName" />.. </C>.. <C T="I32" I="2" O="false">.. <S T="1" F="sourceSearchResultIndex" />.. </C>.. <C T="B" I="3" O="false">.. <S T="1" F="displayNameMatch" />.. </C>.. <C T="B" I="4" O="false">.. <S T="1" F="emailAddressMatch" />.. </C>.. <C T="B" I="5" O="false">.. <S T="1" F="fuzzyMatch" />.. </C>.. <C T="B" I="6" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="sourceSearchResultIndex" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="7" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="sourceSearchResultIndex" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="8" O="false"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3669
                        Entropy (8bit):3.986291181320914
                        Encrypted:false
                        SSDEEP:
                        MD5:D6C33D7A445C4205DCF74DFAF43B6BBE
                        SHA1:ADBFFE7AA91B7C42FD64794AF0B514CBF2DED0A3
                        SHA-256:29052E50515016932E7B68D9CAB21213B85BDB3A7B82F095051C2D926CADBA47
                        SHA-512:7D67363C5EE7863405BCE31D5019B7508AD1F011787B9A10528437B5D61DCCCD9ABF9766DD319E1130FF975763F782B5D0AA7407047E42FCCE62D4A40A4E1E0D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11266" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bv5yk" />.. <UTS T="2" Id="bcdaw" />.. <UTS T="3" Id="bdrus" />.. <UTS T="4" Id="bdruu" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="searchSourceName" />.. </L>.. <R>.. <V V="NicknameCache" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="searchSourceName" />.. </L>.. <R>.. <V V="NicknameCache" T="W" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="searchSourceName" />.. </L>.. <R>.. <V V="RecipientCache" T="W" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="3" F="searchSourceName" />.. </L>.. <R>.. <V V="RecipientCache" T="W" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):674
                        Entropy (8bit):5.014251148012292
                        Encrypted:false
                        SSDEEP:
                        MD5:69D0CE5B332F8CABCDF62F8756A37E8B
                        SHA1:ACA1A25731AC19C4B4C6360F56B65C1F0F2336F4
                        SHA-256:83276DE5F25C084FA1CA47958944FCC54C7B0C0C7D4CCA87500C00A84BDF67CD
                        SHA-512:7857D42B0ECB0E946F1A1549A7586C7FDE62BCB017ABBCC91CC5A759F0B6E11E3565AA82D7C57782ED92F38C5CF19A28483DBB2B732569A7B9CDA47A5E2972F3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11267" V="0" DC="SM" EN="Office.Outlook.Desktop.AutoCompleteSessionsWithoutSelection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp1ks" />.. <UTS T="2" Id="ber0h" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfAutoCompleteSessions">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountOfSelections">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3495
                        Entropy (8bit):4.223913931984952
                        Encrypted:false
                        SSDEEP:
                        MD5:850786FEEE0DF6F30DB941540F0DA5CD
                        SHA1:D0B8C983302E57AEC70655AAB9EBE3B83B8E8862
                        SHA-256:9002CF8736C510DCBD7A8F0FD47468DE895D22F2B4EE894CE272AC41B009F6BA
                        SHA-512:8D4226F50451D331D52763885F610D7197C58CEC08DE3D2E1F766A981705785F5BD17ABEE304B904FDC3BB084C0B057C1209F659B5FEE77303D65D7A1B794DFE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11269" V="1" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchCachesVersusFindPeople" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11266" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <S T="1" F="4" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <S T="4" F="5" />.. </L>.. <R>.. <S T="4" F="7" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="LT">.. <L>.. <S T="5" F="9" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="GT">.. <L>.. <S T="5" F="9" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1354
                        Entropy (8bit):4.766498306814394
                        Encrypted:false
                        SSDEEP:
                        MD5:86DB8E8CF124FC0C7C30B3F93729C6A9
                        SHA1:24211E42A464AED50892FC96930D86DE930578FE
                        SHA-256:DB8E70C7C85837739376F54E8C984A990877C32DA9F2FECF74A692D4DAC29107
                        SHA-512:7A0970FC1F545E5ABB5B07D31598BB478738441F8A48B85A75CE216764FBA5E3C4D452C7AC65BB0C38BF2C9638C09205E4B6ED2246331840C5A7E9E31A4540B0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11278" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.Recurrence.CreationCountUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="390" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="3" F="InstanceCount" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LE">.. <L>.. <S T="3" F="InstanceCount" />.. </L>.. <R>.. <V V="-1" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="F" I="0" O="true" N="RecurrenceCreationCount_AVG">.. <A T="AVG">.. <S T="4" F="InstanceCount" />.. </A>.. </C>.. <C T="I32" I="1" O="true" N="RecurrenceCreationCount_MIN">.. <A T="MIN">.. <S T="4" F="InstanceCount" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7191
                        Entropy (8bit):4.039640909189186
                        Encrypted:false
                        SSDEEP:
                        MD5:EF888029B882D703D2E11C22EB2C7E71
                        SHA1:0B201C55924CCD192D721C2982D09B980E006891
                        SHA-256:7C118544529A7C902B31D280DCE6B2EA1105937B4548CE22B3BF94DA90DCE6EA
                        SHA-512:1FA7FF22C9EA2938A630EA39A6625727CCCCAB40C9A5CA49761208A43429FCC98870260CE5D1DBC07E5034193CFDAC7EFDDC72983CBE3C05CD92722DCFCB7209
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11285" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCard2OverflowMenuClickCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="buk0f" />.. <UTS T="5" Id="buk0m" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="eventId" />.. </L>.. <R>.. <V V="135" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="tcid" />.. </L>.. <R>.. <V V="27852" T="I32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="5" F="tcid" />.. </L>.. <R>.. <V V="27853" T="I32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="5" F="tcid"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):845
                        Entropy (8bit):5.0839489167557605
                        Encrypted:false
                        SSDEEP:
                        MD5:9DECB5B99D97EE78C18183872990DD1F
                        SHA1:00C4E1F0B320B56248E5757C75E99C67FEA0F04A
                        SHA-256:AB0696B57184E09D3D9D15039E68E3BBB1FA56EA46365235464F7C319BE7048E
                        SHA-512:3616E8FD2BEC2D18C1638F5F1A9D3B20DBAE3545FE05D583FA711FA0FECE992C54EEBB06A792CE555C1AD0A0F5A1A8A25802FC5B305D613ACD18156044A67963
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11286" V="0" DC="SM" EN="Office.Outlook.Desktop.AddressingSessionDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="btv1w" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="F" I="0" O="false" N="AverageTimeInMS_CompleteRecipientDuration">.. <A T="AVG">.. <S T="1" F="AddRecipientDuration" />.. </A>.. </C>.. <C T="F" I="1" O="false" N="Average_AddressingSessions">.. <A T="AVG">.. <S T="1" F="SessionCount" />.. </A>.. </C>.. <C T="F" I="2" O="false" N="Average_TotalSearchStrLen">.. <A T="AVG">.. <S T="1" F="TotalSearchStrLen" />.. </A>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):525
                        Entropy (8bit):5.305296300177923
                        Encrypted:false
                        SSDEEP:
                        MD5:E0D2FC7CB3C87014842D5DE92BFF4DDF
                        SHA1:649EA27A30F5E7CE28977ADE279F67D2A252EA53
                        SHA-256:32F30802B30FD11DBC5289F59CF88D7B4A4418B3FCB10B53099693E3BD079AD8
                        SHA-512:E069D16450B2F1FDA7B9C2F9E3182AF9BA745B5D38819387AFF44CC6D7569FB8953A0100C04614F4967A50C59707F10AD37446EA6F2F7020E8BD5BE223E8A34E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11287" V="0" DC="SM" EN="Office.Outlook.Desktop.Profiles.LaunchManageProfilesApplication" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="397" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="Caller">.. <S T="1" F="Caller" />.. </C>.. <C T="U32" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3863
                        Entropy (8bit):4.096824225849939
                        Encrypted:false
                        SSDEEP:
                        MD5:12D04C599611704FC11A4B3F9153CA44
                        SHA1:7922A8D14B9D632B245CD056FA55B06726F5D6E8
                        SHA-256:D3B86EF8C08A6E74DDDAC76BC95D792AA188B1171398893CA84B9CDEDC0CB299
                        SHA-512:D63FA41238DD274D59608C184B2454177AD7226B11A0CC503D07EB55558FBB62937FF9BEF5E9F62DFA86FE67B1011E9070883D4CA61FFACC9BAF1B262701C652
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11289" V="0" DC="SM" EN="Office.Outlook.Desktop.ContactCard2OrgDataRetrievalTiming" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="buzan" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="3" F="RetrievalMilliseconds" />.. </L>.. <R>.. <V V="200" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="3" F="RetrievalMilliseconds" />.. </L>.. <R>.. <V V="200" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="3" F="RetrievalMilliseconds" />.. </L>.. <R>.. <V V="400" T="I64" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1129
                        Entropy (8bit):4.687644329748134
                        Encrypted:false
                        SSDEEP:
                        MD5:0433B33DB21E93334332D9FDEC96FEB2
                        SHA1:1C93F915BC933818145E3C41C8186460213E06F7
                        SHA-256:A2F51D8BB96A2F107F5713196547174EFB9CD9C41C2339013CD67151065D86CD
                        SHA-512:3A9CD3FF03F67C0DCFAEF93166936A4D99624BBFE890D27459C0AE8B3A27CBBFAE4A164C85FEBA0D8AEBB046255E8C123E872500B2C675536887653EA0D5BD01
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11293" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ATMCButtonLabelUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19027" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="LabelShown" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="LabelShown" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="LabelAddCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="LabelAddedCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="AverageDelay">.. <A T="AVG">.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):429
                        Entropy (8bit):5.310603779959023
                        Encrypted:false
                        SSDEEP:
                        MD5:603B89C95BBFC6DAC2178310EA70940D
                        SHA1:725361C3847067DB9111BC2500C3A26BDB3B4CC1
                        SHA-256:B2B633A44FA098CF0A6FA1AF7C4EAA6776A0A9123842AD6E27E0F46BA2C2DC79
                        SHA-512:71DED95FA93089518EC33F5F804FC5D18FDF92C0846E89DA6A7C1431C1B14552C9FDD82EBFB8AA76B04689198975B6B5B3ED21E37CA92889F372ADF6A31D7FBC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11298" V="0" DC="SM" EN="Office.Outlook.Desktop.OABSizeOnDisk" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U64" I="0" O="false" N="OABSizeOnDisk">.. <S T="1" F="OAB Size" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1616
                        Entropy (8bit):4.899500307191146
                        Encrypted:false
                        SSDEEP:
                        MD5:24E61BB5DA7BC75FB4ACD584210D8C93
                        SHA1:A1413E41A7C2741A16E723D239AEC6E3940FC14F
                        SHA-256:8F1BF518397454E6BD304F573627B0AB2F08787A6BD90ED43E8B9B244778C667
                        SHA-512:719211F019D3F8A61F7744C7AEB51BA13AB61E64AEBE7CFBC124A158388980731188ECCADC0E26B123449FC6F3BD01E1829AC8F1D1A8B4B73E66E123156FCDCA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11299" V="0" DC="SM" EN="Office.Outlook.Desktop.WarnedServerChangeInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="698" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="2073" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="2074" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="FReportAttempted" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="LT">.. <L>.. <S T="6" F="HResult" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Rpc_WarnUserServerChangedLogEvent_Count">.. <C>.. <S T="1" />.. </C>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4274
                        Entropy (8bit):4.037014992848025
                        Encrypted:false
                        SSDEEP:
                        MD5:C5414F230477CAFF4D6CACFF8DD4DE76
                        SHA1:1300A7D6F3FE2CFE5116AD9C003FD86BBC973184
                        SHA-256:109D4477A13CAD32C72765224A3F1D5B0EAA8C020D67A76991F5F86A4A433091
                        SHA-512:25EFFFD1EB7C62AFA6F6AD256DA4B5FF8F1C423F360138B78370DDD7DAAF8F2C6446109675776C3BF77319E540B829AB558BE562F39EDD86CBA32125A00BAACA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11300" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCard2TabUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="bv5y1" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="tabId" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="tabId" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="tabId" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="tabId" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2550
                        Entropy (8bit):4.366855904574729
                        Encrypted:false
                        SSDEEP:
                        MD5:0A1986D2552C4F0399E56F96C92CF389
                        SHA1:0FCB9FD7673C76A0BC90BE8E5553CE90B1168F7A
                        SHA-256:D28F30420B69CCC7F24F5F5A3DC3E8C269585CC5EF5063CA158729769A3D23AC
                        SHA-512:03B0090BC3DCCD9EB7B41443814565BDDFCEEE50EB2C735F0F62C833F0836F130E38277FC200E495B652419FB89DA4EFEFBDD433EAFF909C21BCAFF05980465A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11302" V="0" DC="SM" EN="Office.Outlook.Desktop.PhotoCache.ReasonsForMapiEEdpFileNotProtected" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="bpfyz" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="3" F="Exception" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="FileProtectionState" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="FileProtectionState" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="FileProtectionState" />.. </L
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):765
                        Entropy (8bit):4.781915648397962
                        Encrypted:false
                        SSDEEP:
                        MD5:19D1EA6B3597AA0581F7D828476C0480
                        SHA1:E83777B428007A2D7D2311AB7761AA56E374082B
                        SHA-256:68141A163617DA8B376B62E718A0A938664B2F358C35941B0514A9B436C08B4F
                        SHA-512:63CE784793F96850E29417EBBF8C5712EFA68BE955E8D76AC3B51BF2A781021FEBB9CB7B5DB3E6582BD37BB9244087C2715B7C6A8CB3620917332F3D5F9D2045
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11304" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3814" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3815" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="CalendarSharingAPIInfo" />.. </S>.. <S T="2">.. <F N="CalendarSharingAPIInfo" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="2" F="CalendarSharingAPIInfo" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):901
                        Entropy (8bit):5.010343734596521
                        Encrypted:false
                        SSDEEP:
                        MD5:4C9A0E4A87A3F790B908C67331495FB6
                        SHA1:D773246A4EDC8795854606ECCBF3D2AFE1418BF9
                        SHA-256:F2144B7897A75FF5FEB14F0B04B8D5A1466C29D9F2706D2558931D655486C7ED
                        SHA-512:E661DA44C4D008331734D0C12494110EF46B918FC756747D87BEAEB22B7D27759B388447282B6A760D6A526A87C42C2AEF8CF524A760B3789117BB6AF58B4153
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11305" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalSharePerfAPILoadTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11304" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CalSharingAPI_Context">.. <S T="1" F="0" />.. </C>.. <C T="F" I="1" O="true" N="CalSharingAPI_LoadTime_Avg">.. <A T="AVG">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="U32" I="2" O="true" N="CalSharingAPI_LoadTime_Min">.. <A T="MIN">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="U32" I="3" O="true" N="CalSharingAPI_LoadTime_Max">.. <A T="MAX">.. <S T="1" F="1" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1758
                        Entropy (8bit):4.647385488555497
                        Encrypted:false
                        SSDEEP:
                        MD5:8E8A323175A16DB82C1223E7561DE610
                        SHA1:4AB388685F17322E3B699A58FE3A9450F477E507
                        SHA-256:2463FE8A4B07F684D9020AC038BFCE3A0505C170A20ACEA94577CCAAB0861919
                        SHA-512:96EC4129966623632A06E857A5CF6DDD59F5AD951A6D7C8FCE7570FF8AE2ECA83178416B05969E5D3BDA35F900815B1DFFD1C2D80B1901270AE9023334C5F938
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11306" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalShareAPIUsageBasic" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3813" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3816" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsCalendarSharingAPI" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsCalendarSharingAPI" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="CalShareAPIEmsAddrTypeInfo" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):720
                        Entropy (8bit):5.190707446606895
                        Encrypted:false
                        SSDEEP:
                        MD5:D3B089F66EA4AA182387CA0F17AF105C
                        SHA1:09860975A08EB7A36B2BCF493D9669E8A504AEBC
                        SHA-256:1C46715AC9FE9CCA965B0BB9A7396E587571D4CF152BBCB53DEC04024F4E6196
                        SHA-512:45052C4EDA6357842E8C56EAA7F1A5131AC4D91CBCF7084E075766528C78A46287F737DFB3C8EF44C546077B5E91FE820C6E5A07665F0CEDFDD295613D4CC524
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11307" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalShareAPIUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3814" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="CalendarSharingAPIInfo" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CalSharingAPI_Context">.. <S T="1" F="CalendarSharingAPIInfo" />.. </C>.. <C T="U32" I="1" O="false" N="CalSharingAPI_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):771
                        Entropy (8bit):5.150525734606437
                        Encrypted:false
                        SSDEEP:
                        MD5:23FE2FDD92DC757BBDEDD78EAE7F504B
                        SHA1:F0876126FCBDADAF240120B22D47086FA09730F3
                        SHA-256:B2197A40478F540DB4DC9E0E037FD26174731CF94D654DD49BF50B2C8C9FF4C8
                        SHA-512:6559642656E5559E6B799DD34117783C9B35D612A5A5CD9D9E7E458D581066D56344104893E91D6943308086A6D87C4A8529BCDD357C72C7F8ABF42C3601EAC0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11308" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookPrivsDlg.LoadFail" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="70" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3815" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="APIResult" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="CalSharingAPI_OpEnd_FailedEvent_Result">.. <S T="2" F="APIResult" />.. </C>.. <C T="U32" I="1" O="false" N="CalSharingAPI_OpEnd_FailedEvent_Context">.. <S T="2" F="CalendarSharingAPIInfo" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):831
                        Entropy (8bit):5.205510499407575
                        Encrypted:false
                        SSDEEP:
                        MD5:FEF8C7B5141799588218857906D29B7F
                        SHA1:2A47991A78134C882C7BAA1C6C355DFF38735C2D
                        SHA-256:B5A45702E51F6396494D85AB05255D986E03BFC1DC85AF120F34D49D5E4BDD4E
                        SHA-512:23736FB8A8F1926A9041FD257CAFFC044C5E9DCB1A04392E2406392F366D5FC5282B6631FCEAA41790762609FB065C61F0303ED4C48FEE4B5CECDE84F6B1D0E8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11309" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookPrivsDlgSingleUser.LoadFail" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3816" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="APIResult" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false" N="CalendarSharingAPI_SingleUser_FailedEvent_Result">.. <S T="2" F="APIResult" />.. </C>.. <C T="U32" I="1" O="false" N="CalendarSharingAPI_SingleUser_FailedEvent_Context">.. <S T="2" F="CalShareAPIEmsAddrTypeInfo" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5067
                        Entropy (8bit):4.272751703186381
                        Encrypted:false
                        SSDEEP:
                        MD5:1CDA9A893B0909D238EAB38198C89DA6
                        SHA1:F54D8DCC7119853A2038BB857FF6CF4F89A5D5C7
                        SHA-256:11ED982E7AD1C223651346DC32CDCEF93CFE251EAD9661B53CE1F6F6B6A7A3BA
                        SHA-512:02A9EBCD71A6E90B7AD0304E8E37AC6FBC6C4694E0BC730C1AD2528F89593860BDC2FA87CDE245D3A7093D6B7FB9121FB82ACC003EC8ACC59B51C8CB84C9167F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11316" V="2" DC="SM" EN="Office.Outlook.Desktop.SearchSessionUIActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7115" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7002" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchButtonState" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchButtonState" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="SearchButtonState" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1493
                        Entropy (8bit):5.111182750507483
                        Encrypted:false
                        SSDEEP:
                        MD5:10FB7BFA06FC1B288580C4FC917CD251
                        SHA1:B49F0944A05A027CA38B785F0956098DBC0F1C4B
                        SHA-256:D1E61E9E1652B7EF9E8DBB79EAAEDFCDBCF2685611ADFD84AD90FD9B97D633DF
                        SHA-512:A20B8AAC56866C8C34C346F64B71568E8645573A622A503A1D32483EE98210AE55E97543E9B6D8D55BB981A68B4BDA4E3AD11141340B1DE72FFB16C1A0D65BF6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11318" V="2" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AccountDetectionResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="456" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="457" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="454" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="455" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="495" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false" N="EmailAddressesRetrievedCount">.. <S T="2" F="EmailAddressesRetrievedCount" />.. </C>.. <C T="U32" I="1" O="false" N="ActiveIdentityRetrieved">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="B" I="2" O="true" N="ActiveDirectoryEmailAddressRetrieved">.. <S T="4" F="EmailAddressRetrieved" />.. </C>.. <C T="I64" I="3" O="true" N="ActiveDirectory
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):696
                        Entropy (8bit):4.902778960721545
                        Encrypted:false
                        SSDEEP:
                        MD5:0D0CBF720F5C48626F35353F53EC7AC6
                        SHA1:FF61FF76830F4C3FA2E1C473B1580A7B186E745A
                        SHA-256:9E089A8510372AAA736790597680F0DCCC69169ADDAD883935775571726ABD15
                        SHA-512:3E9AFDD719D58AD37115D9842EE044BE167CE6AF1DEC80BDB4B96684FA51A8F2BE5856EC43C29AA1BB9266A743A2143CAE1FA1073AA67B38D11EE2C7A02774C5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11319" V="0" DC="SM" EN="Office.Outlook.Desktop.Emsmdb.CORgToEc" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1010" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="HR" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="FailedHRCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1261
                        Entropy (8bit):4.944096121919814
                        Encrypted:false
                        SSDEEP:
                        MD5:F20687BAAE7E2699F309031D824EA78C
                        SHA1:3C0D42F7DED2CF4BD3949767FB57293DEA5DCDD3
                        SHA-256:38ABF4D3EF71713F4594182F093A6D0981DE0D46D9ED9241EAFADD33C59616B2
                        SHA-512:A665C7DF814225801A26C1A4FFC2F5AFBECB8F24A1682604DBD6B9B76B39AE8A92EBF9E44AEC4503A34E8761FA599961D8680D78718B8DA53D61999E134CBFC5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11324" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupCalendarOperationEvent" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="507" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="508" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="OperationType" />.. <F N="HRESULT" />.. <F N="IsAppointment" />.. </S>.. <S T="2">.. <F N="OperationType" />.. <F N="HRESULT" />.. <F N="IsAppointment" />.. </S>.. <S T="3">.. <F N="OperationType" />.. <F N="HRESULT" />.. <F N="IsAppointment" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="TotalCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Operation">.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1422
                        Entropy (8bit):5.110271243604077
                        Encrypted:false
                        SSDEEP:
                        MD5:7AAFEED5952E3D7D5D43DCA958820970
                        SHA1:C590675FF9C02D6E74510D9E4E5A3E49A1C2DB41
                        SHA-256:023120BE2C58273DAEEB8A9FE073EF008B601C0F2DB003D7EF64F3BF6EA4875F
                        SHA-512:7EFDA98CD04505F8AC7AE18C54E771BA4FF60ECD5A4D9AB0F75E1A48193DFA7DA3C13348C556C385B1EB7A013975FC1D335D22E864AA1111916F248921D32932
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11329" V="0" DC="SM" EN="Office.Outlook.Desktop.TracertDiagnosticsReport_Stats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="130" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. </S>.. <C T="U32" I="0" O="false" N="RunID">.. <S T="1" F="RunID" />.. </C>.. <C T="U32" I="1" O="false" N="IPTypeUsed">.. <S T="1" F="IPTypeUsed" />.. </C>.. <C T="U32" I="2" O="false" N="HostsCount">.. <S T="1" F="HostsCount" />.. </C>.. <C T="U32" I="3" O="false" N="FirstHostIPType">.. <S T="1" F="FirstHostIPType" />.. </C>.. <C T="U32" I="4" O="false" N="HopCount">.. <S T="1" F="HopCount" />.. </C>.. <C T="U32" I="5" O="false" N="IPNonPublicCount">.. <S T="1" F="IPNonPublicCount" />.. </C>.. <C T="U32" I="6" O="false" N="IPInvalidTimeOutErrCount">.. <S T="1" F="IPInvalidTimeOutErrCount" />.. </C>.. <C T="U32" I="7" O="false" N="IPInvalid
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5974
                        Entropy (8bit):4.667173058872338
                        Encrypted:false
                        SSDEEP:
                        MD5:F53082074597B108C48CD36ED2DD5A42
                        SHA1:7B65F4477DECFF324D1E8F7A2F3C23BDA19D4270
                        SHA-256:7A8221B24ED4021AB6F901EA79D7E697A72A2CA988D87561B85C03002899F992
                        SHA-512:A2FE55C238B70E7E000526B1432A09D3220465DCB37DE6E8DB53E88902B58F0DB6A48CA65D5519653EBE4ADC8F6E41AF45DC0E582B7431E2E0541FC58397AE34
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11330" V="0" DC="SM" EN="Office.Outlook.Desktop.TracertDiagnosticsReport_Global_Stats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="120" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <Etw T="2" E="128" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <Etw T="3" E="129" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <Etw T="4" E="130" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <Etw T="5" E="131" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <Etw T="6" E="134" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <Etw T="7" E="135" G="{c911b508-e06d-4f76-8835-ea1b78e2f66d}" />.. <TI T="8" I="Daily" />.. <A T="9" E="TelemetryShutdown" />.. <F T="10">.. <O T="EQ">.. <L>.. <S T="4" F="IPTypeUsed" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="11">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3973
                        Entropy (8bit):5.086124442347522
                        Encrypted:false
                        SSDEEP:
                        MD5:20EF1AF56F3DD883A441FF4C30D63CAE
                        SHA1:89E2187420440DC0D31EA17C31735B82EA619F5E
                        SHA-256:E576E0EE4011267A19FE37E57B55038D057CA7B3A78E9FCD6B308FF941B801BC
                        SHA-512:BDDE604DDCD231E7984461B84CD52CDF6C37F288B8AEB1DFFB8D3C36D478D6BA944DBAEF58B1288DAEC743A87210C1C9F917D4F31CCA5C35CF34CCA2CF6E738F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11331" V="1" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.CreateAccountExchangeResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="445" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="474" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="609" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="583" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="446" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3521
                        Entropy (8bit):4.354022569407757
                        Encrypted:false
                        SSDEEP:
                        MD5:05DD34A20CC556D3EF6B8E94CF757577
                        SHA1:6341D3A0C59A57783938124F74D17A92E05663FF
                        SHA-256:293F937B39CE1B8EE7D4D57EE083100ECF70DFD32934E4942D4397C0C4BD8F54
                        SHA-512:391B43C8D5D44D5B5FE8ACD789E8D234EC1171A4F0C19200B06FCA825D902EBF9E12DB24E3D0A01EE9ADD372B563FC185E3A486AF9AF58EA3F0CF45E11CA1C0A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11332" V="1" DC="SM" EN="Office.Outlook.Desktop.ReleaseTunnelOnTimeout_Stats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="6084" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="6085" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="6086" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="fTunnelReleased" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="fTunnelReleased" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="2" F="Tunnel
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3534
                        Entropy (8bit):4.156836658863191
                        Encrypted:false
                        SSDEEP:
                        MD5:B6CF537DE65951D59C7AD29189CBA7EA
                        SHA1:73772E17479EBCF85E8F78E3D191B0B0941BBA26
                        SHA-256:66701024E226C5EC6EC3148CFB00FCD8A7DF04211901E161778856D2F71D07B8
                        SHA-512:DAA678A9DA8B72504B2C15DB5E78A2B25946FB60E75716EB94F0A3BAD8D37923F6936BA76E631070CFCFF0FD507931E01AE6731375FD0D5A86AC14D9637D32D9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11336" V="2" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="819" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="820" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="821" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="822" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="829" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="849" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="7" E="850" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="8" E="851" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="B" I="0" O="false">.. <S T="2" F="IsTrustedProviderLibraryPath" />.. </C>.. <C T="B" I="1" O="false">.. <S T="2" F="IsValidPath" />.. </C>.. <C T="B" I="2" O="false">.. <O T="GE">.. <L>.. <C>.. <S T="3" />.. </C>.. </L>.. <R>.. <V V="1" T="U32" />.. </R
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3800
                        Entropy (8bit):4.3091989448023185
                        Encrypted:false
                        SSDEEP:
                        MD5:D977EE6D3D23667DD282736795D02A6D
                        SHA1:819329F30CB94468CF8F292B95D2716755108AC3
                        SHA-256:96F730208B8F041E47D6970D1A68DDEDB4750791DCDBB3A787A8D517BD47697C
                        SHA-512:80F6C429B3B78FAB8EC1ADF1E095E6CA4262EB47FB4C88B213C2ECA79BC6E95191F95825048E7DA1FD7948B6D3936EB759334CF1159C6BA4233BB1A8B6EC517B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11337" V="3" DC="SM" EN="Office.Outlook.Desktop.ScIsTrustedProviderLibraryMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="819" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="831" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="844" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <R T="4" R="11336" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="6" F="5" />.. </L>.. <R>.. <V V="true" T="B" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):498
                        Entropy (8bit):5.26857626062051
                        Encrypted:false
                        SSDEEP:
                        MD5:6B0270E1D00B733CC034A0218EDCD218
                        SHA1:1986499713F522666D6874F0916BD14A5F390227
                        SHA-256:7C4388C528C5736F651460D3F462C06264309C6991D8E24C704FAA084598A77D
                        SHA-512:A0812057DA068C85718D41E2D5F6F71D1425DECE75812397E525401A880FD90FCCE52190CB9FDDF20079AB0CA59A32CDF025FFA805260237971C5A6B3EB90ABA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11340" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateUnifiedGroupDialogHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="by7xi" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2980
                        Entropy (8bit):5.040256523061429
                        Encrypted:false
                        SSDEEP:
                        MD5:48A683A05558C3A740BE41F174B0CF9D
                        SHA1:209126EFC0BFEA3B2BBFD3EE9CEB4F60B2F882A8
                        SHA-256:0CA602F0E0EDACC49573E38A18161ECB72954FAEA6B0611B3321616BB34D709A
                        SHA-512:B39BAA8314091155B21B6DA3297DF316A080BCB3D06F2A30FDBCDC624B0904C045209C70328213A6F125E7648DE79AE4800D3FFE6962984332E63676A5940D1F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11341" V="2" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AccountDetection.UpnToSmtpTranslation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="464" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="465" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="466" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="467" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="468" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="469" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="7" E="470" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="8" E="471" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I32" I="0" O="false" N="IdentityProvider">.. <S T="2" F="IdentityProvider" />.. </C>.. <C T="I32" I="1" O="false" N="FederationProvider">.. <S T="2" F="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):957
                        Entropy (8bit):4.6714341552579395
                        Encrypted:false
                        SSDEEP:
                        MD5:F870F27E93AB28040B4A3F7A5E7A8587
                        SHA1:25AA2FEA7F44821EA5C3D6118951D864B6D04D91
                        SHA-256:72ECB926BA653CEE47322063890249E2FC97C2DE8D09BF053C63C0B8451B7197
                        SHA-512:72BB569086D7F76019A1680E6E520304FAC9DA47634C4982E8173D5C5047D46A565FBC22F2F704D0C42B28459ABCC09644164286AD1D058DCFC766A378452DA9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11345" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateGroupAdvancedSettingsHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="by7xj" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsSucceeded" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsSucceeded" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Success_count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Failure_count">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1146
                        Entropy (8bit):5.164825537725088
                        Encrypted:false
                        SSDEEP:
                        MD5:CE959E6B8525FDCE99FC30EE3FD63CCC
                        SHA1:057F27271EFEB65958AFB728F5B684A8EF77D875
                        SHA-256:630CB59C464F4B23A3007DB9039844283F5AAEB699C3FBADBDC3BE1074D235F9
                        SHA-512:0F91B3456B1923DAD8B3DF9E11F4784C51F6A4CADAE5C615882C704589113B0F35A07E0FC1C8E0F157A39345BF0AD864B9B77037887A4D7AC07F28E65CB5E6E1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11346" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateUnifiedGroupDialogUsageWithDialogVersion" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="by7xk" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="B" I="1" O="false" N="IsGroupIdManuallyChanged">.. <S T="1" F="IsGroupIdManuallyChanged" />.. </C>.. <C T="U32" I="2" O="false" N="DescriptionLength">.. <S T="1" F="DescriptionLength" />.. </C>.. <C T="W" I="3" O="false" N="ClassificationType">.. <S T="1" F="ClassificationType" />.. </C>.. <C T="U32" I="4" O="false" N="GroupType">.. <S T="1" F="GroupType" />.. </C>.. <C T="W" I="5" O="false" N="CultureType">.. <S T="1" F="CultureType" />.. </C>.. <C T="B" I="6" O="false" N="IsByDefaultAutoSubscribeOn">.. <S T="1" F="IsByDefaultAutoSubscribeOn" />.. </C>.. <C T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):519
                        Entropy (8bit):5.308025432751836
                        Encrypted:false
                        SSDEEP:
                        MD5:DE76C7F0DB79D49C22D734FCFC08CBF9
                        SHA1:D0A8802FC72538CADC82FB132A43F38313F4B8B0
                        SHA-256:495835D667DE89FAEDB2156BFB84C22E2701846627C0FADD63F17A27A8B33DD4
                        SHA-512:6E85CEB5A2AD2FD5B13D974480558BDDC6F6F0776603453C6E6DBED8FE02A3A1F53B73AB2D5B84D346927D0ED4523C308976222E383F8AA96BDC061F313D29DA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11348" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlmime.IMAPCMDBufferOverflow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="144" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="W" I="0" O="false" N="CMDTag">.. <S T="1" F="CMDTag" />.. </C>.. <C T="U32" I="1" O="false" N="CMDLength">.. <S T="1" F="CMDLength" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):579
                        Entropy (8bit):4.78169479825239
                        Encrypted:false
                        SSDEEP:
                        MD5:4B4EDEB1F2630263E88A58F4E9C878C7
                        SHA1:84DC067F128F9CE205D38B08C183351D727D5989
                        SHA-256:4FCAD204CA424032CA8C2F5BC4DE26FE4C713E3A408861C3AA6E4917423C7E35
                        SHA-512:CFD19F2E258E078B7122E0DC9263063BD1C1F3B8274BE8F566263D580C95205A9668820688A41AC9F89A64C17DF0D760BDBF831F36FA6FA2641BDCD64C697859
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11350" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="142" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <Etw T="2" E="143" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="U32" I="0" O="false">.. <S T="1" F="Protocol" />.. </C>.. <C T="U64" I="1" O="false">.. <O T="SUB">.. <L>.. <S T="2" F="TickCount" />.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2768
                        Entropy (8bit):4.021178377209855
                        Encrypted:false
                        SSDEEP:
                        MD5:D3BF78EDF600083FDCCC49F0AAC2FF77
                        SHA1:8ECDA6A71191C0AE0D0C26AF090675A405C4D500
                        SHA-256:54AF5602EB6BB7E85108376DC8A102C44D48270926ADDDCC43399D3B32604A10
                        SHA-512:403AE664ADC607936D7F6A38B6BAC9FB895BA2E67CD2016BF257ED572C6E48A14D55F427B8CA5B9185BD47D7CB0326BB325E4B2A7660141EF30815C0D4CB1AAD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11351" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlmime.OAuthPromptDetectionTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11350" />.. <Etw T="2" E="142" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="LT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="15000" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="15000" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="30000" T="U64" />.. </R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):520
                        Entropy (8bit):5.295776856244425
                        Encrypted:false
                        SSDEEP:
                        MD5:91D3F1DD518F22BCE919808281798CA8
                        SHA1:CE41A58BD44798B3EA16ACA9B04B4E5E3C9E0EC3
                        SHA-256:F42B84A81F46A58045F90C92C3331B152298D41BF99D19DFC3181A6246E4BE1A
                        SHA-512:F50895F7C1EF1CBAD5F110D21E4765B30AD80B1109883B249DA726A9C0D7A9E068C79B6BEBFD513945C76B636EFEC4513A36FD2B3FB7C2DB1201EFB37CD77650
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11352" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlmime.XOAuthGenericError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="136" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="W" I="0" O="false" N="RequestId">.. <S T="1" F="RequestId" />.. </C>.. <C T="U32" I="1" O="false" N="Protocol">.. <S T="1" F="Protocol" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1257
                        Entropy (8bit):5.061655606058585
                        Encrypted:false
                        SSDEEP:
                        MD5:8E003B78E155B17E419A1639CBC57A6F
                        SHA1:0BA751861AD6D6960CB6EFE2DD3453950BFEE15B
                        SHA-256:C71FA0EDD9D4628D96995E1FDF5446E20C8D23F461D2E536BA44A94964C564A5
                        SHA-512:F316E92B921C673B3FD2DDF4F66DF8CED9E2445FFE7949D76A14BB33AB8EEFC1E4A6A16614476E177F0C1A540F03B8FDAED7395CEBCDC1646C472AB638FCCAB9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11353" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlmime.AuthDataRetrieveSummary" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="137" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="RetrieveAuthDataResultFromPrompt" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true" N="RequestId">.. <S T="2" F="RequestId" />.. </C>.. <C T="U32" I="1" O="false" N="Protocol">.. <S T="2" F="Protocol" />.. </C>.. <C T="U32" I="2" O="false" N="AuthDataSource">.. <S T="2" F="AuthDataSource" />.. </C>.. <C T="U32" I="3" O="false" N="RetrieveAuthDataResultFromCache">.. <S T="2" F="RetrieveAuthDataResultFromCache" />.. </C>.. <C T="U32" I="4" O="false" N="RetrieveAuthDataResultFromPrompt">.. <S T="2" F="Retriev
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1826
                        Entropy (8bit):4.757043082175548
                        Encrypted:false
                        SSDEEP:
                        MD5:58B0BCF4FCF0176967F4D27D4C85AE1F
                        SHA1:B1B69A1216C35C45CA112C2934975391CB912871
                        SHA-256:715BAF8CBBDF4EDBF014A5F78ED675EFC3505E611C27A353D99F3488BDE637E3
                        SHA-512:040E919D00F96E2B7A77F322561E2ABE66D86A7D6C1502151A8E9C33E038A9D357564E825A20DFC851C7EE5E3ADED7F7093DF5288CD2085ECFE334DE2D02D339
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11354" V="2" DC="SM" EN="Office.Outlook.Desktop.Outlmime.AuthDataResultSummary" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="137" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <Etw T="2" E="138" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <F T="3">.. <O T="LT">.. <L>.. <S T="2" F="AuthDataResult" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="AuthDataResult" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="5">.. <F N="RequestId" />.. </S>.. <S T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1459
                        Entropy (8bit):4.732862056574448
                        Encrypted:false
                        SSDEEP:
                        MD5:63F92712F6710F82C85A66F96B700865
                        SHA1:4372DB31BD82102941E446A18A58FFC958A10A13
                        SHA-256:F3BB5DEB39AB64CF74B747C2764C6D724E87A025E56DE627F8847E29FFC00DD0
                        SHA-512:3B24E68D2079AEBE366DC4B5637E58000D994A2C1979997AD6E80EC35D6CCC120D4D6E80FB0C03EBA1EFCF5F70C72BE1D20972180343A7BCC962239C420B0CA7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11355" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlmime.AuthDataRetrieveStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="137" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GT">.. <L>.. <S T="1" F="RetrieveAuthDataResultFromPrompt" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="RetrieveAuthDataResultFromPrompt" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="Protocol" />.. <F N="MailProvider" />.. </S>.. <S T="4">.. <F N="Protocol" />.. <F N="MailProvider" />.. </S>.. <S T="5">.. <F N="Protocol" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1777
                        Entropy (8bit):4.563887331865714
                        Encrypted:false
                        SSDEEP:
                        MD5:3E3E445BF054832E7617B22FD34384B3
                        SHA1:82C72C0F84B3A01B02331D54E4BCD16496BEC729
                        SHA-256:5E6191CDD196C6356A21788978A2A5FFDA8BD4EEF68DD52CCC53B6524A4A49DD
                        SHA-512:3C8266419D6A09275FEB5A10BD48BB72FC0B789EC64A2138781738380E0077615AFC94AFDCBD6D6388FE63D91681554E1A5A7F1B44DFF40AE23D3419C5679946
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11356" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlmime.AuthDataResultStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="138" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="AuthDataResult" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="AuthDataResult" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="AuthDataResult" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="Protocol" />.. <F N="MailProvid
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):800
                        Entropy (8bit):5.106907365831597
                        Encrypted:false
                        SSDEEP:
                        MD5:634783DFEA4B48F95034E86A82C1ADAF
                        SHA1:63DFDC3F0AE152FB68AF76D195AC02E868F95A1C
                        SHA-256:EED0D22FC4FDE86208539A4117AD74151E6D6BC9689DC5DF8E6F7EE8199F3583
                        SHA-512:A1630834B608A54D6CDCBE2138B69A787370EA99F892CA7A248D03A78BD0EEC2331AD007570B651CA0CB5DB7F1569AC6076A6465C4AA9C5BD8BA5BFC4B65AC27
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11359" V="0" DC="SM" EN="Office.Outlook.Desktop.Ews.GetClientAccessTokenPerformance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="343" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="TotalCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="F" I="2" O="true" N="AvgElapsedTime">.. <A T="AVG">.. <S T="1" F="ElapsedTickCount" />.. </A>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1021
                        Entropy (8bit):4.699976851010327
                        Encrypted:false
                        SSDEEP:
                        MD5:1BA2B29CC2B1665D62F2FFC489E8DB46
                        SHA1:B82FEED33FA0B1A6E724F0278E064972D04AD04D
                        SHA-256:493251F3F7DD7848BA7AA2797FA79567279305C6998374CB235838685A20B2C8
                        SHA-512:A80ABED2200B1EBCE4ECF04C3EFFEB8950B26D66DE287BC136ED3BEDE083E4F03FDE6CA49D4BE62F5AA6573A125F102C6E8FAF646F5E13FFF520379E500110C3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11360" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.DetectedEntityHighlightRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8230" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="SuccessCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ErrorCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2071
                        Entropy (8bit):4.596697633095891
                        Encrypted:false
                        SSDEEP:
                        MD5:EA98D3A7DE653D731D5F278E13AEF9B9
                        SHA1:B977781859DDD27A1C241FB878CE1045598318B5
                        SHA-256:82326309C3B8BED6884E276548FEFB3A2D514C209BF93DFEC5797B5D0E64DCB9
                        SHA-512:429D17F8941548F7878D66FDB9CC49D0A06AD9E1909696D0FB56D1FCE4F754BAA9B88C44CA128669CF54EEDDA1F2AB6D57322E2A77CCAF21DF60C2C936300AFF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11361" V="0" DC="SM" EN="Office.Outlook.Desktop.OABTempFileDownloadHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1102" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="1103" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="1104" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5508
                        Entropy (8bit):4.30793332543153
                        Encrypted:false
                        SSDEEP:
                        MD5:8203650DEA49B30CFA19DA152B9941F4
                        SHA1:00BEBB96486C1B2C0EE4196CC19A7ED4C49FF0D9
                        SHA-256:C7FCDAD71BF23B579F33F06F84D5A40AE51ADA789507EDDA7BE71396F1C9013E
                        SHA-512:26D8CA27DA5C7B056D1746B85FCD11434D986AD57A402EEFF063A6E5525CBECAA18790511BD16DEB378F6DB2B3BC349A3354439710A79C064AC78E6168F417B8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11362" V="0" DC="SM" EN="Office.Outlook.Desktop.ContactCardCustomFieldStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="by7w3" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="standardLabelName" />.. </L>.. <R>.. <V V="Email" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="standardLabelName" />.. </L>.. <R>.. <V V="WorkPhone" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="standardLabelName" />.. </L>.. <R>.. <V V="WorkPhone2" T="W" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="standardLabelName" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):442
                        Entropy (8bit):5.361702573611175
                        Encrypted:false
                        SSDEEP:
                        MD5:9764FE97FE5D379A5EE48B5BCD68F026
                        SHA1:0A02FF51C2B7781C27E1668767C6E6FE31154E98
                        SHA-256:FCF73BE7DE3C96108E12564428DAD6BE2C91D2A4B62570C23B15D4CCC0D353B9
                        SHA-512:3A4D751A7DCD13E8D483F92BA91D0ED908B64B6170BCF167BC8753720258831BCF7C26FDEFA138DDE739834FB019044DC54A2AFCDB8B4A3B2830B26E1A1DCABF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11368" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsExpandFirstTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18057" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="SetExpandGroupsRegKey">.. <S T="1" F="Result" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1689
                        Entropy (8bit):4.694592238345232
                        Encrypted:false
                        SSDEEP:
                        MD5:A3D87B371DB3B80301865DD822E8A4EB
                        SHA1:7AB546903DEA6DB7EAFFD77A2F2D905D5465E86E
                        SHA-256:7271EE468D5C39E227B0A29E2EDCED4EBBDFD17BE20B4D22EDAECD7DA6E52A0B
                        SHA-512:2CDD1C3128EE4C37397967C476468F5F1FBCF1A9FE4150B54ABB053804714C9C18DEF0C246A48B75B5339ACC062569A729CAC7F596CD2929772FE783AD5EBFB1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11369" V="1" DC="SM" EN="Office.Outlook.Desktop.PcxOcom2ConnectionHealthStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="bzplw" />.. <UTS T="4" Id="bzplx" />.. <UTS T="5" Id="bzply" />.. <UTS T="6" Id="bzplz" />.. <UTS T="7" Id="bzpl0" />.. <R T="8" R="11794" />.. <F T="9">.. <O T="GE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="10">.. <O T="LT">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Ocom2IUCOfficeIntegrationFirstCallSuccessCount">.. <C>.. <S T="9" />.. </C>.. </C>.. <C T="U32" I="1" O="false"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):667
                        Entropy (8bit):5.004173158996676
                        Encrypted:false
                        SSDEEP:
                        MD5:C282E64D7711E21DFF8C26BC92417A32
                        SHA1:B088056DD50031CC254CC63DC90C2F377B05C728
                        SHA-256:C36A2D390EC0ADA2B77E271696742CF472024F9732F802AF1333A635CE77A5B6
                        SHA-512:2A93415F4F3F9F93339C79ACDA657ED6E8ABD4EECC3A3C4B300AD1E5DDA5D7559F1C7EAA5EA3DB0F98E672C7F25BA4D695C145FDB2911877701BD89220B4978A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11370" V="1" DC="SM" EN="Office.Outlook.Desktop.PcxIMProviderIdStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="bzplv" />.. </S>.. <G>.. <S T="3">.. <F N="Clsid" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="IMProviderCLSID">.. <S T="3" F="Clsid" />.. </C>.. <C T="U32" I="1" O="false" N="ProviderCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):785
                        Entropy (8bit):5.148171860607801
                        Encrypted:false
                        SSDEEP:
                        MD5:6A007502712030335BDCAE2CD83F679C
                        SHA1:849DCF815E68DC5B94E03F4F63E1C792A80B4C30
                        SHA-256:C387E75264F270D2EC29E14DF35D68D5C7ADBC971005B60874BD00949537B1E7
                        SHA-512:A557D8B9089A97C1D25EEDAB163A6CAF84E27E543EB5875BFC4FEBEA778CA896E7F7FACCA4D3FC3B5FFF0520EFAE96170A7578BDD10A0B07F3C058F30D3C80D0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11377" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.WeSpaceHeaderHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18056" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="CountFailures">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="B" I="2" O="false" N="IsGroupHeaderV2">.. <S T="1" F="IsGroupSpaceHeaderUpdatesEnabled" />.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2409
                        Entropy (8bit):4.2355029291387805
                        Encrypted:false
                        SSDEEP:
                        MD5:0BD0AFBFC2854052B3489BD8764EC93D
                        SHA1:EF5CAC1230CDDBC39884A3ABB5CE5B07D8DE209E
                        SHA-256:8043FD42529C4F6D8AE7AF858B4F60342746F4D3CB5A3E587D6925D93A1ECC11
                        SHA-512:176E5B1386946308370F613064DF81FE4A05903F0417BD2AD6756825E56070A9C4A56BEB681C01BE145CF38B31F7DF951F614C1404F9E0FA62F48C608723D552
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11381" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxIMProviderCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="bzplv" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="Clsid" />.. </L>.. <R>.. <V V="{A0651028-BA7A-4D71-877F-12E0175A5806}" T="G" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="Clsid" />.. </L>.. <R>.. <V V="{8885370D-B33E-44b7-875D-28E403CF9270}" T="G" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="Clsid" />.. </L>.. <R>.. <V V="{5C4C8078-24CF-4C71-B05E-8B1D935DB5AC}" T="G" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="AND">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):791
                        Entropy (8bit):5.180529221367605
                        Encrypted:false
                        SSDEEP:
                        MD5:331739D6C0B60A8888054959A1C961DD
                        SHA1:4B8C807AC8252F514CCF25FBECAC12CDBFAED084
                        SHA-256:DEB59A221D72844CDAD69BD93DA7D75C53C3E80A6C92DAB75BF41475CA3B341E
                        SHA-512:11964090B3387E2BE9507E83FFEFD9E27C1A8FA6379594CADD04100C85397670A6B941ACFCC8F8A5BAE021C879322453C08CC12DAC5697347273D996FE2C3882
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11388" V="2" DC="SM" EN="Office.Outlook.Desktop.WatsonThroughRecon" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="500" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="501" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="W" I="0" O="true" N="DateTimeStamp">.. <S T="1" F="DateTime" />.. </C>.. <C T="W" I="1" O="true" N="OfficeBuild">.. <S T="1" F="OfficeBuild" />.. </C>.. <C T="W" I="2" O="true" N="WatsonBucket">.. <S T="1" F="WatsonBucket" />.. </C>.. <C T="W" I="3" O="true" N="ProcessVersion">.. <S T="1" F="ProcessVersion" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):901
                        Entropy (8bit):5.071280004144856
                        Encrypted:false
                        SSDEEP:
                        MD5:A96BE6162CFEE38253A2B73DB4805844
                        SHA1:1345D970F7D816DEF52288E05E313C0C60B33064
                        SHA-256:0C3B0A1D4812D6F34800BD11F47DD100172477B85413F8258BB25CD30F2D5DB7
                        SHA-512:B14897D8F5DE05B6033A4F2791CDFA191055399E72892FF66172F09C7DEB8844A11EE5BD7602145F2F3F399EBDFF00A0A5F36AAFFEB925C62D431925406FEA03
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11389" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EwsSoapErrorInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="345" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="3">.. <F N="RequestType" />.. <F N="SoapErrorCode" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="RequestType">.. <S T="3" F="RequestType" />.. </C>.. <C T="U32" I="1" O="false" N="ErrorCode">.. <S T="3" F="SoapErrorCode" />.. </C>.. <C T="U32" I="2" O="false" N="EvaluatedErrorType">.. <S T="3" F="EvaluatedErrorType" />.. </C>.. <C T="U32" I="3" O="false" N="SoapErrorCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):970
                        Entropy (8bit):4.887876884915576
                        Encrypted:false
                        SSDEEP:
                        MD5:6D77E0611708C53A8C88809D4DD24090
                        SHA1:E8F66AB12D0830BF10C8BCE8751AAC74B0181672
                        SHA-256:57E6F49A97BE9C657383C2CE9340058DF2DDC3A917AD533B7A3104D8540A53A3
                        SHA-512:E1B85FF349FB304D19166CBAAA17A06924C9D3718115F177A2D0761A339ADAE4900CF752199F8DCB7B8B16AC3BCA23FA24B71A32F6345827D5F313AECAE5F01F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11392" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.EasyJoinGroupError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18058" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="TraceLocation" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="TraceLocation">.. <S T="4" F="TraceLocation" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="4" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountResults">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):577
                        Entropy (8bit):5.203154204576708
                        Encrypted:false
                        SSDEEP:
                        MD5:023B9EC194AE9DFBFD8CC42EE995969C
                        SHA1:DB2F3EEBB72724837C7C554018758FA6412FAEF7
                        SHA-256:AF08B3DD4CC5C7140398F6E8034C2A3200CA521F90BF8E11608B3F463DFB66AD
                        SHA-512:3BF132BF4145A502770B89D32F5E634D1984119F8671B03D70E05931B9C17164CFA5CC797130C0DFFD0B6600DFC0F130088C336D6AFCCD428128A546F02B27EB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11393" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchFeedbackButtonClickCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9051" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="SearchFeedbackClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):686
                        Entropy (8bit):5.185347012216247
                        Encrypted:false
                        SSDEEP:
                        MD5:4741D4E1F760642E1C2B1CE0DEEABCB6
                        SHA1:13AA347C0F30CB8A93CC9C9C8B82DE4F054F098B
                        SHA-256:F185E300E00BD6C5C45AD3838F34B6819B353448384AC31188924BC4D11D9670
                        SHA-512:BE7077264AD5132C8206E2FB184F577018CEBED3B1AE543132E94F0F82A6E34C56F18D59BE24E5644B38BD48EE76DA6948889673E0A48688A7EB7AA5D5E1A4FD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11400" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.V1.OpenSupportTicketResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3752" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="FunctionName" />.. </L>.. <R>.. <V V="OlkDiagnostics::HrOpenSupportTicketWithSelectedSymptom" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="I64" I="0" O="false" N="H_Result">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1809
                        Entropy (8bit):4.926618545391022
                        Encrypted:false
                        SSDEEP:
                        MD5:9501DB64F0437067CECE2B15E28741E8
                        SHA1:41E3F2B8614A7381AB11BF8AF47CEF2B2A9DFAF4
                        SHA-256:A6A39C4532332828651C9DC784A4EA2F4DA770D31C31F5AF48C57B095AA9525F
                        SHA-512:123309728205C02FDA9DDB64F51AA45C765F2E476843B898F43484B578A2B65DB0FFA5FAF5DD25DCBF9CA9E6297A0E1E2EB810278E974B095D9D35C1100BEAC8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11404" V="0" DC="SM" EN="Office.Outlook.Desktop.HangReportingScopedBuckets" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="315" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="ScopeId" />.. <F N="BlockingOpId" />.. <F N="BucketId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="ScopeId">.. <S T="1" F="ScopeId" />.. </C>.. <C T="W" I="1" O="false" N="BlockingOpId">.. <S T="1" F="BlockingOpId" />.. </C>.. <C T="U64" I="2" O="false" N="BucketId">.. <S T="1" F="BucketId" />.. </C>.. <C T="U32" I="3" O="false" N="BlockingOpCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U64" I="4" O="false" N="AverageHang">.. <A T="AVG">.. <S T="1" F="ElapsedHanging" />.. </A>.. </C>.. <C T="U64" I="5" O="false" N="Aver
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):967
                        Entropy (8bit):4.747383153599879
                        Encrypted:false
                        SSDEEP:
                        MD5:B2B41A2EBB40075F2EF5999924B2C86E
                        SHA1:AE67E98624513BA072CA324FD3B0BCC22C8482A4
                        SHA-256:56FEB200ADAF39C9848824FF2642C74C1132B1DB856177A9D390DA2B359B77ED
                        SHA-512:22F3AD538189B76D9DC0A7B5E43C9C832322F718922999A1A0B7A6EA5EDB6679670B16C19C60C6BF1E26710DBD17DD8A8D268287339DC7AB6D74999CA208E791
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11405" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6115" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6116" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="isReadingInspector" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false">.. <S T="1" F="IsModernView" />.. </C>.. <C T="B" I="1" O="false">.. <S T="1" F="IsBigSwitchModern" />.. </C>.. <C T="B" I="2" O="false">.. <S T="1" F="IsFromInlineEdit" />.. </C>.. <C T="B" I="3" O="false">.. <S T="1" F="IsPrevPaneOpen" />.. </C>.. <C T="B" I="4" O="false">.. <S T="1" F="IsOpenedFromNextPrev" />.. </C>.. <C T="B" I="5" O="false">.. <S T="1" F="IsOpenedFromGroup" />.. </C>.. <T>.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1700
                        Entropy (8bit):4.588517563889701
                        Encrypted:false
                        SSDEEP:
                        MD5:4083C2B119EB8132DB4D06024FD78290
                        SHA1:1AE3609E659C5769111A1ED83020611B228F241B
                        SHA-256:A81DFB7DF79E97511DAECC759FD3C0E7CC5D62A11A3B97AF5611D0910607EC72
                        SHA-512:6004F46CCCC94522B29572E8E72CD9999B34BFC922E5730735275359131EC4E43CDDAA203DD49DCDE5ADCA753778BEBCAF3CB72934B9A0E79EF438ADF99ADCDA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11406" V="1" DC="SM" EN="Office.Outlook.Desktop.ReadingInspectorPopoutsCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11405" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="TotalReadingInspectorsOpened">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="IsModernView">.. <A T="SUM">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="IsClassicView">.. <O T="SUB">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <A T="SUM">.. <S T="1" F="0" />.. </A>.. </R>.. </O>.. </C>.. <C T="U32" I="3" O="false" N="IsBigSwitchModern">.. <A T="SUM">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="IsBigSwitchClassic">.. <O T="SUB">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1297
                        Entropy (8bit):4.5520541017509215
                        Encrypted:false
                        SSDEEP:
                        MD5:BE771AEB77D8B9B0A758F326867C4A6A
                        SHA1:83A43576296A97BB6A92EF53A9BF2F296C221459
                        SHA-256:13EF3BE617676A36FFAEFCF1160FDB7B90C804957DCA3809EBC22661B464E694
                        SHA-512:2CF9B1070485BA2496352AD1F555ED5C9C9C96C36B12F96222C6877FBE9C833DADBB32FDFA3E8F355E8C3991AB0EF85F11CD89491E9A5412A7FE42F4B3899587
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11408" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EasyJoinGroupResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18058" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="TraceLocation" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="TraceLocation" />.. </L>.. <R>.. <V V="7" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="TraceLocation" />.. </L>.. <R>.. <V V="8" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="ShowCount">.. <C>.. <S T="4" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3492
                        Entropy (8bit):4.568333094328758
                        Encrypted:false
                        SSDEEP:
                        MD5:BB822E709379386E19E982F25A315720
                        SHA1:137C4F2BCC2D7D375BD149AA31DD93E532A827E1
                        SHA-256:D85791E487EDFE7978F436C046E6907D5933E0A0F2740088F2A23D0A57E4E8A7
                        SHA-512:B6C704634EED17AB1122E610F9273ECC5858C558BE9DB64EF4A7C98A427A66F85AD1AFEB8027C63A4D90574C12A079CBAFD8809A6B33DC330AA4EC9AACF5B124
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11411" V="7" DC="SM" EN="Office.Outlook.Desktop.BootPerfMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="5" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="700" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="219" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="728" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="4" E="729" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="5" E="730" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="6" E="9157" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <US T="7">.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </US>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="7" F="fPrompted" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U64" I="0" O="false" N="ElapsedTotal">.. <S T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1438
                        Entropy (8bit):4.554567464825557
                        Encrypted:false
                        SSDEEP:
                        MD5:42CC891283671D2FC5643BAD7FAC27E3
                        SHA1:DABB7364FF79F08D930389164FE3CE96AE0C3170
                        SHA-256:6F81F0DA62BDBD9CBC7E4969EE66A5FEE96CBB40A826FA5AA2959A4BBCA79386
                        SHA-512:AD6DE8002146D7B00A15B3303D51FBFC02EC0361294814F97F49A940D6E2BF48AA89CE9182788FFFF89DDCAAA99F8655285B5409AB6C80985A492B6D3726CBB0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11414" V="0" DC="EUII SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="18034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="hasGroupRecipient" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="4" E="307" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="EventType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <Etw T="6" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="3">.. <F N="groupSmtpAddress" />.. </S>.. <S T="5">.. <F N="Group" />.. </S>.. </G>.. <C T="W" I="0" O="true">.. <S T="3" F="groupSmtpAddress" />.. </C>.. <C T="FT" I="1" O="true">.. <S
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1269
                        Entropy (8bit):4.006442304160597
                        Encrypted:false
                        SSDEEP:
                        MD5:7BD54F66F5615E094A8824A4FF40D83D
                        SHA1:25607D3562CD96125D1EAE9864FD4ADE16784554
                        SHA-256:82D82C7DE19ECF7F0449BEAFE6AF9B86C24AD71323C19D748BF822C944446CC1
                        SHA-512:0E54D87BE5352DA2FF794A6C0FB3C4ECAE182104A962B14F03AE6C248AEAA5FA3EBEFC357A80C9629C21F8966BE67E9C2D6A575C2812B6C8DC36E7680EEE0D58
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11415" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <R T="2" R="11414" />.. <F T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="2" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="2" F="3" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <Etw T="4" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. </S>.. <S T="3">.. <F N="0" />.. </S>.. <S T="4">.. <F N="SmtpA
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):848
                        Entropy (8bit):4.822774097151667
                        Encrypted:false
                        SSDEEP:
                        MD5:C28608F004113F6C2F150946920D3FD3
                        SHA1:8B3A66D2EC5D6D6365253227229A69F40085E61B
                        SHA-256:3DAE6E045352FA941FCBA9A29A8A158E8D4F3272CE06B2ADBF36532D5A448F42
                        SHA-512:4C7D8DE42E0207B327220E71F47EC2BF3719EDAC8797C072B5769271D0ABBAD57C3C7B2913AE7524B11D4310DA89117E8D8675329D4B1CF61DADA0CEFCB3D2DC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11416" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.NewPostContentNotificationLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11415" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="ContentNotificationCount">.. <A T="SUM">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U32" I="1" O="true" N="AveContentNotificationDelay">.. <A T="AVG">.. <S T="2" F="1" />.. </A>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1909
                        Entropy (8bit):4.028621778134932
                        Encrypted:false
                        SSDEEP:
                        MD5:2BBDD8CD30A8AA50C708373653783B98
                        SHA1:72C07AF7EBABFFF143A6F066FE026E2F86EB89CC
                        SHA-256:DB1DEACC8B9B83314C6586971CA1E66A0AE595902E1BA432F3F73C9D96E537CF
                        SHA-512:8E2C86C39D6DC4170BE240D902B8D39675BD1C72FDE55266BE99A0F5D3E8A33C194E81FF3CA0183F749404F5084E3476C6DA5764ED996EF7905E18FA57BEA9BC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11417" V="1" DC="EUII SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="3002" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <Etw T="4" E="241" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="4" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="4" F="LogStr" />.. </L>.. <R>.. <V V="15"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1119
                        Entropy (8bit):4.541582624578356
                        Encrypted:false
                        SSDEEP:
                        MD5:EC48BF2D0E1CD88D499616172293982C
                        SHA1:8B15E37DA80B5D6D0EDB444BCD6F8EE4AB3E1008
                        SHA-256:801FE95D8BAD1CA54E038C72918D675A7BF8D8D51854CF3341682C6399D859D3
                        SHA-512:5A6A3D64B25FBD43A0C1CCA855336B88D771C6E242EFFA9E06F4894162D03F38DA6FDEE33BEEF80410B103CCF342E9C92F736330528C514B784F4CD174BEE0C1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11418" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="3250" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TH T="3">.. <O T="EQ">.. <L>.. <S T="2" F="SmtpAddress" M="Ignore" />.. </L>.. <R>.. <S T="1" F="SmtpAddress" M="Ignore" />.. </R>.. </O>.. </TH>.. <R T="4" R="11523" />.. <TH T="5">.. <O T="EQ">.. <L>.. <S T="4" F="0" M="Ignore" />.. </L>.. <R>.. <S T="3" F="DisplayName" M="Ignore" />.. </R>.. </O>.. </TH>.. <Etw T="6" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="true">.. <A T="AVG">.. <S T="5" F="1" M="Ignore" />.. </A>.. </C>.. <C T="I32" I="2" O="true">.. <A T="SUM">.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):927
                        Entropy (8bit):4.750135804628167
                        Encrypted:false
                        SSDEEP:
                        MD5:E0F5BEE94DA227F4176E0605D6A80C06
                        SHA1:C572605A92A5696BE41735C6A29A2E1F99658582
                        SHA-256:8E6C601134AD96CC2444B819D809E9609166A3861D7B44A4ABA26A146947D5F2
                        SHA-512:9C663F963E14EFCF5A5EEC9F23528E0A064A4364390D80BBD902D9CDE0CC812B75604CF414D0A4FF730685053DDF64543598FDDCB0A21FEBDB06305A8114BFBA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11419" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.NewPostContentSyncLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11418" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="EventCount">.. <A T="SUM">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U32" I="1" O="true" N="AveSyncDelay">.. <A T="AVG">.. <S T="2" F="1" />.. </A>.. </C>.. <C T="I32" I="2" O="true" N="TotalSyncMessageCount">.. <A T="AVG">.. <S T="2" F="2" />.. </A>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):773
                        Entropy (8bit):5.20234014539066
                        Encrypted:false
                        SSDEEP:
                        MD5:75BCDC50679FED98935C35992D67A81F
                        SHA1:614F72767DB89BA48573A891EE3972F5EE93B7C9
                        SHA-256:246007A5046B29CA47D1790385BEB236C0C8CE69DDA61B194FF83739C68021A7
                        SHA-512:4FA8554E4436BA7B332898F5FA1B55B29E0FF4DF05A9A2B1D60C728DD441154BD845E729901AB6479407FFC0B8E9639EC66D8637816DC8F7A829F7C8AD9125DE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11427" V="3" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsV2.ReconRecoveryLink" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="502" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="W" I="0" O="true" N="RecoveryLink">.. <S T="1" F="ReconRecoveryLink" />.. </C>.. <C T="W" I="1" O="true" N="RecoveryTitle">.. <S T="1" F="ReconRecoveryTitle" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="RecoveryDescription">.. <S T="1" F="ReconRecoveryDescription" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="RecoveryId">.. <S T="1" F="ReconRecoveryId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1258
                        Entropy (8bit):4.589271535658063
                        Encrypted:false
                        SSDEEP:
                        MD5:5CDC925879A34E027719BCC9224A3827
                        SHA1:81E5837C6CD1A08F9BE3DD087A89AC424FA74DC3
                        SHA-256:F1E2A273FE3AB28A192706CF851BF56DD22AC96EE52BDAEE61B9978093A609AC
                        SHA-512:4F868BB087245BCC93D779DF525C314E029799E7DF8F168B287760E7A6CC655D185106302111D884A9A2BB770433E9E248347702CF2C26869F5155017C1D5297
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11429" V="0" DC="EUII SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="18034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="hasGroupRecipient" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <TO T="4" I="30s">.. <S T="3" />.. </TO>.. <Etw T="5" E="307" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="5" F="EventType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <Etw T="7" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="3">.. <F N="groupSmtpAddress" />.. </S>.. <S T="6">.. <F N="Group" />.. </S>.. </G>.. <C T="W" I="0" O="true">.. <S T="3" F="groupSmtpAdd
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1022
                        Entropy (8bit):4.16008625487853
                        Encrypted:false
                        SSDEEP:
                        MD5:38B8CF2FA53529DBE0FDC3FC805C30D9
                        SHA1:E5705BF1243B0FBBFFF5761FE1CDE2F35CA9169B
                        SHA-256:492B84C267A21658CDF3D0EB27AB75D98BC37EFC3B2DD68D49749D9DFEFC28C8
                        SHA-512:5B4D61A984BC43F2617836C350D59D6EBBAE3C0E4CF1141B4AD165F71BD6689DD2536C8578EAC2F210D35D1E5E56BD4EEEDD9600C17ED28EAD4F80803E5A74C7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11430" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <R T="2" R="11429" />.. <F T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="2" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <U T="EqualsNull">.. <S T="2" F="2" />.. </U>.. </R>.. </O>.. </F>.. <Etw T="4" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. </S>.. <S T="3">.. <F N="0" />.. </S>.. <S T="4">.. <F N="SmtpAddress" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. </T>.. <ST>.. <S T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):727
                        Entropy (8bit):4.83527387675724
                        Encrypted:false
                        SSDEEP:
                        MD5:BDE9A2D3C1DBA73A066C39E30CF26CBD
                        SHA1:3C84BFF3D08A718B4713475A173F1175EF614185
                        SHA-256:976469FB95EE0B653C77BEEA07716FE79EF91FCB344DCAF0F345F1C8A85E7E27
                        SHA-512:1E358818C3F5C6D4347169438571E5929381BD1A290FFCC96FF4D0FC65366A010B9AA50E6CEEF2ABAE6EE775459FE471EE71F27F82CFA5C1E9909F73B3D3A987
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11431" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.NewPostLostContentNotification" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11430" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="LostContentNotificationCount">.. <A T="SUM">.. <S T="2" F="0" />.. </A>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2056
                        Entropy (8bit):5.045502040473497
                        Encrypted:false
                        SSDEEP:
                        MD5:75ABBA833B3FA6EC5DECD6C06AD731CE
                        SHA1:70C7DFF09D1CC2CEF5B915D7882D456618CB7465
                        SHA-256:A0190FEE758AC0E2F36782A0AFE94A4F50F7EF1417E5B4CD279B2F0E2DDA08CD
                        SHA-512:41102405D6786B1AA66EEAB12FF88161C88264881EEEFCF7F10FA160752E466EED32250A78E9070FA8853B548A0DA1CD98DC1D26BA5E5F8121B34E295FD4F4EC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11443" V="4" DC="SM" EN="Office.Outlook.Desktop.AutoDiscover.GetUrlFromAutoDiscoverV2" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" E="false" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="614" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="625" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="626" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="615" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="624" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="576" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="ClientRequestId" />.. </S>.. <S T="2">.. <F N="ClientRequestId" />.. </S>.. <S T="3">.. <F N="ClientRequestId" />.. </S>.. <S T="4">.. <F N="ClientRequestId" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="UrlRetrieved">.. <S T="5" F="Url
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):585
                        Entropy (8bit):5.2141854016605285
                        Encrypted:false
                        SSDEEP:
                        MD5:C5EC7E8B708F33837EA30E92D1C9C3D7
                        SHA1:93DB7A2B9CF7334906FE8D95507AFD1D3F8FB165
                        SHA-256:4FC2D0F055365761D412CA3245B162843B82A28A45284E86140F91FA95ACCCA2
                        SHA-512:2652C617F24DB9BF56E6A4279080BFEB6582B2F6DA05D5DB12D83F22E4F2B470F3B0932CA8422B277801B03FBE12C820547DC78DF02D99BF59A38222AECB1B4F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11444" V="0" DC="SM" EN="Office.Outlook.Desktop.ClassicInlineComposePopOutButtonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6117" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="InlineComposePopOutAction">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):10729
                        Entropy (8bit):4.199919152742344
                        Encrypted:false
                        SSDEEP:
                        MD5:1BD4B6968BFED45AAEC164FC1424786E
                        SHA1:C69191E8465A30427CA4BA4661DFA8ADBD3DE362
                        SHA-256:36D4F2474508E536B344342B83057AD723C339F2B43D51C7F43756AFC458201E
                        SHA-512:59F6E64D219E8D05A79E9368BB5390745C293ECEABB46E8E62961890B05DD10F1F9C1C99D9DC37BDE16E427C11BF1F31B39A1B5C88AB90B7C7E06625879F829D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11446" V="1" DC="SM" EN="Office.Outlook.Desktop.PCXContactCard2LinkedInBasicUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="b3ko4" />.. <UTS T="5" Id="b3ko5" />.. <UTS T="6" Id="b3ko6" />.. <UTS T="7" Id="b3ko7" />.. <UTS T="8" Id="b3143" />.. <UTS T="9" Id="b3142" />.. <UTS T="10" Id="b3144" />.. <UTS T="11" Id="b3145" />.. <F T="12">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="4" F="NameLength" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="4" F="TotalMatches" />.. </L>.. <R>.. <V V="0" T="U32" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1099
                        Entropy (8bit):5.083641559014121
                        Encrypted:false
                        SSDEEP:
                        MD5:397652BDC267DD48474A301E6933BFCA
                        SHA1:AD1383238D4DB02F298259B0587EBCBE43833179
                        SHA-256:7D4A35008B18635C3930FD6659C0B9D3D3D7DA45393E9D7501FDB06A9257F1F3
                        SHA-512:DBAEED3FDAF6C838A2E6E6D761AF54CA28744B0CE80F8D48BD93BD1CA3DCAE6A4A2531206575F2426376D66519401473FF54F5BF2A19887AE8F0B08920DF0F06
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11451" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.AutoRunAddInsLaunchStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8237" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U64" I="0" O="false" N="MinNumberOfApps">.. <A T="MIN">.. <S T="1" F="NumberOfApps" />.. </A>.. </C>.. <C T="U64" I="1" O="false" N="MaxNumberOfApps">.. <A T="MAX">.. <S T="1" F="NumberOfApps" />.. </A>.. </C>.. <C T="U64" I="2" O="false" N="MinLaunchDuration">.. <A T="MIN">.. <S T="1" F="LaunchDuration" />.. </A>.. </C>.. <C T="F" I="3" O="false" N="AvgLaunchDuration">.. <A T="AVG">.. <S T="1" F="LaunchDuration" />.. </A>.. </C>.. <C T="U64" I="4" O="false" N="MaxLaunchDuration">.. <A T="MAX">.. <S T="1" F="LaunchDuration" />.. </A>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):519
                        Entropy (8bit):5.228097326555488
                        Encrypted:false
                        SSDEEP:
                        MD5:7BED5037C21AA2E45872B02295EBD87C
                        SHA1:BE37E31709301A1C91457B303FFE80C369C7B7FC
                        SHA-256:CC8D36F5286B0EDEF073D98712C7D12FC9F63FD60B1C2CE117D9ED95E2B2B4D9
                        SHA-512:0E413DBC4240842E25C1B1338D08AFC7F473824F6A8F58C50AA6FCB48C3452FE3E555348310AC6505E8260C6D360A8EEA2FBC5E21FE2D16F4728051449E74B9D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11453" V="0" DC="SM" EN="Office.Outlook.Desktop.WorkOfflineMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="WorkOfflineCalledCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):761
                        Entropy (8bit):5.134661361230586
                        Encrypted:false
                        SSDEEP:
                        MD5:931853C31755922B8E223A181190E3A4
                        SHA1:5E377017F4F441738FAD86E8B8010220BD805669
                        SHA-256:A5352985EE8D10BB067FA5D6EAA381316111A883EF83FFACBC8B7F0D89404CB2
                        SHA-512:65FB16511BDE299F34EE02D68F7FA8A2FD07F5F6F433B5146376B77D922E8E9C4F9DC799E39CCADBC079CC83C5F953DC61E9152FBE1380DE568D5FD2C8AAAF0E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11457" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.JoinPrivateUnifiedGroupDialogHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b5qox" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="JoinPrivateUnifiedGroupDialogCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):682
                        Entropy (8bit):5.179138337284848
                        Encrypted:false
                        SSDEEP:
                        MD5:1E84C28A3BB098013E5DB6DEF2B3F025
                        SHA1:0E0AAD17E1808A2055592D780AAA2410753AFBBF
                        SHA-256:4F5FA1261591349C58FCE701D83B6434F8C0A76634C52156BD5DB10EE82E0B6F
                        SHA-512:811823654D49600251E89B059EDBFAE8F4B518A035131770E02C8E693519E23C85D01B70E9D96F7A951A73840E36702FE0B87565092D3AB0386DEAE31AA8EBC3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11458" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.JoinPrivateUnifiedGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b5qoy" />.. </S>.. <C T="U32" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="EventID">.. <S T="1" F="EventID" />.. </C>.. <C T="I64" I="2" O="false" N="DialogState">.. <S T="1" F="DialogState" />.. </C>.. <C T="I64" I="3" O="false" N="MessageLength">.. <S T="1" F="MessageLength" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):871
                        Entropy (8bit):5.121696375634336
                        Encrypted:false
                        SSDEEP:
                        MD5:E3711247E4F469E17CBDE1CF1604604F
                        SHA1:597E2A4690610E10F3686632462631E249FC49BE
                        SHA-256:DB82A41FF27C2C9301AA6A834C66C4293FA88DCF03FC14F855FCB7FE17AE9C93
                        SHA-512:A649108245E512FEE09D1998B42E452A2B9C6FF4544CB094120FEF507DE250775ACF348B9B3C345F495E7F906F0CA3D591A808AD90580BD40AE6F511FA223A71
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11463" V="1" DC="SM" EN="Office.Outlook.Desktop.AddInDelayMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="AddinId" />.. </C>.. <C T="U32" I="1" O="false" N="EventId">.. <S T="1" F="Reason" />.. </C>.. <C T="U32" I="2" O="false" N="TotalHits">.. <S T="1" F="TotalHits" />.. </C>.. <C T="U32" I="3" O="false" N="TotalAboveThresholdHits">.. <S T="1" F="AboveThresholdCount" />.. </C>.. <C T="U64" I="4" O="false" N="MaxElapsedTime">.. <S T="1" F="MaxElapsedTime" />.. </C>.. <C T="B" I="5" O="false" N="Disabled">.. <S T="1" F="Disabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):473
                        Entropy (8bit):5.169007843122619
                        Encrypted:false
                        SSDEEP:
                        MD5:6D7684ED89F01B1F25F22CCCEB188D18
                        SHA1:B0A430410B55AAA957CAAF584DD9D6FA8349D92D
                        SHA-256:71AA44019046EBE311685A30A99C4B53E1473464B833B176D26ACFC2A8A540C3
                        SHA-512:DB07473F10C9BE776B312CED56E3073C7715661E0EAF54909AD57E00165C171508C48C928D101AE7B405F7D73E2768F47B502018E0F3DFE6A12CBCAEDBBA87E5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11464" V="1" DC="SM" EN="Office.Outlook.Desktop.LinkedInToggle" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b5k4o" />.. </S>.. <C T="U32" I="0" O="false" N="LinkedInToggleAPI">.. <S T="1" F="Function" />.. </C>.. <C T="B" I="1" O="false" N="Enabled">.. <S T="1" F="fEnabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3506
                        Entropy (8bit):4.54965819437617
                        Encrypted:false
                        SSDEEP:
                        MD5:44378F5BE7583DF63A53F613142D0186
                        SHA1:28E5C23991A07487FE7921769C3FDFB8AB2F90F3
                        SHA-256:8060812567CC44BEC9B53DA54113D05F655FABD8DB3070346A1DB5519253100F
                        SHA-512:70106BA3F7253D453AC95A3733592E7EFB881383092F396682D4A4BB84C076B74D331E6CBC30095F42EEE18C13B1B2B234003503C560C7AB1886666135BCF4ED
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11470" V="3" DC="SM" EN="Office.Outlook.Desktop.BootComponentPerfMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="218" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="219" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="700" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="728" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="5" E="729" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="6" E="730" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="7" E="412" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <US T="8">.. <S T="4" />.. <S T="5" />.. <S T="6" />.. </US>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="8" F="fPrompted" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="10">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2355
                        Entropy (8bit):4.4920808475405005
                        Encrypted:false
                        SSDEEP:
                        MD5:EAE393BBCE82E8DC4ED069A86727593A
                        SHA1:CDE07542460D13DF7C542B0EDF5CAD8663AFDE92
                        SHA-256:257827137A7EDF237906BF83D00DF166B9688062D3DA815319D0F9D69C85B8A9
                        SHA-512:38867C641275FDBFBBB37AC046EFA117CA09E2E67C2FC7449E0F058068CF0B040F340343AF98901F3937E0F0AA939A374B1358525FB890558CA0D0A444D11CFD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11478" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.UnifiedGroupsKPIMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18060" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="KPIAction" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="KPIAction" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="KPIAction" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="KPIAction" />.. </L
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2332
                        Entropy (8bit):4.684796260030017
                        Encrypted:false
                        SSDEEP:
                        MD5:3BBF012ABF0F54C6C3222126ED7999BB
                        SHA1:7ADA915F5C1D3C95B676EA905B0C6755E7A86CBD
                        SHA-256:77153EF7D7E5286D57E99390C10E3F6FD3CE1BDB441B34165D7A13B6FCECAFA4
                        SHA-512:4B098F1A1F9C84AFC593DFBC010859F4520DC34A365BC5A0F3052558122A0779398B6F63FD867A811F958B1B69E20A31630DAB6552FE8204FBE9E85D15990434
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11482" V="0" DC="SM" EN="Office.Outlook.Desktop.SimpleMAPIModeless_Stats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1900" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="1901" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="1905" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="1906" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="5" I="Daily" />.. <A T="6" E="TelemetryShutdown" />.. <F T="7">.. <O T="NE">.. <L>.. <V V="0" T="U32" />.. </L>.. <R>.. <S T="3" F="ErrorCode" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="LT">.. <L>.. <V V="28" T="U32" />.. </L>.. <R>.. <S T="7" F="ErrorCode" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="GE">.. <L>.. <S T="4"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1794
                        Entropy (8bit):4.897867154263292
                        Encrypted:false
                        SSDEEP:
                        MD5:AABEEB6BE84C54ED530631B07C2A0143
                        SHA1:FF7BC224E436214A7715C49A4622DCE349942AF6
                        SHA-256:9F34DD2F3255716DABDA2953AC1422179EA0365C39209B367B97E40EC31FDFB3
                        SHA-512:93DF361BDB1766BA3BA631AE9A2AF8FFC45CA97325CC5566EBE5D9422488A54FEDBF8ACD383EBBAC4EC137389664070D96DD126A0E30F7078055E24676026205
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11489" V="1" DC="SM" EN="Office.Outlook.Desktop.EnsureProfileProvidersListMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="842" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="833" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="834" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="835" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="843" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="4" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U64" I="0" O="false" N="TimeToBuildProv
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1145
                        Entropy (8bit):5.048128254432455
                        Encrypted:false
                        SSDEEP:
                        MD5:E72D8C7F752848F2A0375E36A41AE307
                        SHA1:2B4504DC9E079F2006A3EA8BE614E978471CD417
                        SHA-256:816C4C7AC20138DC4337904555CF36154578FD9EC97FE1504D1CC9F671EDC2AD
                        SHA-512:99F1F77EC33684AD0A4FB658FB7FC31722B0A7B9BC5A2EB015FEF4D9C283F5203101C2F5C59DE1EEBB329E4B5F5461D660549761983C70A9E8D8E6E7538F64E7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11493" V="4" DC="SM" EN="Office.Outlook.Desktop.Search.RequestContext" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="300" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7121" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="TraceId">.. <S T="1" F="traceId" />.. </C>.. <C T="G" I="1" O="true" N="ConversationId">.. <S T="1" F="conversationId" />.. </C>.. <C T="B" I="2" O="true" N="IsWordwheeling">.. <S T="1" F="isWordwheeling" />.. </C>.. <C T="U64" I="3" O="true" N="Offset">.. <S T="1" F="offset" />.. </C>.. <C T="U64" I="4" O="true" N="ResultCount">.. <S T="1" F="resultCount" />.. </C>.. <C T="U64" I="5" O="true" N="SearchType">.. <S T="1" F="searchType" />.. </C>.. <C T="W" I="6" O="true" N="ClientSearchReason">.. <S T="1" F="clientSearchReason" />.. </C>.. <C T="W" I="7" O="true" N="Localtime">.. <S T="1" F="localtime" />.. </C>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):900
                        Entropy (8bit):5.038575435063592
                        Encrypted:false
                        SSDEEP:
                        MD5:35CA484C42A9E664B5B4AE05E04EFE52
                        SHA1:CC9FFF159C264CADE1DD1434FE26C21A20E197F2
                        SHA-256:E18912220BC049B9948D309791E1C01FE73DB82107A98EA3EAFCE0F8651B7318
                        SHA-512:4C1D10E4E68042BE1B3E25C24848F5E6F8B4C58794534DF6760D2A85026078782A71B7C3CFED38E3E6F46967E4EA45F10796EF5D76F2896613F0ECF22F023080
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11496" V="1" DC="SM" EN="Office.Outlook.Desktop.Rest.ExecutionMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9108" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CallerId" />.. <F N="HttpStatus" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CallerId">.. <S T="1" F="CallerId" />.. </C>.. <C T="U32" I="1" O="false" N="HttpStatus">.. <S T="1" F="HttpStatus" />.. </C>.. <C T="I64" I="2" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="3" O="false" N="ExecutionsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):413
                        Entropy (8bit):5.3475921100141175
                        Encrypted:false
                        SSDEEP:
                        MD5:17A3609F404082A6029B68CFD8B74234
                        SHA1:080F0449F9F12778E381D7CCA5E35C4CC5D5A042
                        SHA-256:BEF5C21FA8BDD1A3D599376797F5A5435C6E4139641CE156FFF9C95453B610BA
                        SHA-512:0521E03E89189423F3019DC500455395F300B3B7E0CD57833A02F2D8BEAD9B5C96EE04189629B3035FE7914894B38C9824B64EFB739C73FA90EA745DC3DEC632
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11498" V="0" DC="SM" EN="Office.Outlook.Desktop.LinkedInSettingsHTTPRequestError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b5vgr" />.. </S>.. <C T="U32" I="0" O="false" N="HttpRequestFailure">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1452
                        Entropy (8bit):4.357045061379154
                        Encrypted:false
                        SSDEEP:
                        MD5:89BC403254C78D9DE16F871CC90D62B1
                        SHA1:60345156473DC978ECB07A6C690C0D31FF1BDFC6
                        SHA-256:BF73007C777271C877AE39A21A7D98FB1EF752D59AB0B157B06B3627481E53B0
                        SHA-512:B3C832F7B1B014006F9C09FACD894B614254D146B7134D96349AD60D7613A649F05FC7369FB260C51F82182384C6FF62E9B6115A698260E88E91CF4163C3706C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11499" V="0" DC="SM" EN="Office.Outlook.Desktop.LinkedInSettingsGetEnabledGraphResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="b5vg1" />.. <F T="4">.. <O T="AND">.. <L>.. <S T="3" F="Tenant enabled" />.. </L>.. <R>.. <S T="3" F="User enabled" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="Tenant enabled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <S T="3" F="Tenant enabled" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="User enabled" />.. </L>.. <R>.. <V V="false" T="B" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):552
                        Entropy (8bit):5.158050495180622
                        Encrypted:false
                        SSDEEP:
                        MD5:B0B0428D2DAC2ACC68088D0FA6968995
                        SHA1:42CEE8EAEAC216FEE697FA2146BB5786AC20D813
                        SHA-256:6C4CE6976D89FBBC99EB4118900AF1D92F1659CE9536CA4316DED6CD09949623
                        SHA-512:4C243EEA3EBD6942A8267DA8430C1F7C8A1540D6DE189A70FEF837C1FEA33B5BC7E910A058C5DE40681FCAC9C7A2F402542D173782AF08BF18F69BC37FE276F0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11500" V="0" DC="SM" EN="Office.Outlook.Desktop.LinkedInSettingsGetEnabledFailed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="b5vg2" />.. </S>.. <C T="U32" I="0" O="false" N="LinkedInSettingsGetEnabledFailureCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):566
                        Entropy (8bit):5.205158322236328
                        Encrypted:false
                        SSDEEP:
                        MD5:874237D47414C078423F9330B6E13593
                        SHA1:22683A564BD4B8A606163AEB5196D3A7CD2E012C
                        SHA-256:9758C2C80547DCAEA55BD422ED6204146B24E2F4B6A4A92C0463DF1A3D92B81E
                        SHA-512:AB3D904462FB2BE267C5E71C8B9591EE65DA6F9FBB72E22BE5B8F400FB5D99623838D9CAFCFA1C820689BC23CD5957241D5E75C48E6BD8A189006ACC706F55C9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11501" V="1" DC="SM" EN="Office.Outlook.Desktop.FMatchesProptypeMismatch" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="208" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CompareMismatchCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):990
                        Entropy (8bit):5.167435603528131
                        Encrypted:false
                        SSDEEP:
                        MD5:69627ED112C3E07DA126859950E875F5
                        SHA1:E00A20A8BF5C9FE7093575E7359E8233C876FCD9
                        SHA-256:312D7F3791122E568A150E3ABAF6C66D2EBC45E3F27E53F8E55E496E43F48E25
                        SHA-512:21A6F01C2C64CEC9776C133597682E482C0C424AF6992FFBA367FDB4217082566D068EF9047D320B4A1345A7FAC60D2CBFAF5AA1E8945E5FEAE833B020535AB6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11502" V="0" DC="SM" EN="Office.Outlook.Desktop.LinkedInBinding.DetailsOfUnexpectedIdpAuthInBindServiceToProfile" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bzt52" />.. </S>.. <C T="W" I="0" O="false" N="IdentityErrorState">.. <S T="1" F="IdentityMetadata_IdentityErrorState" />.. </C>.. <C T="W" I="1" O="false" N="IdentityProviderType">.. <S T="1" F="IdentityMetadata_IdentityProviderType" />.. </C>.. <C T="B" I="2" O="false" N="IsPersisted">.. <S T="1" F="IdentityMetadata_IsPersisted" />.. </C>.. <C T="B" I="3" O="false" N="IsSignedOut">.. <S T="1" F="IdentityMetadata_IsSignedOut" />.. </C>.. <C T="W" I="4" O="false" N="LibraryType">.. <S T="1" F="IdentityMetadata_LibraryType" />.. </C>.. <C T="W" I="5" O="false" N="ServicePrefix">.. <S T="1" F="ServicePrefix" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1101
                        Entropy (8bit):5.017793697630464
                        Encrypted:false
                        SSDEEP:
                        MD5:8B6CC2C79AB285EA2365945B6EA148CC
                        SHA1:3B5899C298529045F8D7FEBDC616FD5A6F5C1BFA
                        SHA-256:909D0919C458765004D922B096EE543DDD3BDD9DC9A232475A144C3BD0D248B5
                        SHA-512:486A750A5DBDA5DDE053CE6CA496843D83C6F9DD6CBD14D5E40517AA11EEFBE4DC1F7AA01B7272132140152F330758E6D3618571633E4909F45F3530A92EE43A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11504" V="0" DC="SM" EN="Office.Outlook.Desktop.LinkedInBinding.PreSignIn.CountFailuresPreparingBinding" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="bzt52" />.. <UTS T="4" Id="b0h36" />.. <UTS T="5" Id="b0h4c" />.. <UTS T="6" Id="b0h4e" />.. </S>.. <C T="U32" I="0" O="false" N="CountUnexpectedIdpAuthInBindServiceToProfile">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountNullIdentityInAddBindingService">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountNullIdentityInDisplayBindingSignInDialog">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="CountUnexpectedExceptionInDisplayBindingSignInDialog">.. <C>.. <S T="6" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):517
                        Entropy (8bit):5.280137573009674
                        Encrypted:false
                        SSDEEP:
                        MD5:67089E4F0B34315C188F92A80E7BC136
                        SHA1:B24C318AA6A0BD2296E74C2921951FD4D9EC741C
                        SHA-256:7732F5C1EECAD64C09C2A894D5F4CAE19ABE02D7693B236957E0281E5D3E30D5
                        SHA-512:354885FE53A3F3110EE6E20495491DAE59AFDAF573AA513AB8FD8E8C32E456EE1398C10EDDA82D30D6014218C8ED94A041E3A73364DE42D6DD93D15D6423AA69
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11512" V="0" DC="SM" EN="Office.Outlook.Desktop.OABDownloadConfiguration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="26147" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="B" I="0" O="false" N="Configuration">.. <S T="1" F="Configuration" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6785
                        Entropy (8bit):4.393023802643219
                        Encrypted:false
                        SSDEEP:
                        MD5:A0F309AEAC31747BDAA138E09976C01E
                        SHA1:93DB840FFCB337B866FAAF50661D1B669194684F
                        SHA-256:FEDF8BCA4585163F904C6B3DAB5AF4C2252190E98C8356244C539B8FA193CDED
                        SHA-512:8A09BF31A72B12F4356E74B0871AA3E2CAF6CEC5437F968BB7CA88445A44DE1EBF3152BBB28B20A44CF65206FC20951B3BC69C17DE3F55FC35960A7E6E19F4FD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11514" V="1" DC="SM" EN="Office.Outlook.Desktop.PCXContactCard2LinkedInUsageAndHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="b5ze7" />.. <UTS T="5" Id="b5ze8" />.. <UTS T="6" Id="b5zez" />.. <UTS T="7" Id="b5ze0" />.. <UTS T="8" Id="b5ze1" />.. <UTS T="9" Id="b5ze2" />.. <UTS T="10" Id="b3g8x" />.. <UTS T="11" Id="bsexb" />.. <F T="12">.. <O T="EQ">.. <L>.. <S T="4" F="AssociationFooterState" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="13">.. <O T="EQ">.. <L>.. <S T="4" F="AssociationFooterState" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="14">.. <O T="EQ">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):707
                        Entropy (8bit):5.154306434324015
                        Encrypted:false
                        SSDEEP:
                        MD5:81EA3F7C7A1662C9E48F0DC8740E9761
                        SHA1:29603EDB1D3D8F214CD0F57C67B5F553F9A10842
                        SHA-256:77C7CCD697DB17F0AE62DBF0238780380D2B67C10D41EA4BB4F8B0A86B987745
                        SHA-512:2C1E6428FEC22096C11EB312E830D758C113DA695AF646EE01F78C5AC7069CFA7131E8BC758A4D80F490AAF888D76B2D1C5F73B8CF9B36DAB15D85CD6E01D8FC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11515" V="0" DC="SM" EN="Office.Outlook.Desktop.OperationDisabledInGroupError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="OperationType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DisabledInGroupErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="OperationType">.. <S T="1" F="OperationType" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):770
                        Entropy (8bit):5.225439772923113
                        Encrypted:false
                        SSDEEP:
                        MD5:EA8142169C92414B9CAAB103DB636C77
                        SHA1:86BEF0210D4C8642CF3C6B9F943E5260DA6C13C8
                        SHA-256:DD026E45D68F807FE78A3421F30E36DEA1ECC3F38D02B221C8BFDE51063119A6
                        SHA-512:7C510EACD20504F74CE0FC9A46378A5CBD7E01412BE4124A8DED5A65540280FD1FA38D2BC2A025E1AAD70A3BDCB6D6C82FB635A7CA5878A9273E5CE0EFC94117
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11517" V="0" DC="SM" EN="Office.Outlook.Desktop.ExtendedProfileDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="900" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ulFeaturePosition" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ExtendedProfileDialogFunctionalityUsed_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ExtendedProfileDialogFunctionalityUsed_FeaturePosition">.. <S T="1" F="ulFeaturePosition" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):741
                        Entropy (8bit):5.181574392553091
                        Encrypted:false
                        SSDEEP:
                        MD5:3B06E5C3C0B3CCBBA2927F96873853B4
                        SHA1:D60F56E02DC235ECAD6B29889585A37730D831A3
                        SHA-256:6E8088659AEBD78E5F530850C75F2A8ECA43307D49EE9979661BCF8BD1251CEE
                        SHA-512:5E0BBDDD19ECCC943A61B5F9C464CDF88B34F0D3B15366DAC39C3B8B04760A4F4695DCCA701013BA5F2FCD7AB570146ABB79052D747E1A4BF9D75C42B2D22AD0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11518" V="0" DC="SM" EN="Office.Outlook.Desktop.ExtendedProfileDialogErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="901" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ulErrorPosition" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ExtendedProfileDialogError_Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ExtendedProfileDialogError_ErrorPosition">.. <S T="1" F="ulErrorPosition" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1244
                        Entropy (8bit):5.1495894302568495
                        Encrypted:false
                        SSDEEP:
                        MD5:4DE38B088B10D060F6EF9194F9C3F6E1
                        SHA1:C578D36CBF9F48EAD4243F15CC6DB0B59770F47C
                        SHA-256:6C05C706D8241715B3F3800488D8C120BC931FB26BD77BAF221EF5A779CD9A79
                        SHA-512:344A74CA16AF3B8053AD8D4EB7BFB4AD019275173CAF7B45A5E5E8E230F88D70EAEAEE073F1E77885320DFE0BCC97719F41797ECE779993CDBDB89495694BBA7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11520" V="0" DC="SM" EN="Office.Outlook.Desktop.AddInUnhealthyNotificationMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="DisabledNotificationTotal">.. <S T="1" F="DisabledNotificationTotal" />.. </C>.. <C T="U32" I="1" O="false" N="UnhealthyNotificationTotal">.. <S T="1" F="UnhealthyNotificationTotal" />.. </C>.. <C T="U32" I="2" O="false" N="ViewMoreDetailsTotal">.. <S T="1" F="ViewMoreDetailsTotal" />.. </C>.. <C T="U32" I="3" O="false" N="DurationTypeAlwaysTotal">.. <S T="1" F="DurationTypeAlwaysTotal" />.. </C>.. <C T="U32" I="4" O="false" N="DurationTypeSevenDaysTotal">.. <S T="1" F="DurationTypeSevenDaysTotal" />.. </C>.. <C T="U32" I="5" O="false" N="DurationTypeThirtyDaysTotal">.. <S T="1" F="DurationTypeThirtyDaysTot
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3654
                        Entropy (8bit):4.357898593202282
                        Encrypted:false
                        SSDEEP:
                        MD5:BE50105D1A24A843F97E6FC9FEBF5208
                        SHA1:26D22726A9618C40A6E25C693036E9009D825091
                        SHA-256:AB870C978BB4BE54893F469A6FA63917C22D9B41E3E863D764A9449FC624F129
                        SHA-512:0002C67F72BC3CDB62765FA14AF88C8CFB30898828728F9B64B0AD4EF4E4349C0C81D7F1EE2187A0A643311935E42E66A28CB3FB7DEC84B678491B669E413B46
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11521" V="3" DC="SM" EN="Office.Outlook.Desktop.Mail.MailToastNotificationUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23400" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="23401" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsOverflowToast" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsWin10Notification" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="NotificationAction" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1101
                        Entropy (8bit):3.6451193143483254
                        Encrypted:false
                        SSDEEP:
                        MD5:5CDF6A4A403B8A26CA99771EF6423C94
                        SHA1:F4478A719BE5B58AFB9759E6D3DE1D8BE8878781
                        SHA-256:F1D5CC26EA982FE779F37BABD069E5600607D490F966BABEA79C8FE676BF277C
                        SHA-512:B46D89E1D36659A4CFF4BCC0058B3CBB5E924CC34C4E4A8C067B93FF748B74562A3FA1DC9085CA56A8E73A4744A7A58EB1A111787EAF95F78207BEEB300DA5F7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11523" V="0" DC="EUII SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11417" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="1" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false">.. <S T="2" F="0" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="2" />.. </L>.. <R>.. <S T="2" F="1" />.. </R>.. </O>.. </U>.. </C>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):692
                        Entropy (8bit):5.180768599278269
                        Encrypted:false
                        SSDEEP:
                        MD5:C9C731EB8075006CC1E0F336D57C4CBE
                        SHA1:66E52C2E6F872964A25F2ABED2B31C1BFE2E01B0
                        SHA-256:EF18D28B24FE27130B3D12FA6CDBEBDB6ED55E1869ADB4509B7752BC186E7558
                        SHA-512:7F7F6563C24AD93ACF2BF03DBC738A0F291BF75B75257ADCBE34E933AAEE02EF9CDF5D0011EABBED6C7820DC862FE4B0066E93BB68542F87C45880F5E769108A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11524" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.BrowseGroupsDlgSubStrSearchMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18045" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I64" I="0" O="false" N="HrResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfHrResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4901
                        Entropy (8bit):4.407727848406328
                        Encrypted:false
                        SSDEEP:
                        MD5:48B10FCA1DF7BE29A8E2B66853D127B1
                        SHA1:C91AB377CF8A416DE9C7204F72339D00563C2664
                        SHA-256:9706DAFA3A89618608ADE8553F29B1BE657717A0B387E90DBA7F6B3E0990A934
                        SHA-512:D23EAD131AABCD9DEB12863EFBC33409500F7770D0C373E7AE411995B7B6AF5B5D094DE9F8DDA5DAA18836C78EAE4679869AB4EE3E879D9CCEA94D8EDBACF667
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11527" V="2" DC="SM" EN="Office.Outlook.Desktop.ServerSearchSessionDiagnoseData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7045" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7089" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7095" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="4" E="7112" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="5" E="7126" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="5" F="HttpStatus" />.. </L>.. <R>.. <V V="200" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="5" F="HttpStatus" />.. </L>.. <R>.. <V
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):5.101531601368304
                        Encrypted:false
                        SSDEEP:
                        MD5:267CE6B61A9D71513E90CCB342121F22
                        SHA1:18BFD21CC373093B9EA683E7CA73130664862055
                        SHA-256:4A8F8D89DF6D52DADDA2FE4FCDF10DD05A4EDE4EE8B486CB6B3DA14B43208238
                        SHA-512:757CA6B2873C7BE9C1D92909990692A20E6A5F59BABEB8FE20B6704BA0D148455355E109C1897FADB491A7D46DEAC72D7618DCCF20BFBD22DCF30551DEA21550
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11528" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.WellShown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6118" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6119" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="EnhancedWellCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="LegacyWellCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):609
                        Entropy (8bit):5.269736541765203
                        Encrypted:false
                        SSDEEP:
                        MD5:C3F590BB9E15B784916B36B318DFFCF2
                        SHA1:B4B40CEE51B23E8B7EB8D1F3AB0124B7362655A6
                        SHA-256:E6AAF5056A7E30B890FF57EF0749A935FCABC5483CCCB4BCCDB63EF822946B76
                        SHA-512:09716345BE8507D60247AF15083889249BE7B5C25C7FA151897C088F2B9D0E3DBE15E1735840141C5EDA09234973373955984B4D83F37960EEFEECF37A17911D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11529" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.DigestEmailNavToGroupConversationClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18059" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountDigestEmailNavToGroupConversation">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1981
                        Entropy (8bit):4.427959934228141
                        Encrypted:false
                        SSDEEP:
                        MD5:19AC4ADCE59AE3CBFBE35B34A056E994
                        SHA1:3273A5751560854649755EA25AD4191FB7BEF808
                        SHA-256:583B6A22840F29FF08DDC691E2C1BA3B5F9A7282475D66C72BF7CD37A5CAF96B
                        SHA-512:C32C5C07876C9A5BA8BF3958CD7574DE48248C7793F1A36BBEF9829C38963C94EBD534757EBAAC5CDE4A3144CBF91BF1DCE3D536AFF92B71ECF5EC04E8961648
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11530" V="1" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.PickedFromPicker" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6120" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="LocationType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="LocationType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="LocationType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="IsZeroInput" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):990
                        Entropy (8bit):4.873738478043802
                        Encrypted:false
                        SSDEEP:
                        MD5:C3BEC92F99ABB3360CC8D6234094603B
                        SHA1:E360A9031C6C321EE621BEFDD9E48C8FA11591EE
                        SHA-256:53E0796E52CFFE19F04A5BB0AEEEB8FB50572AE1596DDF0A3BDF943B248AF09E
                        SHA-512:9392048DEE2F2678AA6B8586C0D3287CBC075126F947E6D8DAB00E4E25C58EDD6CCCDDDFC959A177A09C58008C9AD2BF94B08FD6094B446C47B3C0572EC7FAB3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11531" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.AddedWithoutPicker" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6121" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6122" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="RoomFinderCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="TypedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalLegacyAddCount">.. <O T="ADD">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <C>.. <S T="2" />.. </C>.. </R>.. </O>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="2" />.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1637
                        Entropy (8bit):4.539377584344812
                        Encrypted:false
                        SSDEEP:
                        MD5:5D48C4ED7C066AAF069C130955BC6082
                        SHA1:A4BB3D4CBB773003885768238C2CE78E6F69FED4
                        SHA-256:E92A67DC509B356D9346CD0110CD040BDB6A2A2FD9D873CC94F2F58D8FDA40C8
                        SHA-512:6597E9AE0E173FA60B130B366C66591163F173CA925953DC486346EF70530C607D96E04BE414856D9B406B2CB899008AA27EA0100C69B4D992EEAE430BB3C178
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11544" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.ReminderJoinOnlineMeetingCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="808" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="JoinSkype" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="JoinTeams" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):544
                        Entropy (8bit):5.139115725994136
                        Encrypted:false
                        SSDEEP:
                        MD5:D3D62BD6226676857F3CA3FAC5D2A85A
                        SHA1:25EC53923FEF9EF4147F98B60686C6BEC3B90A94
                        SHA-256:1CDD3DC091F5BDF31235CA8F10EB5C7BFBDF7B64C645F67BE91437F8DD40C95B
                        SHA-512:F25466821C477AAB65703BAF507DB0CFF9AC9A031220850B1FC032B91B7118EC88EEAC2215A3C0E9F9A22FBE43CCA83B65AF6B668C9C3B9858DA837D2EE737B8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11549" V="0" DC="SM" EN="Office.Outlook.Desktop.OABSizeOnDiskIsZero" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="B" I="0" O="false" N="OABSizeOnDiskIsZero">.. <O T="EQ">.. <L>.. <S T="1" F="OAB Size" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1010
                        Entropy (8bit):5.147676549651255
                        Encrypted:false
                        SSDEEP:
                        MD5:90B1B4A8DF00103362FC232C008994BF
                        SHA1:C33D86F59A2B2F27D9AE2C72FEC66F639F1E3EDB
                        SHA-256:03464E65A4FA284A7D8FC691F87BA453E151C68DB24BF92DAB4C7E82804E414C
                        SHA-512:583160B76031AAA13AD2EE0701DA65951A5B79C083DAA722FA30BA92FEFA63813D78F7D6E6605968194E0EE8C6C7B7D520FDD2A0E0D6DBA162C97B4CA5D89F54
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11550" V="1" DC="SM" EN="Office.Outlook.Desktop.ServerSearchRequestHttpRecord" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7126" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="G" I="0" O="false" N="SearchSessionId">.. <S T="1" F="SearchSessionID" />.. </C>.. <C T="W" I="1" O="true" N="RequestTypeString">.. <S T="1" F="RequestTypeString" />.. </C>.. <C T="G" I="2" O="false" N="ClientQueryID">.. <S T="1" F="ClientQueryID" />.. </C>.. <C T="U32" I="3" O="false" N="HttpStatus">.. <S T="1" F="HttpStatus" />.. </C>.. <C T="U64" I="4" O="false" N="NetworkLatency">.. <S T="1" F="NetworkLatency" />.. </C>.. <C T="W" I="5" O="true" N="ServerErrorCode">.. <S T="1" F="ServerErrorCode" />.. </C>.. <C T="W" I="6" O="true" N="ServerTraceId">.. <S T="1" F="ServerTraceId" />.. </C>.. <T>.. <S T="1" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):844
                        Entropy (8bit):4.89785586626707
                        Encrypted:false
                        SSDEEP:
                        MD5:54C7EA54AE2082FFCCFDB64391C3FF3B
                        SHA1:33358F9D5F21F894B22907C5D8EE0ADFB86FB008
                        SHA-256:17564B6F953152A7341C182A1A70F6386869EB3BF5FB9395AED9D431ECFD471E
                        SHA-512:AB622137CE35D599B397FA8E23FE64F9EA7B127B7AEC252039C1D45385F9F72971E1A4084A6B8FB530A0CA008836CB4BDD904F14D88B66A24BC6A639A5ED93FD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11551" V="1" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.PickerShown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6123" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsZeroInput" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="PickerShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ZeroInputCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):823
                        Entropy (8bit):5.060923510260963
                        Encrypted:false
                        SSDEEP:
                        MD5:667FCB02805CBB3F7C41827253DAD1B4
                        SHA1:F59292DBC746EFBD5D75F296C7B7BDD0EB17484E
                        SHA-256:F5E0CFD89B67E4A5FAEAB21685369B8860218E54A06078535515C4D28866BCDD
                        SHA-512:511E7C8AAC4D1FDAAB94C1D6F3CF03DB5459EDCC56C48C7B376457292ED08F1489BAFFC1C2B23862C23F961A3E6C7F054999C192CAED509B772838C2D1317F7A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11553" V="3" DC="SM" EN="Office.Outlook.Desktop.Search.SearchActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9056" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="EventType">.. <S T="1" F="EventType" />.. </C>.. <C T="W" I="1" O="true" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="W" I="2" O="true" N="Id">.. <S T="1" F="Id" />.. </C>.. <C T="W" I="3" O="true" N="EntityId">.. <S T="1" F="EntityId" />.. </C>.. <C T="W" I="4" O="true" N="Localtime">.. <S T="1" F="Localtime" />.. </C>.. <C T="W" I="5" O="true" N="VerbMetadata">.. <S T="1" F="VerbMetadata" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):855
                        Entropy (8bit):5.089141800724169
                        Encrypted:false
                        SSDEEP:
                        MD5:8727820C135175D732D1395EC4468751
                        SHA1:714C35DE98C35D5CB80DCD7DF1FAE727148B2540
                        SHA-256:7552C0C5184C74C255F560E2069EBC5DCA6BF20D05000C6D951132A6E28218B8
                        SHA-512:1FDDF117B5A05332BB9CA891B66CBDD791F3991C65974E0B462FD65D305603B098870C3B1130BC51ACC4827188F3CA3620D77FC2B3910BC3B51A2E0B88D1D238
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11554" V="3" DC="SM" EN="Office.Outlook.Desktop.Search.ResponseReceived" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7123" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="U64" I="1" O="false" N="Latency">.. <S T="1" F="Latency" />.. </C>.. <C T="U32" I="2" O="false" N="Status">.. <S T="1" F="Status" />.. </C>.. <C T="U32" I="3" O="false" N="Rendered">.. <S T="1" F="Rendered" />.. </C>.. <C T="U64" I="4" O="false" N="RenderingLatency">.. <S T="1" F="RenderingLatency" />.. </C>.. <C T="I64" I="5" O="false" N="PageNumber">.. <S T="1" F="PageNumber" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):538
                        Entropy (8bit):5.12398915550093
                        Encrypted:false
                        SSDEEP:
                        MD5:9E6ABACD78111D533ADDDEEC14C51AF2
                        SHA1:0117774835F77541FE1427A314CC30D68DD0F62D
                        SHA-256:7EFC1735D5920EF0A8C8387551327A33413473F694801A93E45BDDDFB8DA9A7B
                        SHA-512:5069E110D2E44B78D39177094BFC32139345C4F1705DE6699F294636D0A6931C6288B8CA9C07E3B614148B1C17FA7C51524BF88C12FB33213FD75A35418FE6B4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11555" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.SearchCreateFailed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11565" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="SearchCreateFailedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):449
                        Entropy (8bit):4.742322563724399
                        Encrypted:false
                        SSDEEP:
                        MD5:A20476D05320EE69C20DDE8A58B33BFD
                        SHA1:4F4D81EEEF07C2B72AC31EE99362DF608D95D8EA
                        SHA-256:3FEBF9DC38A5184CD501A88C661D9BADCA720E72BFE6A0A3AF5D205913EA4B9F
                        SHA-512:6361BE2B38D55AE246FE153A36045231D1E9E5B93B6767F54DA2EB9721F13C3143C9E6BA0A5213E5F314A36D4A4B6031099EE652EAFC898D2E0FD49A734DCEF1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11559" V="0" DC="SM" T="Subrule" ER="11443" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="445" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):449
                        Entropy (8bit):4.7314621832431
                        Encrypted:false
                        SSDEEP:
                        MD5:DD8CEBB0841DBA0F7416A4C67AC34DCA
                        SHA1:54991A03E74AA677B2F2F7232479AB54ED4269CA
                        SHA-256:9FDE5F5829E3398AA756440339398B7E19F4191A1A21D2AACA13DA9B66D9D69F
                        SHA-512:A97D401D3CAA432CD16F3D8D5DB1988E9CAA37B15FCBE253190A09885A97D601096DFD33E29B3D76BF04C7381DFDB61226000A441985419922255D4E745EEED7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11560" V="0" DC="SM" T="Subrule" DR="11443" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="446" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1234
                        Entropy (8bit):4.64087353961245
                        Encrypted:false
                        SSDEEP:
                        MD5:5661CF27FA9618861F804A4CB39AD4F6
                        SHA1:065B57AC0F7BCE8F51845C4DB7F47008DA756227
                        SHA-256:E5E515C3C19C5130267C28F907904DB6D4715F2D059045193C97E496BE104D05
                        SHA-512:0981729F4ACDA38807FD497884E93193B5F6A5239869F4FFD93D86512DE2BA2F9F2C464E7A63D0F67F9E08B8F5B53A390018BDFC468C8255606CF15A45FD2983
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11561" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtAPIMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8240" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="APICalled" />.. </S>.. <S T="4">.. <F N="APICalled" />.. </S>.. <S T="5">.. <F N="APICalled" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="APICalled">.. <S T="1" F="APICalled" />.. </C>.. <C T="U3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):960
                        Entropy (8bit):5.038938683038551
                        Encrypted:false
                        SSDEEP:
                        MD5:44CD4F3636AC668C6DE0BE6DD9E25D65
                        SHA1:85C08F8703408AE8BFEB3D25DB95AF2BA4DDFC3B
                        SHA-256:36593804AB8EB727ABA631308F69A9C37ABE629DCFD26E6DF7AD666AEF35C9D1
                        SHA-512:08B1A484E667548E91F8E0BA127F451DAFC10CB79C184ECAFB9B5FDAACD34C4C76C42DC1881F1E61839B23C93642791353667D3885321CCD05B25212E525161A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11562" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemV2.Authentication" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="37" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TypeOfAuth" />.. <F N="HttpResult" />.. <F N="FeatureScenario" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Authenticator">.. <S T="1" F="TypeOfAuth" />.. </C>.. <C T="U64" I="1" O="false" N="HttpStatus">.. <S T="1" F="HttpResult" />.. </C>.. <C T="U32" I="2" O="false" N="FeatureScenario">.. <S T="1" F="FeatureScenario" />.. </C>.. <C T="U32" I="3" O="false" N="Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):823
                        Entropy (8bit):5.015460474952734
                        Encrypted:false
                        SSDEEP:
                        MD5:A1A19578FD123DB4527766F6A0C26481
                        SHA1:6A29DA1666244F86BE4D52FE9D025D314A6ADFCF
                        SHA-256:5645B1CEC9F5A1EB799A176C171EA6588006CBD2D8F3B0059312220BA84BC750
                        SHA-512:66724C898BB63CC40CE479E90A6A54493EE142D8D2B8029623D11BD42686B0A133D9FD16D17EA8DAF4922B9FA2D9DCED38F05127768317588ED5083D1A45567C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11564" V="0" DC="SM" EN="Office.Outlook.Desktop.HangBucketMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="999" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="304" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="ElapsedHanging" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U64" I="0" O="false" N="BucketId">.. <S T="1" F="BucketId" />.. </C>.. <C T="U64" I="1" O="false" N="ElapsedTotal">.. <S T="1" F="ElapsedTotal" />.. </C>.. <C T="U64" I="2" O="false" N="ElapsedHanging">.. <S T="1" F="ElapsedHanging" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):468
                        Entropy (8bit):4.544906538001387
                        Encrypted:false
                        SSDEEP:
                        MD5:7095AAD71457B3E16BC77BA3074E5084
                        SHA1:41359535073F254E2365343C6571F4C876153D4C
                        SHA-256:FBBC47A93C3A7251FC92DA47890BB657ACB5802252254812D4B42E892A208317
                        SHA-512:F7D158B5D5AD886E5B00FAFF483654AE46A8C59B635329FD6B64A34F22058B058872EF107E742AFA09F7140D96561D9149C287F53B1684758280C543D581037D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11565" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6124" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):895
                        Entropy (8bit):5.149399834102735
                        Encrypted:false
                        SSDEEP:
                        MD5:B2D459D267469A347692F9E27FCBA576
                        SHA1:8115390DDB7A38AA47337FAEDDC0D5D851CFEC17
                        SHA-256:12A92F71D127A716D84E4EEB457DE2A9C9EDE237C36866CABE8F1ACA97AEB71D
                        SHA-512:3C23AE9E1EEA821A7A018C488728CBF0A594CA5061D89CC8751CB8CD59B61FED751E035320A0216013E7AB31861EDBB414EF86E408226CDCDA5D71FDD759378C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11566" V="1" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtAPILoggerErrorDetails" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8241" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="AppId">.. <S T="1" F="AppId" />.. </C>.. <C T="U32" I="1" O="false" N="APICalled">.. <S T="1" F="APICalled" />.. </C>.. <C T="W" I="2" O="true" N="ExtraParameterInfo">.. <S T="1" F="ParameterInfo" />.. </C>.. <C T="U32" I="3" O="false" N="APIError">.. <S T="1" F="APIError" />.. </C>.. <C T="W" I="4" O="true" N="AdditionalErrorInfo">.. <S T="1" F="AdditionalErrorInfo" />.. </C>.. <C T="U64" I="5" O="false" N="TimeTaken">.. <S T="1" F="TotalTimeTaken" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):966
                        Entropy (8bit):5.05495997658092
                        Encrypted:false
                        SSDEEP:
                        MD5:89B13E3D500D725790D2750ED41AD461
                        SHA1:A5B014E42960D1C5C8A18CA2388EF2B9AC808DBF
                        SHA-256:71486383B8CF866D2ACFA842B922341355066B4AEA9260947D3FD3DAD510AFEC
                        SHA-512:A3508F54D6A989CB2EBE8E044A2B6D53FB99081E4F805B31ECB35EAE1F4163C70792A5F73C525D29B407EB75268BA1E21AEC312F2A6BA7B66B8D6C7D2D0611E1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11571" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.SearchResultsType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6125" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CustomLocationTotal">.. <A T="SUM">.. <S T="1" F="CustomLocationCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="ConferenceRoomTotal">.. <A T="SUM">.. <S T="1" F="ConferenceRoomCount" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="PublicLocationTotal">.. <A T="SUM">.. <S T="1" F="PublicLocationCount" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="CallCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):989
                        Entropy (8bit):4.626693671555136
                        Encrypted:false
                        SSDEEP:
                        MD5:1D24B501C7B89A161A37188026D22273
                        SHA1:ABD857C4AEC8F2AE271A21F1246CD5519E9A81F6
                        SHA-256:2AE8562365CA1517660C856AE1FBD3D836D912B8ED315A0F9B14D7EF6F2C3DE6
                        SHA-512:8C4A3BF2FE447845F11B765C99C78AFDAA6CE06E4F96A3B805853154CD9044B87FDA114CFD48AB1FAA328FE6FE8ED4E928F89B1AAA1D9C7FD7052EE42B6FE664
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11572" V="0" DC="SM" EN="Office.Outlook.Desktop.ContactCardOOFUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="caxsv" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_OOFShownCollapsed">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_OOFShownNotCollapsed">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1850
                        Entropy (8bit):4.903440317966439
                        Encrypted:false
                        SSDEEP:
                        MD5:7EE3CC1770A222B1894F27AB4EE9EB9E
                        SHA1:141B140B73E148E46FA572A52BEECDC5A3986326
                        SHA-256:4C9E25225929CB6334ED715AFA069AD46F584135B66DCE08C275656D4A86FC2F
                        SHA-512:40781187C43AFAF219DBFD8FA2BC77D8C7EF588C2894C9DF45F96BA094FB2E9D3DB52B9845CF42DF83C14B6D307AE7599136CD4D939A1BFC2CB6B5B251B8C24C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11575" V="0" DC="SM" EN="Office.Outlook.Desktop.Performance.NCRForegroundCall" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="558" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FOnline" />.. <F N="FCached" />.. <F N="FActiveDirectory" />.. <F N="FHybridOnline" />.. <F N="FAutodiscover" />.. <F N="FDelegate" />.. <F N="FCachedDelegate" />.. <F N="FOnlineArchive" />.. <F N="FTeamMailbox" />.. <F N="FPublicFolder" />.. <F N="FEWS" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FOnline">.. <S T="1" F="FOnline" />.. </C>.. <C T="B" I="1" O="false" N="FCached">.. <S T="1" F="FCached" />.. </C>.. <C T="B" I="2" O="false" N="FActiveDirectory">.. <S T="1" F="FActiveDirectory" />.. </C>.. <C T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):997
                        Entropy (8bit):4.8929294943027175
                        Encrypted:false
                        SSDEEP:
                        MD5:46164FED2229F7FEB8DE8819C5DE7D39
                        SHA1:8065AA2D6422C0FF6723C235E5B8367A76A0643E
                        SHA-256:7043B5A5505BB8CFA5A56F8E6CA0326AC72F3AB03C83D15900DC6EFE061F0BAD
                        SHA-512:82A4FAA5905FF80BEC9ACEF051DDE3F709970E71E69CCAE4B9EFB16BE95809658F54E00E5A1D45FE2DD2E187D494705A6429609802675C086937B276987545A2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11576" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="304" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="306" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="316" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false">.. <S T="2" F="BucketId" />.. </C>.. <C T="W" I="1" O="false">.. <S T="2" F="ScopeId" />.. </C>.. <C T="U64" I="2" O="false">.. <S T="2" F="ElapsedHanging" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="2" F="ElapsedTotal" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="3" F="SkippedFrames" />.. </C>.. <C T="U32" I="5" O="false">.. <S T="3" F="Frames" />.. </C>.. <C T="W" I="6" O="false">.. <S T="3" F="SkippedModuleAndOffsetCollection" />.. </C>.. <C T="W" I="7" O="false">.. <S T="3" F="ModuleAndOffsetCollection" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1849
                        Entropy (8bit):4.6471061952004336
                        Encrypted:false
                        SSDEEP:
                        MD5:BFBDDE13605514B665C9A51EEC9D096B
                        SHA1:A3B537415116EED6D79D0A3B8064032AE5921AF7
                        SHA-256:0BD8F551465C1C5164D0CA78C4C09C3EB936F482F4E0F348361B9E04068FF0EB
                        SHA-512:DA332079CF71B649CAF6BCB90158944567B5DD3BD9D89607762B6950E8226AAA7B29CEE4984C96F88178F4A73BAF4D700ED08B52E30ABE2F2717FC5F02F0424D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11577" V="2" DC="SM" EN="Office.Outlook.Desktop.HangReportingSummary" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11576" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="15min" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="200" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="BucketId">.. <S T="4" F="0" />.. </C>.. <C T="W" I="1" O="false" N="ScopeId">.. <S T="4" F="1" />.. </C>.. <C T="U32" I="2" O="false" N="HangCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U64" I="3" O="false" N="AverageHang">.. <A T="AVG">.. <S T="4" F="2" />.. </A>.. </C>.. <C T="U64" I="4" O="false" N="TotalHang">.. <A T="SUM">.. <S T="4" F
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):780
                        Entropy (8bit):5.169807413233588
                        Encrypted:false
                        SSDEEP:
                        MD5:0BF5CDD84CEE3B5F650550249C9890A0
                        SHA1:DD3E1E63EAF182B9182AC0AB1C2C618FFB2AB107
                        SHA-256:49B50BE12E7C97DD255508B3F55059F864C12782CE0DD652BC6444439F943198
                        SHA-512:ACFC42E03696E472C95C628B2FBC2621CAA281CC30D544CC83B75A3A70E4C3B43744A834A0FB2D13E9E0F74DA3A9DB12F49444381DF4709CF05C466DBD4483C5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11579" V="1" DC="SM" EN="Office.Outlook.Desktop.ComAddin.AddinEventPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="AddinId" />.. </C>.. <C T="G" I="1" O="false" N="EventGroup">.. <S T="1" F="EventGroup" />.. </C>.. <C T="U32" I="2" O="false" N="EventId">.. <S T="1" F="EventId" />.. </C>.. <C T="U32" I="3" O="false" N="UnhealthyCount">.. <S T="1" F="UnhealthyCount" />.. </C>.. <C T="U32" I="4" O="false" N="HealthyCount">.. <S T="1" F="HealthyCount" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1727
                        Entropy (8bit):5.060237616145602
                        Encrypted:false
                        SSDEEP:
                        MD5:A0C0FC7C7912E651E86590301BC4A9BC
                        SHA1:AE03D75EE100CFA2285C6CC10C503F5B0F50194B
                        SHA-256:636CE2A813DBE4387EA9D2A4693D6A0BC599E4C9CD07B72A5D50C8EE5BB4AD2E
                        SHA-512:ABB71A6AD6CCABA617E916A7CE2AC01B1C7E8F5A5BEE788BB72E38A53FC9CFB10F9A09E670F05CD90C7FF682C78822765072F6F9D53F4EE4C70C6855AE33A118
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11579" V="2" DC="SM" EN="Office.Outlook.Desktop.ComAddin.AddinEventPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="AddinId" />.. </C>.. <C T="W" I="1" O="true" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <C T="G" I="2" O="false" N="EventGroup">.. <S T="1" F="EventGroup" />.. </C>.. <C T="U32" I="3" O="false" N="EventId">.. <S T="1" F="EventId" />.. </C>.. <C T="U32" I="4" O="false" N="UnhealthyCount">.. <S T="1" F="UnhealthyCount" />.. </C>.. <C T="U32" I="5" O="false" N="HealthyCount">.. <S T="1" F="HealthyCount" />.. </C>.. <C T="U32" I="6" O="false" N="GreatestElapsedTime">.. <S T="1" F="GreatestElapsedTime" />.. </C>.. <C T="U32" I="7" O="false" N="SmallestElapsedTime">.. <S T="1" F="Smallest
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1443
                        Entropy (8bit):4.5876919138809225
                        Encrypted:false
                        SSDEEP:
                        MD5:0389FAC00E751CA7770653005A982105
                        SHA1:3ABD993C86DFE70344409E3C8F398A6928CD55EA
                        SHA-256:337E67814E5E251E7B82931F28CA01F8549BAD41746557A11DA5584DA494C693
                        SHA-512:972A735434F7814CC6AAD250733461514849D6904AB159342C7D3EF40349D6AE0F47998B34D2C5C9F3E40E4961AEFF289463DE4FCEC9380E7C32AAD7A5817128
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11581" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.TimeZoneSelection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="831" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="NrTimeZones" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="NrTimeZones" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="NrTimeZones" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CalendarTimeZonesSelectionFrequency">.. <C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1389
                        Entropy (8bit):4.683887789015413
                        Encrypted:false
                        SSDEEP:
                        MD5:37ED823C67FB02E2D49931EC3CA11295
                        SHA1:CD34F1E553C38D5F91CCDE273C6BE8D14A2FAEC1
                        SHA-256:E72EA1282C20D373998B3C546D1100D20C871275D3D68EB1CD52481283361AD4
                        SHA-512:AAB2A02BF50230DCC272DD628871A6B29BF07F92B9DDD7ADBBAD86DE376BD46E74F5635A368618B1F243EE78A931DE8AC35B6EAED4EE7388405720FC7CF27AF7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11582" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShowRemindersOnTopUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="833" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ShowRemindersOnTop" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ShowRemindersOnTop" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <S T="1" F="ShowRemindersOnTop" />.. </L>.. <R>.. <S T="1" F="ReminderShownOnTopOfOtherApps" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1811
                        Entropy (8bit):4.17344594271943
                        Encrypted:false
                        SSDEEP:
                        MD5:6F4526507B71551351CCFFBBCE296A38
                        SHA1:F31A54C0664DAC8B5792450C1BA41FA2B631DD24
                        SHA-256:9F86AFED08E86675A9DB31E2A5BFF1EBFAC62BB914EA22EC49A25DCE6172789F
                        SHA-512:98A8AE29917400B8E7F458A020E79150406E954B2781988CC8BBDA4C6ECB229419BFBC17E27955D319EC1CA2532109D97FDF10186AB4FE3C31D38CCE64AC202C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11584" V="1" DC="SM" EN="Office.Outlook.Desktop.Mail.ToastNotificationCustomActivatorRegistryNotSet" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23402" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="AND">.. <L>.. <S T="1" F="IsC2RBuild" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="fC2RRegKeyExists" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsC2RBuild" />.. </L>.. <R>.. <V V="false" T="B" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):482
                        Entropy (8bit):5.402511118481495
                        Encrypted:false
                        SSDEEP:
                        MD5:E32167A29069C0C7FF6D3E55D7397C14
                        SHA1:18CBED1EE16237BEAAAC65418DE5223657F19C8B
                        SHA-256:71E4A1EF364BEC64E2D41295E47AB3D4FA72F9C50FA51DEA6C66ED9A2B4AD0DF
                        SHA-512:E1186FA48090591884F4C80AF9016A128156ECA20B96942FCBC3D3A9DF0EC6E9CB410656EA719E7D73DAEB0BC2D5480EBACD7BC16BB48C3CA8ACFFA1EB7647F3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11585" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShowRemindersOnTopOptionsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="832" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="B" I="0" O="false" N="ShowRemindersOnTopFeatureToggled">.. <S T="1" F="ShowRemindersOnTop" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):600
                        Entropy (8bit):5.1976634978025436
                        Encrypted:false
                        SSDEEP:
                        MD5:F54D0E7EF047FDB216255E3658544250
                        SHA1:012E9B3E9F0E3C87553947F468262A78BF7FB535
                        SHA-256:530DCB9E2BE273A5D2E7833F6A12CEA4320A8A644757B8779CED810ACCCCD64A
                        SHA-512:44232D994CA5C23EF3B7E8E9D7C4C3B968F6DB1574896790483499E5AA24A232718F758E5422890906550AF737E6454FBE0AB625F784CF7CB92A296F17C9858A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11593" V="0" DC="SM" EN="Office.Outlook.Desktop.UserDefinedRulesCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="UserDefinedRulesCount">.. <A T="MAX">.. <S T="1" F="UserDefinedRulesCount" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):841
                        Entropy (8bit):5.212523722154653
                        Encrypted:false
                        SSDEEP:
                        MD5:B0409870D83FC2B81EFB6FE40D078DF8
                        SHA1:88C66C8692B10048AED6C859F38D7F7598095FE3
                        SHA-256:94D8C0DC7C075D5A3B6026DE63125F400277A633032CB46ED76B9A65C0213FDC
                        SHA-512:4ED16BC8731D07A470FB54F4E4570D29B9F7B99A3C6901B68AE9B6FCF69AD88A164B152A4B9E6C24322B439C2F8239579C4230FB5216185247DA58072261047B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11597" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvGroupSendLocalLieAction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="BIN" I="0" O="false" N="HashGroupSmtpAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="GroupSmtpAddress" />.. </U>.. </C>.. <C T="W" I="1" O="false" N="NewConvId">.. <S T="1" F="NewConvId" />.. </C>.. <C T="I32" I="2" O="false" N="ActionType">.. <S T="1" F="Type" />.. </C>.. <C T="U32" I="3" O="false" N="Source">.. <S T="1" F="Source" />.. </C>.. <C T="W" I="4" O="false" N="OldConvId">.. <S T="1" F="OldConvId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):674
                        Entropy (8bit):5.283524920229644
                        Encrypted:false
                        SSDEEP:
                        MD5:E290D90EE8D7DDB3DFF1D72CB3EB85C6
                        SHA1:95D499091026BC262EE1CCD67AE52B87D0371C32
                        SHA-256:5E5F51372B6F412A1485D0A77191D011AF2908C394CC55C0F6236C8670936C0D
                        SHA-512:B82D5AEE4C2B7C1DE27F04B227811E3EAC118197AB708DFBB986DECCFAD0312EC0C0B68F570A0A2887C6E1EECBD0E68F9A3A875F67179D6F9EE3E0F43078E04A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11599" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupTransitCacheNotifyCache" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20070" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="BIN" I="0" O="false" N="HashGroupSmtpAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="GroupSmtpAddress" />.. </U>.. </C>.. <C T="I32" I="1" O="false" N="Source">.. <S T="1" F="Source" />.. </C>.. <C T="I32" I="2" O="false" N="NotifType">.. <S T="1" F="Type" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):773
                        Entropy (8bit):5.1682185883197285
                        Encrypted:false
                        SSDEEP:
                        MD5:51F3D63DA3A162B4E417E6971EF43A9D
                        SHA1:89C619EEE779C08D5F910B06C77693418E017F80
                        SHA-256:004569769A4C76FCAE6C99EACF56CF7633AD60FAFB7E0CE23DBECB4AD0DF54A8
                        SHA-512:D21BEC0DACB781FAA1CCB9C32885BFC572A501BC3586D36296233329A73C83FEC112D4CEC544D81C8518C3AADF4C740E43447D46C60850D48C9BF1ED9F7CCC6D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11601" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.OrganizerDNFUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="902" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="903" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U16" I="0" O="false" N="MeetingsWithDNFAvailableCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U16" I="1" O="false" N="MeetingsWithDNFEnabledCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):768
                        Entropy (8bit):5.148924262031493
                        Encrypted:false
                        SSDEEP:
                        MD5:CAC570D07C2689D6B7078B966C2A14B6
                        SHA1:C846A38B97C2A11B6EC2B779D0D3D1BA59E445D0
                        SHA-256:28F341EA9A54F05FD502C789D55E2A022FE1CCCC8E1BBA0128CF1946AA65FA44
                        SHA-512:B645F7D4335DE0FECE615D6D7CD7F8E943E86B3816331B067293C6E98F55D269CDC18C3766053B517931DEDF2BE9755A1AE1F24FF01DC5443815DE35C38A7294
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11602" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.AttendeeDNFUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="904" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="905" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U16" I="0" O="false" N="MeetingsWithDNFCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U16" I="1" O="false" N="ForwardAttempedOnDNFMeetingCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2823
                        Entropy (8bit):4.667743054516838
                        Encrypted:false
                        SSDEEP:
                        MD5:88F9AD5500BA7A90B93ACADE3A279F98
                        SHA1:A4EE759E607A4C8FB782AC3D1DDE253ED54500B6
                        SHA-256:2F23335CB7D55DA7F03712822DCFF409C09B0D85C455C46EF003266BB3DE61D2
                        SHA-512:37388FB2BEADF9FCE9524CC1F8A409064C170F88617F85AE46C60B2268349F7FF07C5376D6E6398A78CA95E0637214AC335F3B143BF7427E4E33C640F9F824A8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11603" V="0" DC="SM" EN="Office.Outlook.Desktop.CMapiSvcMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="823" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="825" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="824" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="839" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="840" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="841" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="PrivateMapiSvcInfFileSource" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="5" F="PrivateMapiSvcInfFileSource" />.. </L>.. <R>.. <V V="1" T="U32" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):507
                        Entropy (8bit):5.261684898715884
                        Encrypted:false
                        SSDEEP:
                        MD5:4FF6E7DD1A005A6E0EA09EB6C84CB4EE
                        SHA1:F2CD21F7D451000F25B231E5BA2EC29BB93A6972
                        SHA-256:4CADE7447043CEC0D4E40FC8E157C30A2AEE4FFB1D4BD0A384ADA34395AE0D72
                        SHA-512:F85846879A851F3BAA27CB5ECA0DE56D6CBC1964AA55661BCB2A5CADEA1466204758A7EEC3A8BBDCFE3D75CC69B715F46ED6261F5F682A8D69C6EBFC236FAFAA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11605" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateUnifiedGroupServerResponse" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cjmad" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1526
                        Entropy (8bit):4.252850455875291
                        Encrypted:false
                        SSDEEP:
                        MD5:375962AC37B863FB8F56595FE41A4220
                        SHA1:C35BB4FFD7877681A03CB4C1FC200235B6C12AFC
                        SHA-256:2D7D1A73B0CE6FEA475C5F07C94EE62A90D3A0DFD2938E7777B1D19B80777F85
                        SHA-512:7C53646A0C957A46B61B60FFD147EC00ABD5DF824AA8FA860473D93E0558AFE0239C4614BFC9E3808CFC0D6F4F6061D1A4EB025ABDBA674EDF9AAEB1E4CDA2D5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11607" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="18034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="hasGroupRecipient" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="4" E="13031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="4" F="Type" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="4" F="Source" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <Etw T="6" E="348
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):590
                        Entropy (8bit):4.92401885448348
                        Encrypted:false
                        SSDEEP:
                        MD5:C9ED7E00C5FC6A2437F9DEFB2CAD4266
                        SHA1:6DB6A4CEDAFD240DA128CB0B89D052BACD48120D
                        SHA-256:9D8A2BF7AE190FE35A148480EA604BD1641A2F392E2B3458F5F766C02A0DDE0A
                        SHA-512:7519ADFC64CEECC861D2E481B1DAEC444331EB3E1C4CA5493F774A19C38AE126503669CB6DB1510E4A39BA15F18B736E37C68CBEEAA3FEFF615A6FE662BFA2CE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11608" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvDisplayLocalLieLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11607" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="86400000" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="LocalLieDisplayedLatency">.. <S T="2" F="0" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1518
                        Entropy (8bit):4.257585206740892
                        Encrypted:false
                        SSDEEP:
                        MD5:5E44132333395A63CEBC650C9EE72AF7
                        SHA1:2A6C61334547CEC32D45465FA9281295B81EF829
                        SHA-256:3C69F711C08A729821A020F4121E0C022F7F14B8FEECCDA19EB9D1942AD0B89F
                        SHA-512:A1E64365D3FD7EA54422AA1521FFF9F973C72002E17F454FD7C49F79CDD62A78577BCF3C86CFF6637356320F3AA6E7238CD0F78C9918B0CEE8D16A411EF46C65
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11610" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="13031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="Type" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="Source" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="Source" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="Source" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <Etw T="7" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae0
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1612
                        Entropy (8bit):3.261252887216048
                        Encrypted:false
                        SSDEEP:
                        MD5:41E04558B36BC671E456895430C55C14
                        SHA1:2BA621AF7827DE517A5FB2986BCB14E480A1F6F9
                        SHA-256:7274EECE758E786BFBA3AD8C4FAE8B7064ED96DA2DCF7D2C9E5CDB67F23660CF
                        SHA-512:6B8FEBD4099106E425743BEAB19B48E02130F3E3DC8E76D46C1B971237F9F60906CB75A84822FAA4D70BB3D1384E461A2B1357DF0E18ED2495103F1841C03B33
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11611" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11610" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="1" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="2" />.. </U>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):988
                        Entropy (8bit):4.421351563273142
                        Encrypted:false
                        SSDEEP:
                        MD5:BEAA2FD1A2D038F5DEE15C2DBABF4C88
                        SHA1:D689718FB5220A21093922E5BAD77889E9197CF7
                        SHA-256:E548AFC38ABC73D008C0587FC1F9DF5EF993FFD1C6858AD8577F9350F2AA4DF1
                        SHA-512:72DDA1F28D4B19A8BB9570EDA3492EC9957A833CF1481CF3D0A7526438C65D6763D5646E6E4BA8B4FE470F5DA196DC7B5D9138BDCE5CB231C0ED186CEAE6CFAB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11612" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvReplaceLocalLieLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11611" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="86400000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="86400000" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="LatencyReplacedBySentItemLocalLie">.. <S T="2" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="LatencyReplacedByTruth">.. <S T="2" F="1" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1384
                        Entropy (8bit):4.376237125125716
                        Encrypted:false
                        SSDEEP:
                        MD5:E4345E31645B23CBD29C50789BF9128D
                        SHA1:A27FAF9D4998A48401AC3262E773F13E294A3380
                        SHA-256:3A0BDBF2A24D2F185BACF9B61A5C5B550BE1A20D0E22AA6E115793CF4E85F275
                        SHA-512:26A35C0CD4A2657D7DFD2BBBC25BCABEEB989C5AA28FFB6F5E057B4A1F0512818BA383DE05075BC422702FD6EC071B4C948B86F59310769DF509A747673926D8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11613" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvLocalLieCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11610" />.. <F T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="1" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="2" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Daily" />.. </S>.. <C T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):361
                        Entropy (8bit):5.39233656535639
                        Encrypted:false
                        SSDEEP:
                        MD5:F8744BD1BE5242D88C34AA2C556EC16B
                        SHA1:AD14C087BDE7EB78DA6475ED280FCECEA51B8AA1
                        SHA-256:D9260C1466FE0EA17B7D9AB97F7889B44C8CD9A4A3153C12708EB08A565D4A01
                        SHA-512:9AD9FAE2CCCBCD6B9FCAA96B33DF7A4689FF836E163709676B70212DAB2F9EB87D817B0A581B6930BB8E18E4560146CAB239447C3F670DAF2BD64A24844DCF5C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11620" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchFeedbackButtonClickCount2" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9057" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):412
                        Entropy (8bit):5.288494063001617
                        Encrypted:false
                        SSDEEP:
                        MD5:8DCAAA83EE50033AF90C1787EADECF6C
                        SHA1:9B662B4672E5D3BB8837158B15125F486C9B0123
                        SHA-256:8C12B4ACC9D2F30E767F1FD733D844C72308517A0641FA8AF63226C8838DC48D
                        SHA-512:064C0A4BF927F278B3859A1A0A38FA21CD967F30BB539A0ECF5E9DCBA9ABBCC4DEEE9E959FDB50E6D8899A8F0FA423F9B133CB88D09B18FCA0D382D4E17A9FD4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11621" V="0" DC="SM" EN="Office.Outlook.Desktop.AutodiscoverServiceClient.SuccessPath" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ci7jr" />.. </S>.. <C T="W" I="0" O="false" N="SuccessPath">.. <S T="1" F="SuccessPath" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):997
                        Entropy (8bit):5.11152206841213
                        Encrypted:false
                        SSDEEP:
                        MD5:2B92E217714E525D779D275EC93B5614
                        SHA1:F0D066061FC8C5421BE7FCA595999617834F307E
                        SHA-256:0DB79E1F1623E80DCBBD309266DB672C5848087973D3572B28F054BA0094DE95
                        SHA-512:048901F4EC602786A82BF720668D116A0CC6983FE81A915E151312E2149E13F5AA5E5AF8433A25DFB288439B551D1F4C47BEA3D0424358404159250C9F1152C7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11627" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupMembershipChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ckvxl" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="U32" I="1" O="false" N="DialogType">.. <S T="1" F="DialogType" />.. </C>.. <C T="U32" I="2" O="false" N="NumberOfAddedUsers">.. <S T="1" F="NumberOfAddedUsers" />.. </C>.. <C T="U32" I="3" O="false" N="NumberOfRemovedUsers">.. <S T="1" F="NumberOfRemovedUsers" />.. </C>.. <C T="U32" I="4" O="false" N="NumberOfPromotedUsers">.. <S T="1" F="NumberOfPromotedUsers" />.. </C>.. <C T="U32" I="5" O="false" N="NumberOfDemotedUsers">.. <S T="1" F="NumberOfDemotedUsers" />.. </C>.. <C T="I64" I="6" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):460
                        Entropy (8bit):5.368196352254861
                        Encrypted:false
                        SSDEEP:
                        MD5:878875EF33D9BB4782972971DFFB2F4F
                        SHA1:F9B747392C37CDF72E10FE8EAE966049715C4C92
                        SHA-256:6BF7C3F96B107DA94786A8D72C7D2DE7753B28B32464EF79251C363EC67C7CAA
                        SHA-512:B9F3844F1E6D2494B4B98204221023E6CE07D84AFD5E8E70C4FF4CA103D87B81BF0C0B7EC0E4F15FBB00729EB57F3FB82CB213F93E5E105FD0E57703D6FF7BDB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11631" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.StopGroupTimerSync" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3126" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="TimedSyncRegDisabled">.. <S T="1" F="TimedSyncRegDisabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1213
                        Entropy (8bit):4.7939456440401305
                        Encrypted:false
                        SSDEEP:
                        MD5:14795F07F55479AC04D0225B2D9738DC
                        SHA1:A279817545F47B08AA9C479F1F92119CCB91ADCF
                        SHA-256:5635AF79DC4D130D6D20D4C07D840C538FC5289D1F970B7C51AF710369EC8FFB
                        SHA-512:877410D8475D535AD904186288524F261EA1F6590AF6F355117FB905E7A37AB45F097AFB1EA2B5ED13715BD206C2E3DC3EB0973D8770202B4D7FCD209B9844D6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11637" V="0" DC="EUII SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="3459" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TO T="4" I="30s">.. <S T="1" />.. </TO>.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. </S>.. <S T="2">.. <F N="Group" />.. </S>.. </G>.. <C T="W" I="0" O="falseNoError">.. <S T="1" F="SmtpAddress" />.. </C>.. <C T="W" I="1" O="falseNoError">.. <S T="2" F="DisplayName" />.. </C>.. <C T="U32" I="2" O="false">.. <S T="2" F="UnseenCount" />.. </C>.. <C T="B" I="3" O="false">.. <S T="2" F="ShouldAdvise" />.. </C>.. <C T="B" I="4" O="false">.. <S T="2" F="IsFavorite" />.. </C>.. <C T="B" I="5" O="false">.. <S T="2" F="IsTopPrankie" />.. </C>.. <C T="B" I="6" O="false">.. <S T="2" F="IsRecentlyVis
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):922
                        Entropy (8bit):4.823261789882077
                        Encrypted:false
                        SSDEEP:
                        MD5:5F18C5EE2EE201C21B03C935D738A85C
                        SHA1:BB672F26D1B52F34CEAA74350BAF1EAF0DFE5F4D
                        SHA-256:E5362153CA6F04F6F4EF13D69D7B82DA690FA119F40CC184E40F8BBC391C4F74
                        SHA-512:892F749435D553170EE8A45403164CDCF69F8C13D82224F921112AF75C012596BA7E15E5594E89ED8FF1A3639E532877145FF2B0345B78258F3FD86E7960C4D9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11639" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupVisitedWithNonZeroUnseen" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="300" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11637" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="NonZeroUnseenCount">.. <S T="2" F="2" />.. </C>.. <C T="B" I="1" O="false" N="ShouldAdvise">.. <S T="2" F="3" />.. </C>.. <C T="B" I="2" O="false" N="IsFavorite">.. <S T="2" F="4" />.. </C>.. <C T="B" I="3" O="false" N="IsTopPrankie">.. <S T="2" F="5" />.. </C>.. <C T="B" I="4" O="false" N="IsRecentlyVisited">.. <S T="2" F="6" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):701
                        Entropy (8bit):4.832194960740667
                        Encrypted:false
                        SSDEEP:
                        MD5:2BD8AB15237D265974F14E0BDCC69F9D
                        SHA1:C2575F3A9A15D80C08AE20C2C1884222E29FFC9F
                        SHA-256:4F43B19151FA9E90C2A88A7F26420515AE7A8C5AF6653722C90CAAD74D4230CE
                        SHA-512:B3B6EE2309A4DF631FD0A09896E60FAE3FFCB3938A5CB93A10448B5FAC9F233B9A3DDD53420B061DA27DC69EB73DAAFE25E77AE38FC579C09F0FF1F904D850E5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11640" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupVisitedWithZeroUnseen" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11637" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="ZeroUnseenVisitCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1399
                        Entropy (8bit):4.07908865712039
                        Encrypted:false
                        SSDEEP:
                        MD5:5CF1168B92DF59DD85035277F7EB3C0D
                        SHA1:8F7FA47B49568155722110550D95FD531384D23D
                        SHA-256:B4C7BD0FDD3FAE338D692797A43CDF2316DF4AE303703373422D1D26B96A9420
                        SHA-512:F2DFFD1019D910A09A067E459C9F3409675F90B5765BA0351882FB67FFF6F46796DB11942C55C812A3CC3BDEF78464DF859EFBB9D9497E2245F82F4DA7B519AB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11641" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <R T="2" R="11637" />.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <TO T="4" I="5min">.. <S T="3" />.. </TO>.. <Etw T="5" E="241" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="5" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="5" F="LogStr" />.. </L>.. <R>.. <V V="15" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):696
                        Entropy (8bit):4.927767271855225
                        Encrypted:false
                        SSDEEP:
                        MD5:E48AD6BA2E7E8DA3BE4EE62E5AF5A3B9
                        SHA1:E9909A98CC925410AEBBCFBA4FAE9E24F3B20FA3
                        SHA-256:7AFAD94DF3F8AA9504092CE1EA975C67BC92533854DF7D4BE0AD03395497329B
                        SHA-512:8D0F2CDFED9C0A568F40EAC728F7B8C8BFFA9E70263D3B42A93CF65EFF20862E11776993A2750AFC306147BBB1318FDD8F89A172E0D6E0B0BAB3C6E65DB8C73E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11642" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupVisitsContentSyncLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="300" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11641" />.. </S>.. <C T="U32" I="0" O="false" N="NonZeroUnseenVisitCount">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="NonZeroUnseenVisitSyncLatency">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <S T="1" F="1" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):3.961646487265531
                        Encrypted:false
                        SSDEEP:
                        MD5:69F3C5B599738F7FFEC592B6EB905B66
                        SHA1:478D47AEA85BBF6DD508C1DCCB30C2923C8A165A
                        SHA-256:1B48993B7CA638BFF78E21DC31FE31345EF348ADD5CDA1E5072EF5C879312985
                        SHA-512:C9743EC917ADE9F12B709B23A45A63851335E6779A9A748DE3F204D129E496FC3ADDEE09BAC60B52729898491AF4FFB82C7FCEE88AB401D74339D43003D03127
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11643" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="241" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="LogStr" />.. </L>.. <R>.. <V V="15" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="F" I="0" O="false">.. <S T="2" F="MessageCount" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):792
                        Entropy (8bit):5.108078659105838
                        Encrypted:false
                        SSDEEP:
                        MD5:5E55AE1F0F9797B94D3B334AAA18A5E9
                        SHA1:71530C677F6C15D063C75189636B0D04C840564A
                        SHA-256:9D01CD8DDB5E550E7D7F46589BEA6A1C902815BC3BDD55E8ECA5D19D41FA2E09
                        SHA-512:2B0EC534DAB221564CDC52A6F423738B90BA34159B6FA5367131D041470793D3A709CA7F1C6EAD8F8F2A891BF86D4CFFBC199D2DC6CBB75D57B12CB3184E4572
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11644" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.TotalSyncCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3459" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <R T="2" R="11643" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="TotalSyncCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="F" I="1" O="true" N="AvgSyncMessageCount">.. <A T="AVG">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U32" I="2" O="true" N="GroupAdviseFlightFlags">.. <A T="FIRST">.. <S T="1" F="FlightFlags" />.. </A>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):596
                        Entropy (8bit):5.246372126859281
                        Encrypted:false
                        SSDEEP:
                        MD5:E95A59C1371BC2EDC6438207E5E4EEFA
                        SHA1:F8CBB23174007C506746DE287BCFD51F914E3389
                        SHA-256:86A7C5A6E82E65EFC191E1E68FE20E7A38392282EFCE092E988E02D754525A77
                        SHA-512:04E84D6CE531255D7D1A36B8378BC4838AC416BEF1CF1C9CE73A73CA9019685270D39B1A4CF86641BD6722BC18721D5838824A96433B949A3A9F70283BB03BB0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11649" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CountSuccessOfEnhancedGroupFollow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3260" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountofSuccessEnhancedGroupFollow">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):687
                        Entropy (8bit):5.126823146916047
                        Encrypted:false
                        SSDEEP:
                        MD5:9A847FA4B6D8CE5FF25C39116ECBB6F6
                        SHA1:70EBD99A3EF893AA22075F8211A330EE68CEB424
                        SHA-256:FA642CCBA88219B8DAC4F931016412F9708C22C0C1FB3BEB6960FC747343B183
                        SHA-512:89463AD7958638D45D9C87D7E4994F48D3250CC4695261577D98305EFFF41195A31953E0F5E9BCFFFA3CE31439B2832E5E4AE95009A9AE8CD8BD2AF641367226
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11651" V="0" DC="SM" EN="Office.Outlook.Desktop.SendToOneNoteAddin.ButtonClickTelemetry" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19035" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ItemType" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="Type">.. <S T="1" F="ItemType" />.. </C>.. <C T="U32" I="1" O="false" N="ButtonClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):744
                        Entropy (8bit):5.277491808508557
                        Encrypted:false
                        SSDEEP:
                        MD5:6C473735DDE7FC149A8ADB47E9A88F6C
                        SHA1:77331B90D0B09F12F99A63BED59B726A5B582BE8
                        SHA-256:5BDA375FADB48365A9BF8F7030FFEBDD89E3AB6866B362D358F9CEA2338F1C05
                        SHA-512:9F9BF87D5FD3724595F050C991FC36B4ACF32E4590329AD537FFE062D9E536ACD41E7CD24328ED621F3EFEE9E906A96AA01BC75103524EAEAA41CE3BD3A0CEA0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11657" V="0" DC="SM" EN="Office.Outlook.Desktop.NullOutlmimeHeaderTableRow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="163" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="U32" I="0" O="false" N="MIMEPropertyContainerID">.. <S T="1" F="MIMEPropertyContainerID" />.. </C>.. <C T="U32" I="1" O="false" N="LoopIndex">.. <S T="1" F="LoopIndex" />.. </C>.. <C T="U32" I="2" O="false" N="HeaderRowIndex">.. <S T="1" F="HeaderRowIndex" />.. </C>.. <C T="U32" I="3" O="false" N="PropertyRowNumber">.. <S T="1" F="PropertyRowNumber" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2264
                        Entropy (8bit):4.614108140239659
                        Encrypted:false
                        SSDEEP:
                        MD5:60B4C7E806CEA29568CD09B187789DF6
                        SHA1:7162EEBDB33BF3510A5B958F941D03E625806EB9
                        SHA-256:60AE6580182F624F79A43AE6731691D16CB82D0232FE93601341BE8EEB72BEC9
                        SHA-512:5920991A47A4B5C45EBBDB5B61C7C7DC4E0F016704679EE1BBFB7FEFF77795E11D1242D54681B5DAF2CAA4C5475D885507A7670648D710A56B6300BB7F95B8EF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11658" V="0" DC="SM" EN="Office.Outlook.Desktop.Social.PickerActivites" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4051" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="MentionPickerActionType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="MentionPickerActionType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="MentionPickerActionType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="MentionPickerType"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):428
                        Entropy (8bit):5.3112013575014405
                        Encrypted:false
                        SSDEEP:
                        MD5:87D41D382120A6802A3BB2958687B53D
                        SHA1:2951AABC5380E524126A94385E6F72B281859552
                        SHA-256:12571CFDF73A7408D3D31D386E2572D1AC9BA843F3D67346496266E4F1EA990E
                        SHA-512:A4365C6951D987F124A6B089EF965DCFBD2C36CEA2A6C882C1B074A7E226B73DCF3EBEA7D4C05178BE8EF1688497F9857A37765C4FFC7520EAEBD7EDF0F38607
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11659" V="0" DC="SM" EN="Office.Outlook.Desktop.Pst.BestBodyMarch2018" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="8" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2001" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="B" I="0" O="false" N="Enabled">.. <S T="1" F="Enabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):904
                        Entropy (8bit):5.065926052144306
                        Encrypted:false
                        SSDEEP:
                        MD5:0C2581E059676F1D4D2E072EEC4C819B
                        SHA1:58A239F1A191559C07DE4B294DEFF073BE35B7A2
                        SHA-256:8A81FC16187E01DAC227FC959F6482D276EF47185AF48457263C87EFABB699F2
                        SHA-512:FD523AEE996B8F2602FD35D5B7F130332E720EAEEC7F1D13089ADE369B365FBF67E2BD8BB8335E7F2648CECE41EE197E5C05B4DF424AD40B560681889A9E1186
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11660" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlmimePromptDetection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="281" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="Protocol" />.. <F N="MailProvider" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Protocol">.. <S T="1" F="Protocol" />.. </C>.. <C T="U32" I="1" O="false" N="MailProvider">.. <S T="1" F="MailProvider" />.. </C>.. <C T="I64" I="2" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="3" O="false" N="CountPrompts">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1036
                        Entropy (8bit):5.052888049355876
                        Encrypted:false
                        SSDEEP:
                        MD5:D6BD8961C9DAF3AD04B7914231893953
                        SHA1:5A2F487BF429DF9B8BCD5540A1C82AD27E9AB2C8
                        SHA-256:A2A289DBB84A9895A59BD3491D423014CEADF18F14E34DFDA6006D858BA877BC
                        SHA-512:CCC87B12CB96683383EDD06965B9CBBFCDBFF4BAAE1B3AB6AD1435FCA5441AF2249F4FD875A3E07B3EBDAA8252F0A192D1FFA924B250BB0D90ECBC114EDC197F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11661" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlmimeAuthenticationAttemptResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="282" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="Protocol" />.. <F N="MailProvider" />.. <F N="HRESULT" />.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Protocol">.. <S T="1" F="Protocol" />.. </C>.. <C T="U32" I="1" O="false" N="MailProvider">.. <S T="1" F="MailProvider" />.. </C>.. <C T="I64" I="2" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="3" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="4" O="false" N="AttemptCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):691
                        Entropy (8bit):4.343267265855362
                        Encrypted:false
                        SSDEEP:
                        MD5:FA2F7005514A4359173994EB38ACE452
                        SHA1:03A2B872697DD679E42457CFB387A46F1E80B232
                        SHA-256:04DCA68E6CDCD140BA57C4871C0C978CF36A73ADD2186DA3CDCB4894E0240FFC
                        SHA-512:DD257FEFEDAF0C0555BCCA20526F325E376860C0454FFC86AC78893BD9C5B7AE283C1473FC0E9831DCB87CA996676ABBA7471C200020CD26BB91178CC57C4C38
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11662" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="I64" I="0" O="false">.. <O T="DIV">.. <L>.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="1" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="Last Updated" />.. </R>.. </O>.. </U>.. </L>.. <R>.. <V V="86400000" T="I64" />.. </R>.. </O>.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="OAB GUID" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1618
                        Entropy (8bit):3.485346728988187
                        Encrypted:false
                        SSDEEP:
                        MD5:4822CD7D4F6D25DA04555FC192E7DB49
                        SHA1:90E996E0C01639F38DF0EF1578A3DA7F5A4C3874
                        SHA-256:A8E812D2AEBAA846838B76FA71C8E6E321890B6C29D6B2934525F3400B334B1F
                        SHA-512:1EFBA9F124C486956456F905121E26DA09ACC9074463030D9457E6A97C262F0CBAA5BC15A73766851A99EDCBA19050A9210FAF98245ABDFC4F2E50D6AFF27D9E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11663" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11662" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="8" T="I64" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="7" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="30" T="I64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="4">.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="29" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false">.. <S T="1" F="1" M="Igno
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):801
                        Entropy (8bit):5.183512479764439
                        Encrypted:false
                        SSDEEP:
                        MD5:D4E5008B04625E256C6017EAA1B03C65
                        SHA1:D696CF5D98F85469EB3E37EEDC49DE3B156ACED9
                        SHA-256:5B79FB719D8086B0CF706146CE30C3ECC6F4B04932B0BB039D6DD83F9E7F4D2D
                        SHA-512:591932E414B9EC209E01B1B09F3F59E5CE2B5B956D7462A2221E55F8FF8BBFAC95A987C02D4000A125A5997A8573BDE35F8B46A95568853FC1E8BF6779B08E38
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11666" V="1" DC="SM" EN="Office.Outlook.Desktop.Search.FuzzyMatchContext" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7142" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="W" I="1" O="true" N="ReferenceId">.. <S T="1" F="ReferenceId" />.. </C>.. <C T="B" I="2" O="false" N="MatchRequested">.. <S T="1" F="MatchRequested" />.. </C>.. <C T="B" I="3" O="false" N="MatchReceived">.. <S T="1" F="MatchReceived" />.. </C>.. <C T="W" I="4" O="true" N="QueryAlterationType">.. <S T="1" F="QueryAlterationType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1603
                        Entropy (8bit):4.096573799634484
                        Encrypted:false
                        SSDEEP:
                        MD5:EFF24E264A94BAB3AC5AC81C4A365126
                        SHA1:1A27414CAC578093EC647E4619415AABE2B2FB8C
                        SHA-256:69F4A0373E45D0AFCF61D1855DC40CAE97769B7475DF1CC49B44DACA80F6B3CB
                        SHA-512:286767F526DBFB5ED6508C2F8C13B1B3894A28FBF51F07FBACB42F3C3BCC29C5C517E14F610449EE9754A1A1E2553108C9A328417E6EDFD7966BF6A0F4928C77
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11668" V="1" DC="SM" EN="Office.Outlook.Desktop.OABFreshness" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11663" />.. <A T="2" E="TelemetryShutdown" />.. <TO T="3" I="Hour">.. <S T="1" />.. </TO>.. </S>.. <G>.. <S T="1">.. <F N="0" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="OAB_GUID">.. <S T="1" F="0" M="Ignore" />.. </C>.. <C T="B" I="1" O="false" N="IsFileAge_0To1Week">.. <S T="1" F="1" />.. </C>.. <C T="B" I="2" O="false" N="IsFileAge_1WeekTo1Month">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="2" />.. </R>.. </O>.. </C>.. <C T="B" I="3" O="false" N="IsFileAge_1MonthAbove">.. <O T="AND">.. <L>.. <O T="AND
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1235
                        Entropy (8bit):4.7377046930203335
                        Encrypted:false
                        SSDEEP:
                        MD5:1E61C4F618449A751F5D0FDA23F7C5A8
                        SHA1:8DE9A92DE523BC27946C2F1497C89806FB402CB0
                        SHA-256:7EFD71797EB55D0AE75A8B3BB684CC590E378858850EC17E385481FA8AA3ED77
                        SHA-512:2DCE7BA2B7DEE7E593DE5CAA879002F029527E50D4B5226B2C73D94A7C81EDF98EE87A186EF6186ACF985BDF8892334E1552BD5C530733CA5919050300AC2A2D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11670" V="1" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.UserInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3734" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="SpecialFeature" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="SpecialFeature" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true" N="Audience">.. <S T="1" F="FlightAudience" />.. </C>.. <C T="B" I="1" O="false" N="MachineIDPopulated">.. <S T="1" F="MachineID" />.. </C>.. <C T="W" I="2" O="true" N="Build">.. <S T="1" F="ProductVersion" />.. </C>.. <C T="W" I="3" O="true" N="Channel">.. <S T="1" F="Channel" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):593
                        Entropy (8bit):5.21375563156899
                        Encrypted:false
                        SSDEEP:
                        MD5:C99837BEF7ABC9C6FE33FBAA8918CF28
                        SHA1:0C5D73E4FBD55ECAB0DB15A775F5618F30A4FCD8
                        SHA-256:502B418FB65648A13A463363B89A6D487691A71C4ED8DBCD78AA5D33EB4CFD04
                        SHA-512:5A4967B29B4F7FF220C6C61CB0A82FDF058F1F6EEAF647D71DB747CAFB4D0D0F814204EF94D370196F81FE9D8FF896BD2D3270BD3A511E03D1FC6979671E6A83
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11671" V="1" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.ServiceCalls" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3735" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="Route">.. <S T="1" F="SARARoute" />.. </C>.. <C T="W" I="1" O="true" N="HTTPError">.. <S T="1" F="HTTPError" />.. </C>.. <C T="U64" I="2" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):535
                        Entropy (8bit):5.300118517573922
                        Encrypted:false
                        SSDEEP:
                        MD5:CD298C1142DB1D07B4827D337A25FFE9
                        SHA1:0318CCB538CF4F61B2CC354851860E9FD7A09858
                        SHA-256:A4D6D5D66F3576274DCC0CEC3AE3A1AE9F155BD730A4A753164CB8146B238A95
                        SHA-512:63843528FAA98FC36CBD861A955B5680B57EE68E89B42732152C318C67E6BA8C7572D9E38E2DA617A319112FBFDB64F839B45885CD37B1F3F8456F49F0C35D2F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11672" V="0" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.FlightSetStatusEcs" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3736" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="FlightEcsOverrides">.. <S T="1" F="FlightName" />.. </C>.. <C T="W" I="1" O="false" N="Success">.. <S T="1" F="RegSetError" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):510
                        Entropy (8bit):5.276756368324579
                        Encrypted:false
                        SSDEEP:
                        MD5:92C0ED14E9F05FB4DBF2E0CFB35A21A0
                        SHA1:697EF4E2DFA33D47FC70ADE7C7CB4C7FC3AA7777
                        SHA-256:FBEB5AEFA68F205CCFEE428F3D884BFCE83F0935573A35C78DB7CC5BB8627FF7
                        SHA-512:8CEDDA7C810A60A29A6C8DFE848AE7B12DE616384700338A5DA1C5AD2D74C012EE2534A2B8CEBE493AF289398C4FFB432B8252B27C9B965B881770693F97114F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11673" V="1" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.HelpID" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3737" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="ArticleID">.. <S T="1" F="ArticleID" />.. </C>.. <C T="U64" I="1" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):524
                        Entropy (8bit):5.309611572297989
                        Encrypted:false
                        SSDEEP:
                        MD5:5EABE55F261B90EB200FBDBAC73DF7A8
                        SHA1:F54A61531259A65E7E9B002D4F6630561E617BBA
                        SHA-256:0FD32D4F6C075FF8806EBA50ADBA5300A6EF53F9DE491EE005BB1A25F225F13B
                        SHA-512:D1D332DA0E02AD316332FED6E9B2D6815512F73AA672E734CADC14974FAA1AB51B63CB3E5AEA3FD342D7A9B35858C9A869761CCF81DB7E4E1ACEEB364A9B31CA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11674" V="0" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.SARAReturnedFlights" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3738" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false" N="Success">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="Amount">.. <S T="1" F="NumFlights" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):543
                        Entropy (8bit):5.313779818888839
                        Encrypted:false
                        SSDEEP:
                        MD5:6BAA1EA7E09C1A322FC8D73D2E43EB85
                        SHA1:37C539988737DE8F06A69DCBAB043ED468F339AD
                        SHA-256:548F231FB947AC58E41BDFE213EDED9CB5E19B60F7469F3B6A72146DA9627EFC
                        SHA-512:4D4738D89E248BBCC8BC0F9E76D5F95663BAF6828D4D37DEFABBD8BB5336EC08F8898B1188C17DC123CAA06D49760398F04B24D52B79AE864082035DE7648C82
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11675" V="0" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.FlightSetStatusPreviewPlace" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3739" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="FlightPreviewPlace">.. <S T="1" F="FlightName" />.. </C>.. <C T="W" I="1" O="false" N="Result">.. <S T="1" F="RegSetError" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):653
                        Entropy (8bit):4.969980962354719
                        Encrypted:false
                        SSDEEP:
                        MD5:6DE08C38A17666D25C49BA341D2E273C
                        SHA1:855F7B5E20C9E15E94376B2566436772729A0EE7
                        SHA-256:8376B176B7B136C36524BE7D2AC3D01C492CEC12190C0F24F299F564DE86DACC
                        SHA-512:100DFA081B836CAC63C00774B36F80A42C8314ABA44773E46C49AFD9124C7F87EDCDFFD59FA49045002F0E7C65C5CDB7B4347D49E1B4FC969DE4AB850777D59C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11678" V="0" DC="SM" EN="Office.Outlook.Desktop.Authentication.SignInDeadlockAvoidance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="cm0bl" />.. <UTS T="2" Id="cl1qq" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="NumberOfCancellations">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):600
                        Entropy (8bit):5.197656753208381
                        Encrypted:false
                        SSDEEP:
                        MD5:BAD0B2D26A8A5A361FF4016DB9872EAA
                        SHA1:650083CE825CB0762CC27E077690D6D9CE659235
                        SHA-256:6D8685303D3153C4387B8ABA4D20BEC36A6C3815E1A330224A9B5A4614219EC0
                        SHA-512:048BC8820C283FF16C8D6ACEB8379AB65C5C9452B86DC11091E9855BFA5215C3F54A58CB4E15DA07A73C0A67E0B67524DE270E95AF55809E8AD411BBC1C911C4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11679" V="0" DC="SM" EN="Office.Outlook.Desktop.SubmitMessage.CopyToMsgProblem" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="5021" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="MessageID">.. <S T="1" F="MessageID" />.. </C>.. <C T="U32" I="1" O="false" N="PropTag">.. <S T="1" F="PropTag" />.. </C>.. <C T="U32" I="2" O="false" N="SCode">.. <S T="1" F="SCode" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4313
                        Entropy (8bit):4.3773032940657846
                        Encrypted:false
                        SSDEEP:
                        MD5:C7DA8A194363215C06C829B1327701A9
                        SHA1:132B6E7AF5C922996CDC386FC1996765F226F3AF
                        SHA-256:24CAA63EC7699ECADE0B5A7BB5FF114E43E97B74C3ABB07A1396B8D9A13CBDFB
                        SHA-512:3A5205AA3F8DC5052F19FA20758D9CD2E5C896FB7ACB9CAA802D461C38CC0F7ED08469F55BD93BC5613BC28B6009577C64CF915206D3F4F0CE804C5CD4E2B97E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11680" V="0" DC="SM" EN="Office.Outlook.Desktop.SubmitMessage.CopyToMsgStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="5021" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="5022" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="5001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="5007" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Daily" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="HResOld" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="GE">.. <L>.. <S T="1" F="SCode" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):506
                        Entropy (8bit):5.203457606856901
                        Encrypted:false
                        SSDEEP:
                        MD5:A6E11D4FA649872D59FD9757F86318BB
                        SHA1:338C051F2D0408C15A24CAFD781A0B1DFADFF150
                        SHA-256:7D0688BE24682D1AB41598387DCF368E9684B1E760DF44E5911A0CE88AFB537B
                        SHA-512:290248EE1D4A989E43E70AAFE8FCED345022870F6DAF9001FB8160F72B0F70BB41D9C1181A19E541C907E8ABEB71C5004CB42E58820CDB877B21E3378CF79CFC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11684" V="0" DC="SM" EN="Office.Outlook.Desktop.AutodiscoverServiceClient.ErrorDetails" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="coiol" />.. </S>.. <C T="W" I="0" O="false" N="ErrorLocation">.. <S T="1" F="ErrorLocation" />.. </C>.. <C T="W" I="1" O="false" N="ErrorDetails">.. <S T="1" F="ErrorDetails" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):440
                        Entropy (8bit):5.334582931550476
                        Encrypted:false
                        SSDEEP:
                        MD5:802E1235BBEB74166AF2EDB9B0FB4EA1
                        SHA1:D14C30FE7AD3C47189F059E4AD8A9DDB2B9D1DD9
                        SHA-256:ABE3E3D0F3D4422C24CDCB01F16EB8E718120CA29229C5BD370891E8CED5A671
                        SHA-512:DFAA7E746CB4B6EE21C73119DF49052FC41CC45E854398EFF167FB98F895B85A2A3B12D28180442F0C88ADC8F771330718F8960C35B65A12C87E8CF0ACEC5C87
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11688" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.FuzzyMatchClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7144" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="ReferenceId">.. <S T="1" F="ReferenceId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):678
                        Entropy (8bit):5.197510052873043
                        Encrypted:false
                        SSDEEP:
                        MD5:A8F835F7292D079D85FA7E866EC31049
                        SHA1:4D0A5346C86C418B2CD6E8EF49A33FD42F04EC04
                        SHA-256:8230496BE302328304749F0B5695D64D03A86E86BA22E02FD9934086110C90C2
                        SHA-512:2059637DDBECCC6871A36C7E5E146B230626005FA3E0E7EF598536D0B8A3B0E24843E6422B62D97F9ED166DF151EBE73D79A44DAAE44EBF8C50D45719BFE143A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11689" V="1" DC="SM" EN="Office.Outlook.Desktop.ComAddin.BootInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="GUID" />.. </C>.. <C T="U32" I="1" O="false" N="LoadBehavior">.. <S T="1" F="LoadBehavior" />.. </C>.. <C T="U32" I="2" O="false" N="BootTime">.. <S T="1" F="DelayTime" />.. </C>.. <C T="W" I="3" O="false" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):859
                        Entropy (8bit):5.141910280583144
                        Encrypted:false
                        SSDEEP:
                        MD5:E8218970143F2372A8F143D732115D00
                        SHA1:9DB7AD67F6776E834D3691AFE61496B73201FD42
                        SHA-256:9E1815722AEF1ECA4C49798C773D19BA329BFAEC9D3032796E06E32D15AC4D6A
                        SHA-512:F8067FFD728049458AFDE2ADFD708524FA8D19DC58A0C92C333A94C43847EA703B7740AE2EBD8E5DA03E7E4B237427269C8C41449CB3A4A54A9B780B8D714B92
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11689" V="2" DC="SM" EN="Office.Outlook.Desktop.ComAddin.BootInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="GUID" />.. </C>.. <C T="W" I="1" O="true" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <C T="U32" I="2" O="false" N="LoadBehavior">.. <S T="1" F="LoadBehavior" />.. </C>.. <C T="U32" I="3" O="false" N="BootTime">.. <S T="1" F="DelayTime" />.. </C>.. <C T="U32" I="4" O="false" N="BootLoadTime">.. <S T="1" F="BootLoadTime" />.. </C>.. <C T="U32" I="5" O="false" N="OnStartupTime">.. <S T="1" F="OnStartupTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3133
                        Entropy (8bit):3.865714546088812
                        Encrypted:false
                        SSDEEP:
                        MD5:AD6CABB80F294DFCE1F0BC67FEBA3293
                        SHA1:7E524932530E56FC95D88DB79D7E8DE907A675E7
                        SHA-256:1D12E1472C997F3E4AA768E815F603F2C83B67FFD93F15E475D7AD82D794B149
                        SHA-512:790CD14239A103E7DA78E70DD3840342B65C98FA13610D2CA2308CFC5DE2B1751B90293B3F35DB21E0DCC9DA36DEF748BF21F6AC77847A714643D4285BF00022
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11695" V="2" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroup" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19036" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2976
                        Entropy (8bit):5.032236730295511
                        Encrypted:false
                        SSDEEP:
                        MD5:F1E10E88036AB5750B021A6C00C32DB0
                        SHA1:49D70B89CD6B2A905F2C194BB86E05335549F0CC
                        SHA-256:927BD2D4CB827BEB947C66518F808BA1DDD23E736670B3F7AADBBB38643B1821
                        SHA-512:3EF5971BA0DB483C6197157C44C400817C8F3C4DC90586F6C8DA1B33FE9A5F49DDF51FCD57DE5B40AF071A0E9D8E335C615CF78BF0C1ED48A6717DB991BBDB1C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11698" V="3" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AccountCreationFailureDiagnosticsResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="493" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="491" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="8" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="4" E="494" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="W" I="0" O="true" N="AccountType">.. <S T="4" F="AccountType" />.. </C>.. <C T="W" I="1" O="true" N="AccountCreationResult">.. <S T="4" F="AccountCreationResult" />.. </C>.. <C T="W" I="2" O="true" N="RecoveryTitle">.. <S T="4" F="RecoveryTitle" />.. </C>.. <C T="B" I="3" O="false" N="TitleRetrieved">.. <S T="4" F="TitleRetrieved" />.. </C>.. <C T="B" I="4" O="false" N="ErrorMessageRetrieved">.. <S T="4" F=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3379
                        Entropy (8bit):5.03456639262393
                        Encrypted:false
                        SSDEEP:
                        MD5:8128FC3D43D014B1817459A17EAA530A
                        SHA1:2166F7C86E936A66A5639FCABF7F49FF1524F63C
                        SHA-256:8DED8CBC88E55F941608705F5A992B48329C97914493CF2ED2AEFCAB09B54F46
                        SHA-512:02917A6011B1D566664DDDBEFF28645A211409B072272C843EF701CBB31B324AAA2E8727448A2C4094B4EEF5AD5BE0EE0A722261A9566BDCB465DFB84626D931
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11700" V="2" DC="SM" EN="Office.Outlook.Desktop.AccountTypeDetectionResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3791" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3792" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="3793" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="3794" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="3795" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="3796" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="7" E="3823" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="8" E="3824" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="U32" I="0" O="false" N="TotalTimeForAccountTypeDetection">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1129
                        Entropy (8bit):5.140935693060115
                        Encrypted:false
                        SSDEEP:
                        MD5:33F29D9D773542AB05C2A725A5AEBBD6
                        SHA1:31275F20A0D0D7B1538AD3D4B7C1D4136F3B44CD
                        SHA-256:DE1FD2D5D06581EA0CE4C315E27B7EC0B63B5B036B1D6015297B1E72B9A482FC
                        SHA-512:DE6D6C3F93795F6D58766A74CDFC8B374FF975EDD62720CC54C2D96D3529F01716CC56D18148E1B10AAE7E78D2EDC6017ABE0486B5B12F49FEF305B153CEA3C5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11701" V="1" DC="SM" EN="Office.Outlook.Desktop.Lpc.LokiOutboundEvents" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b3g8r" />.. <UTS T="2" Id="b3g8s" />.. <UTS T="3" Id="9rfv2" />.. <SR T="4" R="(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)">.. <S T="1" F="CorrelationId" />.. </SR>.. </S>.. <C T="W" I="0" O="false" N="RequestUrl">.. <S T="1" F="RequestUrl" />.. </C>.. <C T="U32" I="1" O="false" N="HttpStatus">.. <S T="1" F="HttpStatus" />.. </C>.. <C T="W" I="2" O="false" N="CorrelationId">.. <S T="4" F="Matched" />.. </C>.. <C T="U32" I="3" O="true" N="Milliseconds">.. <S T="2" F="Milliseconds" />.. </C>.. <C T="U32" I="4" O="true" N="ResponseSize">.. <S T="2" F="ResponseSize" />.. </C>.. <C T="U32" I="5" O="fal
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1028
                        Entropy (8bit):4.708398065278194
                        Encrypted:false
                        SSDEEP:
                        MD5:DD4BF297493CEE5D60AD9AB426858DA1
                        SHA1:D53819D4A9BBB9260B808A24A99F08CF613376DE
                        SHA-256:B910E99D7283AF42FD3010F8D28F995AF859F235D5FAAB65CDF602237773B529
                        SHA-512:E1A6BAEDC8E0FDCF5EEAA0FE89379C368057E64D976B177E2643D72E1B25FBEF0CB5C0C08F68E3EEE93149F40297E975724AC8AC9F0C025B904078B0066C7148
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11702" V="0" DC="SM" EN="Office.Outlook.Desktop.SchedulingAssistantRecipFromEditControl" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1020" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="fNewCell" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="fNewCell" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="NewCellCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ExistingCellCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1271
                        Entropy (8bit):4.978455972588113
                        Encrypted:false
                        SSDEEP:
                        MD5:8BEF061B77604BF75FF655DEBDA5CE22
                        SHA1:A8BBF5CC40CA4CC5B80BA441891774BEC3CE1C22
                        SHA-256:752AD2BE6D92E5F2A02EECBED2F5EF388660B8DA76DA1DFCBEA04C09312F355A
                        SHA-512:4E58C49C04CB19D53918758659A9422AF98BD4BDBC86369FDEB2D2FE3D2BB3F8FF291F24C273D7983BC09C50DBCC150CF6882A91DF21C719E1F84B883A06DBB2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11703" V="0" DC="SM" EN="Office.Outlook.Desktop.SchedulingAssistantPeoplePickerHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1015" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="1016" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="1019" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="GridColumn" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="AttendeeSelectionFailedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="IsUpdatedCheckFailedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="EnterAttendeeValueExceptionCount">.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3171
                        Entropy (8bit):4.706340035425865
                        Encrypted:false
                        SSDEEP:
                        MD5:D15475174EE7DB434C43EC8ED48B0373
                        SHA1:6E1DEE8F9B3F932EBE3BA55BE39AE42161E09054
                        SHA-256:8B333E949A2A85F70EFE1E46A81E631039671D6A1D8498106D325228C0203EC4
                        SHA-512:90C823BC439314FFDEA79ADCF33999ACC9608C26072095711BB57A0A615F7F396F292438BC52DA25E91697AB85A91F98394CAF402CA86CC7E630F32828158D05
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11705" V="1" DC="SM" EN="Office.Outlook.Desktop.Lpc.LinkedInBindWorkflow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="100" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cmpda" />.. <UTS T="2" Id="cfzmw" />.. <UTS T="3" Id="cfzms" />.. <UTS T="4" Id="cfzmp" />.. <UTS T="5" Id="cfzmr" />.. <UTS T="6" Id="cfzmt" />.. <UTS T="7" Id="cfzmu" />.. <UTS T="8" Id="cfzmv" />.. <UTS T="9" Id="cfzqn" />.. <UTS T="10" Id="bd7ah" />.. <UTS T="11" Id="b3g8x" />.. <SR T="12" R="error=(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)">.. <S T="8" F="ErrorDescription" />.. </SR>.. <SR T="13" R="error_description=AADSTS([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)%3a">.. <S T="8" F="ErrorDescription" />.. </SR>.. </S>.. <C T="W" I="0" O="false" N="Bind
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):631
                        Entropy (8bit):5.23021248178263
                        Encrypted:false
                        SSDEEP:
                        MD5:5A8A41CEE56BDDE6EA382C24CEA91908
                        SHA1:95F861FDE1A01A29E3883218935D7543ADFE047A
                        SHA-256:0667A234151FF3EA3F1E955206C4E2BAB64C4A9B0283171A6F4BDE4AEC971DAD
                        SHA-512:7230661E9578C1B4BA6A94B45B0B3F1BCD8F2C9EDC93304F3717F21C2229B31D549E5BBED84216DD24610F83B6DB6838DBDBC3B078CD9E8756F91CABC86F319C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11710" V="0" DC="SM" EN="Office.Outlook.Desktop.NdbCorruptionResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DL="B" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="368" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="W" I="0" O="false" N="ReportingProcess">.. <S T="1" F="Process" />.. </C>.. <C T="B" I="1" O="false" N="CreateNewFile">.. <S T="1" F="CreateNew" />.. </C>.. <C T="U32" I="2" O="false" N="Consumers">.. <S T="1" F="Consumers" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1501
                        Entropy (8bit):4.1314083035473805
                        Encrypted:false
                        SSDEEP:
                        MD5:E5FE0FAB52FEC3FE674F1ED97C43DF43
                        SHA1:AAC9A4AD239C8152B8A86230061A7CD63C0BD3F2
                        SHA-256:DE0E32E7DF5E4E6EE1788E01CE8107D23327A357CC38DB0A170C31B73C9ABBE3
                        SHA-512:EED0C042D77C1528C70B50AB6F4F08471D6F8F8CE2112156600C848C5C4305CFAFA1362AC8FD3E1A2919056BDC6BE4D8020EE2914C2C58702609E1EC5FC92E2F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11712" V="0" DC="SM" EN="Office.Outlook.Desktop.ContactCard2HoverCardWarmup" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11736" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):587
                        Entropy (8bit):5.187286281544145
                        Encrypted:false
                        SSDEEP:
                        MD5:EFE7AAD31D626E6E0E7151DD0D2175B2
                        SHA1:18486D8911701C8FE583B28720B4193AC825B60E
                        SHA-256:121678735B8867ECE0B4341B260D19D75465995F2E9426B1F469F6CBA02FEF02
                        SHA-512:D3796CBFFBE3940E76BC6187E5FAB7FD35046A6243DF7636E7B3647B51F3069029054915D6E763C90C2D320EA65D8D1FEFF79028A6552261A93745626DA04ED0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11715" V="0" DC="SM" EN="Office.Outlook.Desktop.OABDownloadThrottledTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="26150" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="true" N="TotalElapsedTime">.. <A T="SUM">.. <S T="1" F="ElapsedTime" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6006
                        Entropy (8bit):3.5879471064362303
                        Encrypted:false
                        SSDEEP:
                        MD5:528E0A4867B30F009233B4832EEA5381
                        SHA1:4280DF2DB38D3934890075BC191C74917FFDA4AA
                        SHA-256:ADDAC979CCD4E4D8679D8731F153363D041ABB2F1E680D87B17E9FDD6396A6CC
                        SHA-512:CE40AB622CF02E6441407A82F0482C0F4D469CD6528F024762D4905F05B148AE4B4F2618BCD0ABB8339B9570B0FE8BE8E2ED4CA4029F4288CE30289E1D8C1E42
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11724" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3805" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168464" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168488" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168465" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="4" F="HRESULT" />.. </L>.. <R>.. <V V="-2147417848" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="5" F="HRESULT" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6006
                        Entropy (8bit):3.5880726682924546
                        Encrypted:false
                        SSDEEP:
                        MD5:FBDA30AB466B37D36748966EFB942BCF
                        SHA1:CF715601FEEB8C90FDCD45E5854FE980F2A35324
                        SHA-256:A58CDF1E1B176D6083E0025D0954FFB2B54A05E650D2A447AA0880D243C61B0D
                        SHA-512:A0D0634510D3C8EB93BF3E91C355F7D6792D895A4E99E53533FAE293F4975634C1184B4F621ED3BE5DED2CD7F10281AC6F70287928A14D07469525BD805906FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11725" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3806" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168464" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168488" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168465" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="4" F="HRESULT" />.. </L>.. <R>.. <V V="-2147417848" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="5" F="HRESULT" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):768
                        Entropy (8bit):5.142151072181204
                        Encrypted:false
                        SSDEEP:
                        MD5:C8EF53FB9365514D0BA47571505FA30F
                        SHA1:2BD8061D934F64F8C4887A436F43D1BE8364BF2E
                        SHA-256:3CF87314ED0D03900FE97DF3794193E01809099B1940D4EECDB609FAA08A8DF2
                        SHA-512:5D2A1A60011F5DE8B1AA244ADC694C2ED437B064B14CC97899C4177F760003A2FE745898BB635C0B9E7B3914082C35C94BE0DF6B58E07463E600231277B1166B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11728" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.SwapTZAndLabelChangeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22420" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22421" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="ButtonClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NumUsersPriLabelChanged">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1506
                        Entropy (8bit):4.6508051674056485
                        Encrypted:false
                        SSDEEP:
                        MD5:D1C1EBD24EB990964498B112B2FE4DAE
                        SHA1:F4A5236731A66C45700C3DF437643D9F3029D7DB
                        SHA-256:4D790BA268912F2EB85A87B547D86E41B1CE2F4148AE4D1CF9736DAFF4FD7F99
                        SHA-512:67849DC18B1DDAD1119ECF3E0A624F630282E1158C78EC7E722D5EF3F4127175C7BCC8EA020BAE18C61FA2CAF9EE4726C9F5F4988649BF91EB09082A6FE6F7C9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11729" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.PresetTimeZoneSelectionUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22422" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="NumTimeZonesSelected" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="NumTimeZonesSelected" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="NumTimeZonesSelected" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_Calendar
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1265
                        Entropy (8bit):5.068838819144208
                        Encrypted:false
                        SSDEEP:
                        MD5:D1D4DC60041DB3C3DEFF8868F0EA993E
                        SHA1:2C601D493D74A0EDFE6EC6C459C03EEA519CC61B
                        SHA-256:2EBE23C74D5E7292D08D7C85B919479D2B398B291263D59CB5F85D488AE59990
                        SHA-512:C5F13979D75907ACA27CBEA9DA5C2584EA61DF37143E2DF942C1D88BB82CC2B442641D92ECC599D7F8D78A7A2A08AA3E12A6C409C8474A9CEB7F3071E916B4FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11730" V="0" DC="SM" EN="Office.Outlook.Desktop.AutoDiscover.AutoDiscoverV2Request" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="615" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ServerResponse" />.. </L>.. <R>.. <V V="{&quot;Protocol&quot;:&quot;SubstrateSearchService&quot;,&quot;Url&quot;:&quot;https://outlook.office365.com/search&quot;}" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ServerResponse" />.. </L>.. <R>.. <V V="{&quot;Protocol&quot;:&quot;SubstrateSearchService&quot;,&quot;Url&quot;:&quot;https://outlook.office365.com/autosuggest&quot;}" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1041
                        Entropy (8bit):4.7259754056208045
                        Encrypted:false
                        SSDEEP:
                        MD5:AD55A15C3A31032E1F253F24462F08E6
                        SHA1:4508BA5918FF6A25874254CEF4771FB7F0DF7364
                        SHA-256:84BD78D7909C7B09950AF25A94EEEB05CBB61738F6F7AE8E37C55B215872D3B0
                        SHA-512:22EA087F80F9E9D8698C8544FC71B1E8FEFAC3F737DD53A3D4E826FA4023F495CEE896E8DC1CBC899B4BE4FE4D0B019FEFA77533B8761EFC8987FB17F02A054F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11731" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.AutoDismissalOptionsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="834" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OptionValue" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OptionValue" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountFeatureTurnedOn">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountFeatureTurnedOff">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1214
                        Entropy (8bit):4.819427131350566
                        Encrypted:false
                        SSDEEP:
                        MD5:9D3E63522F1772BB889670761BA9DE91
                        SHA1:87C232D0FFC059621B6EBC8CEC1D9767CD1BDE5E
                        SHA-256:AF8AD4ADFFDF777BFA4407B5AF2621B662C0095CD902E6924D397E3577E07308
                        SHA-512:7FB1EC96543F09A1A08FB3123BB47737DAED840B981E46DBAC94850D990B1F62C9999837AD5D755246EFBCABDBA9C0CB6DC8437BCA92EA5D6EB91D0D45345416
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11732" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.AutoDismissalUsageStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="835" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsDismissedFromDialog" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsDismissedFromDialog" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountAutoDismissedReminders">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountAutoDismissedRemindersWithoutShowingInUI">.. <C>.. <S T="4" />.. </C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1309
                        Entropy (8bit):4.606942035174418
                        Encrypted:false
                        SSDEEP:
                        MD5:AFC7EB407F1A6F3E1EBE3130C48DE35C
                        SHA1:AD22B1C50F6FE569D51DA045137C300D40E2500B
                        SHA-256:2BC3ED832E96F004181576EB388AE97FAB9D959ECC14C67BF2CB466CFCDBE4FA
                        SHA-512:559056DE12798F63F9E7D958AC20FEF892FE6557361003087B8D86D324BD49635E54D14314DEAA2195A946445CBC75DD0DD8132AABD966B0DBE808D2981FA190
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11738" V="4" DC="SM" EN="Office.Outlook.Desktop.StoreApis.RESTVerb_Execute_Online_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="VerbIdNew" />.. </L>.. <R>.. <V V="1000" T="U64" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="3">.. <F N="CorrelationID" />.. </S>.. <S T="4">.. <F N="CorrelationID" />.. </S>.. </G
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1457
                        Entropy (8bit):4.886477791787648
                        Encrypted:false
                        SSDEEP:
                        MD5:DE34976C9A2929D4B031C0D014ABFDFD
                        SHA1:63B93267B5BA45B68839E2032E0C3DA74B86D03D
                        SHA-256:F83047BAA123BBA21AB0071675BE86FEF1D153A22AAD5553432FF7C5389C6188
                        SHA-512:F027FAF5F6486FA08395AD5A6566842D4C978585CEC7ABE3A1605142EAC28CF342F2209787ACF172722673CB168C72C04FD339A243D5A49C3A57E6F4C379FF80
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11739" V="5" DC="SM" EN="Office.Outlook.Desktop.StoreApis.ContextReliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9005" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="9102" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="9502" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="2">.. <F N="ThreadId" />.. </S>.. <S T="3">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="3" F="StoreType" />.. </C>.. <C T="G" I="1" O="falseNoError" N="CorrelationID">.. <O T="COALESCE">.. <L>.. <S T="1" F="CorrelationId" />.. </L>.. <R>.. <S T="2" F="CorrelationID" />.. </R>.. </O>.. </C>.. <C T="U64" I="2" O="false" N="ApiCtx">.. <O T="BITWISE
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):611
                        Entropy (8bit):5.244867997063719
                        Encrypted:false
                        SSDEEP:
                        MD5:40FFF1935CB1D2EF95AA6B91357CA8F8
                        SHA1:4CD6851EE44FF9901A5DEAE81A3F166A9622F80E
                        SHA-256:352EFA58305CA584148B79DB884A248DA6D305B4EC093E9F0D0CA75E03892C6E
                        SHA-512:EFF5E1EAE53D8ACC77C0F84A37EFF1A97241354CC677FDA2DA6DA5C52F5F14DBE6F97304E7E132FC404D1ED663AAD2011C3B32B18F5D8886A0C9D363A41015DA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11740" V="3" DC="SM" EN="Office.Outlook.Desktop.StoreApis.HelperFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9501" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U64" I="1" O="false" N="ApiMethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="2" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1778
                        Entropy (8bit):4.699554913428993
                        Encrypted:false
                        SSDEEP:
                        MD5:D1D00C4507050D3A4B9EADD59DEE2FFB
                        SHA1:0D6F2186E04C9DEA47A8DF4BAB19ED9DAA265F20
                        SHA-256:281876D911162231BCF60A2513F1A7F5E546DFDFB2CF0ACEC2874F024B318969
                        SHA-512:B18941975C8587CB48EA5B1F6C4FD6869D8BB10800C0AB5D2D47CFB0C5D6B14C57440BE5CD59B9F8D20C11F96CBE7FE4A960513E7163EAE7F6B39817D34C9874
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11741" V="4" DC="SM" EN="Office.Outlook.Desktop.REST.VerbExecutionMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9102" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="9101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="3" I="Hourly" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="SubVerbId" />.. <F N="HRESULT" />.. </S>.. <S T="2">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="SubVerbId" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <O T="COALESCE">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <S T="2" F="StoreType" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="VerbId">.. <O T="COALESCE">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):809
                        Entropy (8bit):4.608239851250772
                        Encrypted:false
                        SSDEEP:
                        MD5:15084E45CFEEA65254FEB0074248C1E5
                        SHA1:262948FF7A1D35944C500D4A203787FD6B9660F2
                        SHA-256:02701EC9B77351E4C629DACD5CB30B49AD0CB005BF43AD4A18E5FB37367F6707
                        SHA-512:674315E1CF42AE73DD60C1CEEDFB88CEDCDB60EE84623EF816FBEC7A11B35735C1C0B01E1BB3304FEA3F47923694A95B76C96E52D903C49E36D988E66545F102
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11749" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9502" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="BITWISEAND">.. <L>.. <S T="1" F="CONTEXT" />.. </L>.. <R>.. <V V="268369920" T="U64" />.. </R>.. </O>.. </C>.. <C T="U64" I="1" O="false">.. <O T="BITWISEAND">.. <L>.. <S T="1" F="CONTEXT" />.. </L>.. <R>.. <V V="65535" T="U64" />.. </R>.. </O>.. </C>.. <C T="U32" I="2" O="false">.. <S T="1" F="SessionType" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="1" F="StoreType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):780
                        Entropy (8bit):4.968177337830356
                        Encrypted:false
                        SSDEEP:
                        MD5:98A42B8306E75462EAC045974B62E73B
                        SHA1:81DB69C2C883B10E4CD254D2292B92ED95A41F6A
                        SHA-256:A9B6FD341229927BE884E096D896159EE8CDFEBBC5DB184C78B4DAADB2866B39
                        SHA-512:35FB5EF795DB0227FA1659F8949A2EAF37A18B7763D5E15F9D064619781A79C8DF5A3F239352AD475AD9E583B6CF632E1779351AA0CF0050E845DC2B0446E3BE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11750" V="4" DC="SM" EN="Office.Outlook.Desktop.StoreApis.Failures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9502" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="2" F="StoreType" />.. </C>.. <C T="U64" I="1" O="false" N="ApiMethodCtx">.. <S T="2" F="CONTEXT" />.. </C>.. <C T="U64" I="2" O="false" N="Failure">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1739
                        Entropy (8bit):4.341665904389952
                        Encrypted:false
                        SSDEEP:
                        MD5:6315D2E3B42D86BF3499DD2FBFFE1E56
                        SHA1:E40A5D909CF00F5801C9470BA8077C219B14DF8D
                        SHA-256:9C4990AF8F8B82A39D7BBB03616577D55ACAAA21BAC88C5546631520F9E988D1
                        SHA-512:2D4D5F145A2F3C417A98A6A662F593F98B6544608A0728867AB805A7626D9459E7C46C79F29C612E6D192BB32397B8067B1E1F9F4F4ACDF9D9DE9DED0B2BDE33
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11751" V="2" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCalendarPermissions_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="33882112" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1735
                        Entropy (8bit):4.335945445005739
                        Encrypted:false
                        SSDEEP:
                        MD5:7A894576292B078BA5E4BE1ED2778CBE
                        SHA1:E674F8B151903D780553840C45DA366B6301871E
                        SHA-256:EACE1A21ED2E51AE953E91B2C184B296D6D61B08515B9D50DD0ABACAC819ADF6
                        SHA-512:A8AA947EC0D051539BDDF77F3A7397D202B3C3D0C15338D35F9C35E817C788E4244FB1D8F305CD03288D2C98951AF8DEB7CB9119EE9A01501168845FAC81E607
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11752" V="2" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCalendarSharing_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="33947648" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1723
                        Entropy (8bit):4.32085691396312
                        Encrypted:false
                        SSDEEP:
                        MD5:C5DB3C4869A47FA352DD250EA2D534B0
                        SHA1:E0DEFAF5BEBA5E175B639BD3691FE8754A58BDE6
                        SHA-256:B3A6C636FD5B4B5C5FF45DE6C9B90564CA56F82226C574FAF6CAC2CFC36FEB6F
                        SHA-512:8D572B435330CECF736C7FCFE03E1D9D8F77499BDF3E4F8672C41F9AF58F118EE01A8BA1577CEB0945B85D0FF6756FD698E3852AF6417B1487F59D688C8417E0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11753" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCommonItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34013184" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1725
                        Entropy (8bit):4.323360675578003
                        Encrypted:false
                        SSDEEP:
                        MD5:BA5FF7F44BB22218C4F7CE77E890FDEF
                        SHA1:E3B8EF7C8B95754F2BCBC48E4FB47D622B0EA7F0
                        SHA-256:5E4C32D81403444C5A847A15FBFC4C1F7372CF11DD6687593BE145F2FCAD024C
                        SHA-512:F92F09F1DF99DFC9737DBBA4158044CB27FD084385B1143284422B75A0B5AE4E43160E77E32CDC1589D4D07051AE03E0D1F04FB9C0F7B89F0620C6584A8319C6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11754" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCalendarItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34078720" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1724
                        Entropy (8bit):4.3225776265618965
                        Encrypted:false
                        SSDEEP:
                        MD5:A2BC2693B1794955DE5EC5813D405B30
                        SHA1:24873043AAF24D58C4B92DB7BAAEA35FECCA5A54
                        SHA-256:AE761A704DB41D57640E063DFAF8D4939BF47B17F42B002F7A87C4DBB10547EF
                        SHA-512:D870ABAE833C5A2E624C7C53939411163D411F7C8995FC239CA9D487A23C5725FCEEF1678A25D8B981AC55CB6FF396C91AEFAD3427CDAC04204CABF93666448C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11755" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiMeetingItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34144256" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1723
                        Entropy (8bit):4.324253382941466
                        Encrypted:false
                        SSDEEP:
                        MD5:32CFCBC0A2F536B6A6B6A3FD822E354F
                        SHA1:DB7B913CE02D733B5BAAB7ABF100D655C8CB55AF
                        SHA-256:FB2F037D6A7A9CE8912FE45F7F1F087E8CE39844F86FF8C60C8A1D9C43DFCEA5
                        SHA-512:C8B8A7E893B8CB1B5576301B7395E4E4AF04C7F1DA3EDAB902116BCED7279F131B9738ABED8ECE3BB31354CBEEE6677DB50EE8D56A38D9B770A1B781F5FE1621
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11756" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiAttachItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34209792" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1723
                        Entropy (8bit):4.321111424743761
                        Encrypted:false
                        SSDEEP:
                        MD5:1CF09EC92E88EE8016078592FA61CE19
                        SHA1:CBC38D75365D7B5D02286C2BBA7A2A28AFB7EE77
                        SHA-256:D310A276E20D7449258D71FB1D4616434BC5966990644C75F5D6F075E398207E
                        SHA-512:7909B5678DBFFD01E54E40725B0DF4FD40D9A9DFBC840342AC4B4BEA302389A91FD9262DA4EF811CA3FCB0A1D6E22EC5CA50F3A7C7A703BE0B22D905AC193C53
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11757" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiRecurrence_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34275328" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1736
                        Entropy (8bit):4.3319136824723925
                        Encrypted:false
                        SSDEEP:
                        MD5:5E0D8FFF11D1C7B692C19C9EBDA87FB7
                        SHA1:4770BAC803C4675D7F904D3528F4AFF806E01CF8
                        SHA-256:C7A89B4954131B0481AAA5F3A782FF50E588853D254699706737DA684D5BBE4A
                        SHA-512:874F87C81885430AD6B53D2AEFEC832B7188804896EC740F250D3391B58144E72ED6B47B289C460346BBA405995D3B3E64F393793A5C859FDF5D299AE134CB29
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11758" V="3" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiFolderCollection_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34340864" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2405
                        Entropy (8bit):5.170990019698884
                        Encrypted:false
                        SSDEEP:
                        MD5:C8FBC084A34D87E2DE868F772CA43C51
                        SHA1:6B7CAEF31754F4A922FA57DDD342420682AAD3F7
                        SHA-256:1B69FEB356AED03E3B34F4872EEFBB727F062BA344E05FD93A5625CF555780B4
                        SHA-512:64C97B3A22F55350E5CF1C4AA25952B018213E1944A1CDDFBEE9E115956E84217950FF18299CDBC305FCD2A1BA29EEF6FA9A1B6CC72809A86C950F0B02ACE330
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11759" V="0" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AzureActiveDirectoryZeroConfigExchange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="498" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="496" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="497" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="499" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I64" I="0" O="false" N="AddressDiscoveryHRESULT">.. <S T="4" F="HResult" />.. </C>.. <C T="I64" I="1" O="false" N="AddressDiscoveryTaskHRESULT">.. <S T="4" F="TaskHResult" />.. </C>.. <C T="B" I="2" O="false" N="FullNameRetrieved">.. <S T="4" F="FullNameRetrieved" />.. </C>.. <C T="B" I="3" O="false" N="PrimarySmtpRetrieved">.. <S T="4" F="PrimarySmtpRetrieved" />.. </C>.. <C T="B" I="4" O="false" N="UserPrin
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2649
                        Entropy (8bit):3.802109708779993
                        Encrypted:false
                        SSDEEP:
                        MD5:B566F6C2DA0CF8CB9E711C9588F76ACE
                        SHA1:61A26EE38863A45186779F55F779B6C1FDB66069
                        SHA-256:B41138BA164326EA1A2F2D7C8DDE4182FA69AC9687D7ABBB6502236FA1F8577F
                        SHA-512:1225F1FE1C4D1851CF3EE75D2EEC78588EBC33BAAE58FBCE55A5BF65C9D049E70B413E49AD40D89FB130D4E0ADF3F4056CBE8709E7E320BC0E573AB109903E06
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11767" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmz0a" />.. <UTS T="2" Id="bmz0b" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="RequestSuccess" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="HttpStatus" />.. </L>.. <R>.. <V V="401" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="HttpStatus" />.. </L>.. <R>.. <V V="403" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="HttpStatus" />.. </L>.. <R>.. <V V="404" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="2"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2153
                        Entropy (8bit):3.605188552555672
                        Encrypted:false
                        SSDEEP:
                        MD5:867D74FB75E911F06808693D549FC57A
                        SHA1:E803911A4E5CB8016973839CFFDDB18E51998C3D
                        SHA-256:2648C260B56EEABD9ACB4AEFE1501700712180A0517781D5F30FA0C46F1E7960
                        SHA-512:8E4EC68AA57ADB1881CF1EF5A652E9B3FF3F7BE95E911CC3192676B87A854FC9CD4D97EE2B9BE98C255E7852E56CD623C638E53F20EEA48D39F58B7B2AE36C61
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11768" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11767" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="2">.. <F N="0" />.. <F N="1" />.. </S>.. <S T="3">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="W" I="0" O="true">.. <S T="2" F="1" />.. </C>.. <C T="U32" I="1" O="true">.. <O T="ADD">.. <L>.. <A T="MAX">.. <S T="2" F="3" />.. </A>.. </L>.. <R>.. <A T="MAX">.. <S T="3" F="3" />.. </A>.. </R>.. </O>.. </C>.. <C T="U32" I="2" O="true">.. <O T="ADD">.. <L>.. <A T="MAX">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2798
                        Entropy (8bit):4.187029908716092
                        Encrypted:false
                        SSDEEP:
                        MD5:651E78EAD579D2DC36429D12024DE5C2
                        SHA1:E27CBE0E5DADB0485382F0301415994EDC7A5A77
                        SHA-256:26BCA3417BC3B40E8EFCCC69433E5EAEF09018D90D6719FE1ECAE6AF5923F1DC
                        SHA-512:25898DAD0AC61D507A8A36C8246CB9C3E58469C4D0A547AC57FBDA738BD840B495FD57880B24730A1D5C102B8706D67061AB2629C06B6140C7821DFDB94848CD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11769" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxAndOsfHttpStatus" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11768" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GE">.. <L>.. <S T="5" F="2" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="GE">.. <L>.. <S T="5" F="3" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4634
                        Entropy (8bit):4.601125821968251
                        Encrypted:false
                        SSDEEP:
                        MD5:07D1624FEEC8E1CBC56C4805F2CFC1AF
                        SHA1:8E2C491B2D4BAFF981B8952110F8683B3EB815AD
                        SHA-256:225EDF6F7FDEDC1FF49C540A2435D033F1253BC25B31E808C3E4DB4ABC33D9EB
                        SHA-512:883B3B426AFDF05B8DF2AAE1F6BECCECA1EBA9A0032BAE5D10A0D39A939B17779DD362E4D9045E6BD874FDACF4682BE7C770DE6827FFBE3C39F940525B7477D4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11770" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchResultsReturned" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cu5of" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="TotalResultsFound" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="LE">.. <L>.. <S T="1" F="TotalResultsFound" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="GE">.. <L>.. <S T="1" F="UnfinishedSources" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </R>.. </O>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7262
                        Entropy (8bit):4.292942473815119
                        Encrypted:false
                        SSDEEP:
                        MD5:E92DB98E314911DA51E04EFA313C4DC6
                        SHA1:25A1988C58C2273ABFFE9D8039529370102BCD29
                        SHA-256:678AA0A18F44A65DA8B857B58BD45E8A69D0B8026287A25C7BFF5DBC7866352F
                        SHA-512:3E5588B7D2F6547CCBD5366099D512292F6ECE837C9BD109CF9BB617785EE5287A179EB9CED2E601CA853545E4270AB92CAAB786F95C4912BA829668B7804CFD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11771" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSuggestionsSessions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cwfnj" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="SelectionMade" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="StringLength" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="StringLength" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="StringLength" />.. </L>.. <R>.. <V V="2
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2056
                        Entropy (8bit):5.023105490945167
                        Encrypted:false
                        SSDEEP:
                        MD5:4D14F934141F4077B282BF260D0EAB55
                        SHA1:D0F8F0A72F206B66AB9B82AE56324B771D9DA911
                        SHA-256:DE8BB531EB4A058C8B379E9EC804795B1A71F30FC345F60E085ACDF6C574D913
                        SHA-512:EDCF47EAAB59889250F8D74CFFB5C466F334BD5EF0B0DD5D935E470B4BE58DE5A20CED3B390B9A1523ACC6D435F416DD537A82E42AB8DBB55811CB0AF1DFFCEA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11772" V="0" DC="SM" EN="Office.Outlook.Desktop.Diagnostics.System.GetDiagnostics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="733" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="732" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="734" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="735" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="ControlName" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="ControlName" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="ClosedView">.. <S T="1" F="CollectDiagnosticView" />.. </C>.. <C T="I64
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):771
                        Entropy (8bit):5.261592979598644
                        Encrypted:false
                        SSDEEP:
                        MD5:2115913299B74CA91CEA081B8D4DE545
                        SHA1:71B5ABC026BDE0EC732B9ADBE7C1EF15F15CC4B8
                        SHA-256:2C244A915753832973743C436A927356B8BCFED5FF707BD02039C9FB798B3214
                        SHA-512:2BFAE2B49A1E697760AC66849973573D6850ABD61CF6A7FC8C58C437EAF31BC2DDA6752581B864A7AE6D5BE250D635F5935A3EEA6D0020BD6F2B7D284987C0C6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11773" V="0" DC="SM" EN="Office.Outlook.Desktop.Diagnostics.System.GetDiagnosticsCompressFiles" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="736" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I64" I="0" O="false" N="HResultFilesCompressed">.. <S T="1" F="HRESULT" />.. </C>.. <C T="W" I="1" O="true" N="CompressedArchive">.. <S T="1" F="CompressedArchive" />.. </C>.. <C T="I32" I="2" O="false" N="FilesCompressed">.. <S T="1" F="FilesCompressed" />.. </C>.. <C T="U64" I="3" O="false" N="CompressedArchiveSize">.. <S T="1" F="CompressedArchiveSize" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):443
                        Entropy (8bit):5.339981847676649
                        Encrypted:false
                        SSDEEP:
                        MD5:850FDECBAC8158CEE24945F63A6DDD45
                        SHA1:E42EB9F1D198EC6956F3528CEF7FABA1EB301854
                        SHA-256:C19E688D0EB3AE9E92179A6EDD461539E1CA41E41C3BE34264F5F82A3E70A567
                        SHA-512:DC4B2D302410F5D22618EEA5D1F6934D7408B41AAE237AD8C898059CC42EB186B1F00E5ADCA66BFD0923628535CFCB544EC5CAD15EF6532062B54D1A087B784A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11775" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ArrangementMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13032" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ArrangeType">.. <S T="1" F="ArrangeType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1438
                        Entropy (8bit):5.289843595247927
                        Encrypted:false
                        SSDEEP:
                        MD5:FACCAD5A993E27229A39BA717674AEBA
                        SHA1:1D21C7CCF5653F87FD7F165E346CC506B47DDBA1
                        SHA-256:AFC69B98314A876669ED3B64814493886E27AFC06C69152DED5EB3E9D6612217
                        SHA-512:33C2E882720D7EBFC33B369771ADF224EF79A9C61C5C875726ACB885912EEC67759EFAFF6B1D762AF47D1E53A372DA61474F6B2EB8B83B4B74F7D492D47A5EE6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11780" V="1" DC="SM" EN="Office.Outlook.Desktop.InAppContactSupport.InitialScreenshot" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="739" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="740" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="741" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="742" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="743" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="744" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="true" N="ScreenshotCaptureHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="1" O="true" N="ThumbnailGenerationHRESULT">.. <S T="2" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="true" N="ReconInvokedScreenCapturingHRESULT">.. <S T="3" F="HRESULT" />.. </C>.. <C T="U64" I="3" O=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):452
                        Entropy (8bit):5.345561286329968
                        Encrypted:false
                        SSDEEP:
                        MD5:F6109E54AB82FED091808C53481C9435
                        SHA1:120F3E2AB578397FE0D13BBB770B7005A00B32E2
                        SHA-256:943AD6C16AEEFC5C3C36C945345CAC190595D4CFE18C29B24D3B9CC9D6C62783
                        SHA-512:56F69C1A2E51DD195339A772252D4EF292EECE06731125AEA0B892BCDFA4195DA1E1A0861E73F18B83643DE0057371EBF47E4E719B3AEE43E8099F06A6A13B27
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11783" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchQueryScopeAndGetterType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7002" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="GetterTypeString">.. <S T="1" F="GetterTypeStr" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1011
                        Entropy (8bit):5.004524873937057
                        Encrypted:false
                        SSDEEP:
                        MD5:173069DDF69BC9E19FCC2FB5098BD6C7
                        SHA1:551513B350D04F803607A7EBC3A409E5BCD707E4
                        SHA-256:DB85ACB517242F2E174857BD665CE5119F8CEB60BA11442C2D1D46ADC4A8967C
                        SHA-512:F96F7CA74DC9A6600A19454410130A32472FB18DA3B1FB99B427F11CA1BB6F018FBD769008D82CD711BB699FE1FCEDD2109C1B64F320C1ADFCDE85F213047871
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11787" V="0" DC="SM" EN="Office.Outlook.Desktop.Store.RestVerbFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="StoreType" />.. <F N="SessionType" />.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U32" I="1" O="false" N="SessionType">.. <S T="1" F="SessionType" />.. </C>.. <C T="U64" I="2" O="false" N="MethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="3" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="4" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):796
                        Entropy (8bit):5.1074346506122446
                        Encrypted:false
                        SSDEEP:
                        MD5:6E2AC6E60ABAD69D35216E20CBD87B17
                        SHA1:5C1332B702F222A951845CBE0FDBAAE6C839F6A6
                        SHA-256:02B2D53D5EE5C083C102BC996C1883C225992729FA0304C64DC87390ADF967FB
                        SHA-512:30B7EFDD7B8B41CBBAAE785BC26DE5D5531FF9C7F341CD157BC773D8FB77C7BCD0B2A9521CD7773879D7C5B7DAED7218A60E7A6643E8FC8B3140D5F93A594744
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11788" V="0" DC="SM" EN="Office.Outlook.Desktop.Store.RestVerbConvertHelperFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9003" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="MethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="1" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):790
                        Entropy (8bit):5.096313992996928
                        Encrypted:false
                        SSDEEP:
                        MD5:45DE7F16841201DD4C31F6C4D7D3FC68
                        SHA1:9E018C9EFB512E4FE33A3A2AC0348C74AC8159F8
                        SHA-256:79CFBBF31162CBF95AC41EAD2671210217759C91B4918D2723125C337DD330B6
                        SHA-512:7C0524CB526F0B4E38163B3A22F2F73C6CDF9EC5F2EA53F18E9C20C178338EDA8790F3D06F3E23C13093410E9F9D67EA6D8A5254ED7CF812BA94C2FC4AEE546D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11789" V="0" DC="SM" EN="Office.Outlook.Desktop.Store.RestVerbConvertFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9004" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="MethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="1" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1033
                        Entropy (8bit):5.318046582182046
                        Encrypted:false
                        SSDEEP:
                        MD5:51946DC35ED3BF5C6A318D148D73094D
                        SHA1:0B3C9276E177AEB97C3C855F2162558E875497AF
                        SHA-256:330FFD3951C9EBA271853EC5EDD736D1E6C5D8D369C7EC280A92E670DDD49DF6
                        SHA-512:A380BB78BB9811076830EB7C9319B909B05B9B719AC4EF0F0E4EE90B1E68EFA72D6A65AC217C2E5502E4F983100CDD019C8D62014CA3AD6E41CDD86078F188B1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11790" V="1" DC="SM" EN="Office.Outlook.Desktop.FeedbackPane.InitialScreenshot" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="753" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="754" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="755" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="true" N="FeedbackInvokedScreenCapturingHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="1" O="true" N="FeedbackEmbeddedThumbnailHRESULT">.. <S T="2" F="HRESULT" />.. </C>.. <C T="B" I="2" O="true" N="UserCheckedIncludeScreenshotBox">.. <S T="3" F="UserCheckedIncludeScreenshotBox" />.. </C>.. <C T="B" I="3" O="true" N="AddedDataCollector">.. <S T="3" F="ResolvedLoggingLocation" />.. </C>.. <C T="W" I="4" O="true" N="OutlookSession">.. <S T="3" F="OutlookSession" />.. </C>.. <T>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):7022
                        Entropy (8bit):3.789256707640678
                        Encrypted:false
                        SSDEEP:
                        MD5:E847D7DF616B3A0E027DE6EB8E6FF235
                        SHA1:8EC93455D7C15AB5F896CB730E39F9B752F41313
                        SHA-256:E2564AB6A484A9753453B93E173844D3FF3CE794BF3A28F39557CDBED1E2223E
                        SHA-512:AB46DC4E28905E04036D72CD1C26B7D9FE24605A66F388A9954F201662A6CD0A62C470836E0A5C451A4CC8B7A597FE8526AE1E6CF1A2509250C53BA751C39E56
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11792" V="1" DC="SM" EN="Office.Outlook.Desktop.PeopleSuggestionsDisplayTimes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="cwfnh" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsFirstInSession" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LT">.. <L>.. <S T="4" F="ElapsedMsForSession" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="4" F="ElapsedMsForSession" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1217
                        Entropy (8bit):4.65026027684882
                        Encrypted:false
                        SSDEEP:
                        MD5:DA668269FEE0A29C7ECCDE1A0358FB99
                        SHA1:DE01DCF29DF053044E4DE5B30AA623AA8F8DA6C5
                        SHA-256:C7F732A8FA1233F261CEC481AB65B93456EE6D9B55B2956E728BEC4A8DBDE070
                        SHA-512:6C3AA373E3AFB4ABF2CF3A5BDA35C3C03CF010C515061591175442ED76ACFF51DBFD8A823EDF7050BFC80FA8508749BBF20E4C8EE6FBD63A7AE18AFF11BC5D3D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11793" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSuggestionsSearchStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cwfni" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="Suggestions" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Suggestions" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountSearches">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountSearchesWithSuggestions">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountSearchesWithoutSuggestions">.. <C>.. <S T="5" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1382
                        Entropy (8bit):3.6365736385425627
                        Encrypted:false
                        SSDEEP:
                        MD5:E52549C1D1538EDCA8579CBD6609F2EB
                        SHA1:CF9C6D726FC627F576C026F782A09E98FB390502
                        SHA-256:4DE0A3F26DE982FD5930E5F250B545EF928F7D3C63B542E582D287BBD1A57AC2
                        SHA-512:73447D460ACC793630EE22095729CB6E6F34B94455417D52FBC02E030091F1BD7D1D8BCF106D07D2259B7CF443CCBA1E3CA7195C74659FBCFF81FDBB89559DF9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11794" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="by7xb" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="valueName" />.. </L>.. <R>.. <V V="DefaultIMApp" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="data" />.. </L>.. <R>.. <V V="Communicator" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="data" />.. </L>.. <R>.. <V V="Lync" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="data" />.. </L>.. <R>.. <V V="Teams" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="data" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3286
                        Entropy (8bit):5.129492498358063
                        Encrypted:false
                        SSDEEP:
                        MD5:5BCF913C003837AC915DCBCA2F2BCB02
                        SHA1:4F7C2C00A5296F54B42AD5F9C477D1813786706E
                        SHA-256:B0ADBAB65A26317E44D515FF7A7883F6BBF001546A3F29C18B1836DA4DF7F7E3
                        SHA-512:83B6D45BEFA2962AF566EAC1940DA3B3C9618985D19DE70B1B0DB6791DBA80F1A4B86FAB84C2C112548775B1134E1311D68EA41F799B90C6327F115198180DDA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11796" V="3" DC="SM" EN="Office.Outlook.Desktop.Diagnostics.System.WatsonCrashDeflectionsOnBootNovFork" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="396" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="500" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="503" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="506" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="507" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="508" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="IsCrashTypeSet" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I64" I="0" O="true" N="BootComponentSuccessHRESULT">.. <S T="1" F="HRESULT" />.. </C
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1685
                        Entropy (8bit):4.6711415976317605
                        Encrypted:false
                        SSDEEP:
                        MD5:9C87C252D62194564E5282B647D4E8DC
                        SHA1:6E26567F8EE04F5A971F3BF181CC0E3BA4F61CE3
                        SHA-256:557426E09B2B48FBE1EDCF3990750AF01D732AAA7B338BF72324DA438382A47B
                        SHA-512:51BF122E94DC1102B1AC0A37480F3C660D6E36E4C6186CDD3836E87E6DDFEA5BBFD3D32E07A6836026B07E87EFF0022AA7CCB16CFA98ADA7AFE3D48C822B8A21
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11798" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1605" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="cbRequested" />.. </L>.. <R>.. <S T="1" F="ulStreamSize" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="ConnID" />.. </C>.. <C T="U32" I="2" O="false">.. <S T="1" F="ec" />.. </C>.. <C T="B" I="3" O="false">.. <S T="1" F="fReadCacheEnabled" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="1" F="ServerConnectionType" />.. </C>.. <C T="B" I="5" O="false">.. <S T="1" F="fPackedCompressedEnabled" />.. </C>.. <C T="B" I="6" O="false">.. <S T="1" F="fAllowLargeBuffers" />.. </C>.. <C T="B" I="7" O="false">.. <S T="1" F="fReadCacheV2Enabled" />.. </C>.. <C T="U32" I="8" O="false">.. <S T="1" F="m_cbReadAheadBufSize" />.. </C>.. <C T="U32" I="9" O="f
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2030
                        Entropy (8bit):4.619617140501037
                        Encrypted:false
                        SSDEEP:
                        MD5:97D4B23FE5BFDE7ACB9CA5BCDDDA1514
                        SHA1:C4B7A692ED41BE5EAA77DB65E364468537CCA742
                        SHA-256:1CE34C2820D786F08BDB985A06858965BCC22F92790C039D77817FE177BA04D3
                        SHA-512:177110DCBDE5AFC76F68B73AF44BF9C0540F727B645A64915279254B3270C1B64CEC2BB226F4836815595BA010821C43B2C54E0B50F5B93BFBEC447A54A61C30
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11799" V="0" DC="SM" EN="Office.Outlook.Desktop.StreamObjReadSummaryStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11798" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="3" />.. <F N="4" />.. <F N="5" />.. <F N="6" />.. <F N="7" />.. </S>.. <S T="2">.. <F N="0" />.. <F N="3" />.. <F N="4" />.. <F N="5" />.. <F N="6" />.. <F N="7" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsPartialRead">.. <S T="1" F="0" />.. </C>.. <C T="B" I="1" O="false" N="FReadCacheEnabled">.. <S T="1" F="3" />.. </C>.. <C T="U32" I="2" O="false" N="ServerConnect
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):796
                        Entropy (8bit):5.179220776086826
                        Encrypted:false
                        SSDEEP:
                        MD5:88FDD5C4E51211380CBD8336C6A30F0E
                        SHA1:C5E5342F6CF3376E26735D96B010D921F0C2D3CE
                        SHA-256:FEC051E42DEDAD8B3414D57A8EDF46F3C5E2C954A059976BFB74335E3C17F71D
                        SHA-512:35592F6593A84917E548A0F36781D0339258BF7BC1A2E3B5542AB0D481FAA75208E8C5D6BA322E17E1D77C383CD34EA0DFB0B4BC77D824C0990514E18453B3A9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11800" V="0" DC="SM" EN="Office.Outlook.Desktop.StreamObjReadCacheV2Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1606" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="1607" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountReadCacheV2AppendBufferFailed">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountCursorPosNotMappedInRopBufferDataChain">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):555
                        Entropy (8bit):5.333822079764966
                        Encrypted:false
                        SSDEEP:
                        MD5:5E1779D526A22FF145F58546B465F0EB
                        SHA1:9E6C8E8FAD365FBBAFFE7DAA3C03C713CB40B210
                        SHA-256:8DF184C50A95DD4E729907F91B570517C391C1BAF66994B7E81840E167ADFE45
                        SHA-512:DBD1A7C55F856A9AD4788BAB2C99690369A11A1CA9FBC799FED0731F014D0CEA266251F71D9D2A67E3E952A11E16B4DCA6641DE8F01FC09A2B0027BA7EFE4AFC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11801" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.FuzzyMatchShownTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="7148" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="ReferenceId">.. <S T="1" F="ReferenceId" />.. </C>.. <C T="I64" I="1" O="false" N="DisplayedDurationMillis">.. <S T="1" F="DisplayedDurationMillis" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):826
                        Entropy (8bit):5.185561178399846
                        Encrypted:false
                        SSDEEP:
                        MD5:39CF88120D3975C11207DF00F42BA0A5
                        SHA1:0C4F1C3E584ECBAD159BA4ADF137FD559D077A03
                        SHA-256:4C05FCCA6E1AC1EEF9ACED796EA9837D267FC7806DFE461CDCA6902CB66360E9
                        SHA-512:65796D017E619D55AB7F0B4388831C41E1E0C47093C2DF7868920965A2ACF466B754A35F308986A7C1FD9FBAB5C121885EFAA3F6106DE6239E05F672159502E7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11805" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.FailedToConnect" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="2077" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreLogonHelperID">.. <S T="1" F="StoreLogonHelperID" />.. </C>.. <C T="U32" I="1" O="false" N="CurrentState">.. <S T="1" F="CurrentState" />.. </C>.. <C T="U64" I="2" O="false" N="ResultErrorCode">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="3" O="false" N="GlobalError">.. <S T="1" F="GlobalError" />.. </C>.. <C T="U32" I="4" O="false" N="CountOfRunAutoD">.. <S T="1" F="CountOfRunAutoD" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):918
                        Entropy (8bit):5.181172050807619
                        Encrypted:false
                        SSDEEP:
                        MD5:D009139DEE8226683804CBF72295916C
                        SHA1:D2FCF20E4975DC680FCBB333A4BAB5DECFB33AA0
                        SHA-256:67C81689BE24B85BCC6570EE826038F2C240EFAED56B2B8BD51520370CD6B7A1
                        SHA-512:2A61BDD8BB9313FDC3DD4DB8BBA68EB9751F8B1F9F5956C2EDB6B651F1CBC470208B62E789F074BE47A3B396C62C7232BAE363E654FB7368C97A40B00B024EF1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11806" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.RunAutoDAsync" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2075" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreLogonHelperID">.. <S T="1" F="StoreLogonHelperID" />.. </C>.. <C T="U32" I="1" O="false" N="CurrentState">.. <S T="1" F="CurrentState" />.. </C>.. <C T="U64" I="2" O="false" N="ResultErrorCode">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="3" O="false" N="GlobalError">.. <S T="1" F="GlobalError" />.. </C>.. <C T="U32" I="4" O="false" N="CountOfRunAutoD">.. <S T="1" F="RunAutodiscover" />.. </C>.. <C T="B" I="5" O="false" N="IsFireAndForget">.. <S T="1" F="IsFireAndForget" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1301
                        Entropy (8bit):5.176058544002295
                        Encrypted:false
                        SSDEEP:
                        MD5:812DC9CC1AC86317CCCE49A30A467CE1
                        SHA1:02EBA0A3C875D80A4A80D36B02559117546FFBDC
                        SHA-256:704422399B852A02C3E8C1E923010A92507F6E612A379991F856E96F2AB7E977
                        SHA-512:A623A1A54FF6D16D22754CA25E2EEE4D5E247501AB6091054B3DE5D8E0BF2CCBA070E8F025225B0F8DF857A4C9EA3C0A541F71BE68B19B1E80D4F272E5276519
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11807" V="1" DC="SM" EN="Office.Outlook.Desktop.CalendarEndEarlyByDefault" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="906" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="907" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="DefaultDuration">.. <S T="1" F="DefaultDuration" />.. </C>.. <C T="B" I="1" O="false" N="EndEventsEarly">.. <S T="1" F="EndEventsEarly" />.. </C>.. <C T="B" I="2" O="false" N="EndEventsEarlyGP">.. <S T="1" F="EndEventsEarlyGP" />.. </C>.. <C T="U32" I="3" O="false" N="EndEarlyShortDuration">.. <S T="1" F="EndEarlyShort" />.. </C>.. <C T="B" I="4" O="false" N="EndEarlyShortGP">.. <S T="1" F="EndEarlyShortGP" />.. </C>.. <C T="U32" I="5" O="false" N="EndEarlyLongDuration">.. <S T="1" F="EndEarlyLong" />.. </C>.. <C T="B" I="6" O="false" N="EndEarly
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):565
                        Entropy (8bit):5.284114766191096
                        Encrypted:false
                        SSDEEP:
                        MD5:5B1C85AC89EF3080CEE22941979E72AE
                        SHA1:8E4FD87B4700C4CB276BD039944987F2D5C9BFCA
                        SHA-256:ED98A72360BEE7E07959D69B58DF70474084285B26FBE3A13A122F23482DE81A
                        SHA-512:0449202951BE449AD2A923555951D6632295D09700450BB037744367B15F8A6F4BEB6049D0B3C0D8DE4289DFDD20823F9FFD1116CA6164AE5D4C90302375E140
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11809" V="0" DC="SM" EN="Office.Outlook.Desktop.ReadingPaneSelectItem" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6218" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="ReadingPaneSelectItemOption">.. <S T="1" F="fReadingPaneSelectItemOption" />.. </C>.. <C T="B" I="1" O="false" N="FromReadingPane">.. <S T="1" F="fFromReadingPane" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3122
                        Entropy (8bit):4.385421737557271
                        Encrypted:false
                        SSDEEP:
                        MD5:9C7CEAF0E51F5D30EB90560B123EA71F
                        SHA1:C069C542C27593C5D2F8F03B427CBFD43E893B40
                        SHA-256:38D76229BC5756C5299FB9B9B903D44C828502F29C96A34667C7F63F7D8DADA7
                        SHA-512:2C69494AEBB667D84A52916AA5F28BD921F990FF8486716B17A292E27E9FDFA0276AB6ECA25CF905D225CE85A306B1DD9ED8B26760E05F42847E5EC42536FC5A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11810" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.AutoDismissImpactStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="834" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="837" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="RemindersDisplayedCount" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="RemindersDisplayedCount" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="RemindersDisplayedCount" />.. </L>.. <R>.. <V V="3" T="U32" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3245
                        Entropy (8bit):4.267958950605029
                        Encrypted:false
                        SSDEEP:
                        MD5:8AA67F3543B9544084593C1118267ECC
                        SHA1:E5B529FB90A98A35A3D193FD46F4FDE808BE99BF
                        SHA-256:9293665B2265EECC0ABC5223A1D4A68222C34E89BB6181EAAB2223D53DF925EF
                        SHA-512:D14428D5FFA99AA7690CC63A8BD28F02B742BF040A14437403DE9BE449D97C5E55EE0251203386696D6113B45D4464603B7623D88061EE0FAA1CE23A998B6D59
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11812" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.ReminderSourceStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="838" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="839" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SourceMessageClass" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SourceMessageClass" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SourceMessageClass" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1463
                        Entropy (8bit):4.90533255035527
                        Encrypted:false
                        SSDEEP:
                        MD5:002F4E2FB6CC9E35EFC663364AD9C5CA
                        SHA1:F73E656BB342C1AE63BF2C3A2D1FA4F7707B4F91
                        SHA-256:082DA1A833535AD8FB44846CE559CB17170F2D58AA2D7DA4BD5B10A5DE203D70
                        SHA-512:B888B47ECBE626FDDC9349ADFB1F1FA0E70C4CF177CDE5C4AD68689A04BD9015ECBA3D5CEC6BF4DF22C845CA5567598709517CEA975803C6B1E5B989DFFD670D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11813" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchSuggestionHitHighlighting" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7152" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7153" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7154" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SuggestionType" />.. </S>.. <S T="2">.. <F N="SuggestionType" />.. </S>.. <S T="3">.. <F N="SuggestionType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SuggestionType">.. <O T="COALESCE">.. <L>.. <S T="1" F="SuggestionType" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="2" F="SuggestionType" />.. </L>.. <R>.. <S T="3" F="Sug
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1398
                        Entropy (8bit):4.729629546757337
                        Encrypted:false
                        SSDEEP:
                        MD5:0CD366528765FE78F5BBBB844C881910
                        SHA1:CFA4E6042D922CCB6C30E01BD17AEE5B435BAACA
                        SHA-256:4A80852B3C97D86EBDF909A16AABFCAC5A8401B675CF753C5D7B15DEC359CDCF
                        SHA-512:A51A8AE8DF6F3695C6A69892F2F7A80FBFD3D496511C6787E004157B22A6922EDB8AEB123928E3DF41016144C6BB96A5F561470DE7C3A9E0ED09449D92B15432
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11815" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBar.MobileBanner" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3742" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="3743" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsInDraftsFolder" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):710
                        Entropy (8bit):5.182305722031781
                        Encrypted:false
                        SSDEEP:
                        MD5:B0AD21C9DE626670E7ACBC468441F66E
                        SHA1:858AE494032CC8DA3CE1EB6952BCEA6AE975C70B
                        SHA-256:D67DFCE8004A25FD56F31924B4A23A6367597B558F92386D6C6A38BA892B7F86
                        SHA-512:EF927288943CCAAE7FC7A26998E139E633E947A603FCAAF06F159E4B97DB81150B82B13E43F49C1E5B935B016C28A5405CE0EB3AE822ED3CFF123EDC9E083445
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11816" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBar.MobileBanner.Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3743" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="MobileBannerClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MobileBannerClickHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):824
                        Entropy (8bit):5.12526187702441
                        Encrypted:false
                        SSDEEP:
                        MD5:F56D9EB86EDD57B410CBB4558A7EB876
                        SHA1:8CB3E55AD2789F5CE938927A13038587D3865533
                        SHA-256:FE90D2F8AA5694150B38C1F27A037C77A961E5917290F0D8E4AED13D0DA20E9B
                        SHA-512:A5028DF737C17232BCCD75BC65DD6475813B5CC1F87C19608BCAEDD93D06972DC9C6B80856C7CCFE1D3642FEE30D0EF09553BD769B89FA88AA1155F1770A4CEA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11818" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroupIncapable" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19037" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="IsOwner" />.. <F N="Incapability" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="IncapabilityType">.. <S T="1" F="Incapability" />.. </C>.. <C T="U32" I="1" O="false" N="SumOfMessages">.. <A T="SUM">.. <S T="1" F="CountOfMsg" />.. </A>.. </C>.. <C T="B" I="2" O="false" N="IsOwner">.. <S T="1" F="IsOwner" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1254
                        Entropy (8bit):4.653039335917695
                        Encrypted:false
                        SSDEEP:
                        MD5:ACF7A36B03765D036F25EA097180D5FB
                        SHA1:D2F9E4ACDBB2B077A4E41131B7EA9726E675F23F
                        SHA-256:04C93B67B26D286E4962DF8A717BDE9609CFA9D10E0ACA97B78B11FE0C2AEB25
                        SHA-512:87F6342C20BC2448835DAF2514B9E8DAA6D00D5C33396542721632A47C8673F07AC46BE933ABC6BB98F6DB712E5706475E101A11B9C5C9AA0CAD68C42092EB3E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11819" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroupUndo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19038" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="IsOwner" />.. </S>.. <S T="4">.. <F N="IsOwner" />.. </S>.. <S T="5">.. <F N="IsOwner" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="UndoCopy">.. <A T="SUM">.. <S T="4" F="CountOfMsg" />.. </A>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):456
                        Entropy (8bit):5.282923398064508
                        Encrypted:false
                        SSDEEP:
                        MD5:20733B1AF7963B7EAFC57B6ADAD5CBD3
                        SHA1:3956A0DEA8FC0BE9DE0EFF1BC842580A5B28C965
                        SHA-256:30E0400FA94DBCA73ED5BF4E287911B1FA74A113AA85889B85395238E2925C08
                        SHA-512:FBBBC22A5CDD01BC0E8871AB9D97774550E6EDE5BE4FB67272619E1A421AAA68C2E7959BE0D06C7A209876F749C1C38F6F3A1E0B39DE5EF6488AD798862BB0F8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11820" V="0" DC="SM" EN="Office.Outlook.Desktop.SelectedItemLocation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19042" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="SelectedItemLocation">.. <S T="1" F="SelectedItemLocation" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):705
                        Entropy (8bit):5.196671366165347
                        Encrypted:false
                        SSDEEP:
                        MD5:B861265CFBEF37D04D046F31640CA901
                        SHA1:64FC738C698FF72F6722076632A172B3F119AEC8
                        SHA-256:8E561AAE2AFB2540B3CB54265EDEC790B9849DB89814FAE736EA212FE059789F
                        SHA-512:269442FDCE90E58595ECCF42793FF4913C5D86616BC9B89A0AADC3A6E227B528EBDA2CCF3D479D57FA1B77257DE1388A1F34A9F01685136DBB05203507379122
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11821" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageBodyFocusChanged" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="FocusGained">.. <S T="1" F="FocusGained" />.. </C>.. <C T="B" I="1" O="false" N="PreviewPane">.. <S T="1" F="PreviewPane" />.. </C>.. <C T="B" I="2" O="false" N="ReadOnlyCanvas">.. <S T="1" F="ReadOnlyCanvas" />.. </C>.. <C T="G" I="3" O="false" N="CorrelationID">.. <S T="1" F="CorrelationId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1751
                        Entropy (8bit):5.198686726421675
                        Encrypted:false
                        SSDEEP:
                        MD5:10D59D386F2D2F970902C47A4F20E183
                        SHA1:6EBE85A63D27919A0BC776684E019D2C0D695362
                        SHA-256:75B9CDBE1E76D0A6904452D8DFA9A2CBA7446EB865BF3F4A46CA72F2065E07A6
                        SHA-512:5E5923DAC1A1A0B47751101E653528D08F45DACA463426EE69FE5B950F22A8F80ED68AAEF6BBB174A5CF45EABA9C59931EAFA6C97AAF9905BE63A67E6903DAA7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11822" V="0" DC="SM" EN="Office.Outlook.Desktop.InAppContactSupport.RecoveryUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="30" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="701" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="702" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="42" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="4" E="45" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="5" E="46" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="6" E="47" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. </S>.. <C T="W" I="0" O="true" N="RecoveryName">.. <S T="5" F="RecoveryName" />.. </C>.. <C T="U32" I="1" O="true" N="Invoker">.. <S T="5" F="Invoker" />.. </C>.. <C T="U32" I="2" O="true" N="RecoveryTask_PrecheckStatus">.. <S T="1" F="Status" />.. </C>.. <C T="U64" I="3" O="true" N="RecoveryTask_PrecheckHResult">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5467
                        Entropy (8bit):4.320907975816982
                        Encrypted:false
                        SSDEEP:
                        MD5:46BD397F3E5353D704F945C50E58E0F7
                        SHA1:3A3BEE0CE58B33D491AE7F763D90376BD25ACF89
                        SHA-256:E705E97CA24B93C3B32AB76F587EEE6A1CD1F0A4D1B293A2D1D45A802601AEEA
                        SHA-512:9C53735DABF11BE70DF493B4171F27C31AD2C9B4C6A09DFB7502D75BF8B26EFB93C1BC1ED8E162F4B12217793756D648866000A5C56DDF13B8CAA3DA905DA5F5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11825" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchResultGetterStat" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7157" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7158" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultsProvider" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultsProvider" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultsProvider" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1165
                        Entropy (8bit):4.771851921115038
                        Encrypted:false
                        SSDEEP:
                        MD5:E45D7274BB0C85E79E3E19F144375616
                        SHA1:EF2D105F0A5CF63F0F9116EC7EF2E20D542E3C04
                        SHA-256:D72CF29DADE25EDF80CE0A10660D9B10C84E6B9ED451EBB8405593F7973D8DEA
                        SHA-512:E5B70D1F0F7B1235DA4A30404B70079BE58A2F268037689508CC70E4BE6D1309673A97F615976A8D551B96EFFD0D3C70508D0646ABC2DD90481AF025053F45CC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11829" V="0" DC="SM" EN="Office.Outlook.Desktop.Attachments.EmailSent" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4306" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="HasCloudFiles" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="SentWithSharingErrors" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_MailsSent">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_MailsSentWithCloudFiles">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_MailsSent
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2273
                        Entropy (8bit):4.173928223889092
                        Encrypted:false
                        SSDEEP:
                        MD5:D824AB4471D5D7C6B0DDBF39C4A85EE3
                        SHA1:C6C84A216DE43F3EF9EC661114DFEED4CB1B9665
                        SHA-256:0AF3EF738DBD0E832E616E6CECE75469779B72A98F0F4F163B49D831A6504C96
                        SHA-512:22BEF986FA4F106E526B7B02D8303E6A14A608CDB155C4B4AC0004B2ECEF7F2240CE8CD4FB6D3ABAEE0794EFFE2F673C7E65AF63E3606492E750A016710A524A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11833" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.LocationFetchTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6126" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="ElapsedTickCount" />.. </L>.. <R>.. <V V="500" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="ElapsedTickCount" />.. </L>.. <R>.. <V V="500" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="ElapsedTickCount" />.. </L>.. <R>.. <V V="1000" T="U64" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1403
                        Entropy (8bit):3.9857348097565484
                        Encrypted:false
                        SSDEEP:
                        MD5:69D58B1B8AC1B0E51E20FE50352ABDAB
                        SHA1:2DA03C9206E19389CE104C24F2940E39055C4E27
                        SHA-256:C82B40E2804EFA42EE951193B75E9206544EB2F0AD1041ECEB91B082DF0BBFEC
                        SHA-512:C443326DE313C42D436C1B6D0540CA80A10595D595B4BF7A70FB548CFCE63880AA6A4F3FC4D2CF1C251DFEEE752953518D64570D887C185449C4FCF55897BC7B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11834" V="1" DC="SM" EN="Office.Outlook.Desktop.TcRebuild" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="617" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="Elapsed" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="NIDType" />.. </L>.. <R>.. <V V="14" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="NIDType" />.. </L>.. <R>.. <V V="16" T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):438
                        Entropy (8bit):5.2983359003737895
                        Encrypted:false
                        SSDEEP:
                        MD5:DA7160E821EAA803DA2B1A7181C5A47A
                        SHA1:6F117BF95A35AFC94A1336DA7CEED44A3B2E3AC0
                        SHA-256:514603565C830E5F6378B2522EBFF165900AB9E4A53BFDEF4BBE2A644FD13FF7
                        SHA-512:6155668B61D366BA13A5683D0937F2A9684B6A30F915CDD7F39DF92389D2825B13F03A4A0C4AF378957B083ADC1E17C1CCBB7593FB58366A6D8F724E48838CC4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11841" V="0" DC="SM" EN="Office.Outlook.Desktop.DarkModeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8108" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="DarkModeEnabled">.. <S T="1" F="IsDarkModeEnabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):530
                        Entropy (8bit):5.275584213761911
                        Encrypted:false
                        SSDEEP:
                        MD5:BD204AD3264858CFED5FF0FD3EA98337
                        SHA1:DE6ABB7CC77E77E281626C24D23FB146953EEFC4
                        SHA-256:7E50B2E98CF4F348D3E5CA98855930F16F2389742945920BB2FB25ACA782A7B2
                        SHA-512:15973ABC3DAF687D065A4A7214389066FF971D70546239AA8C5795FF296DF74CCF4E7BB7A194AD79607B1AD41B74CA1ACE6426C9F2CA1F6C694F51DCDBF79F65
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11842" V="0" DC="SM" EN="Office.Outlook.Desktop.RssHashPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="385" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="I32" I="0" O="false" N="RssHashPropMaxKB">.. <A T="MAX">.. <S T="1" F="RssHashPropKB" />.. </A>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1460
                        Entropy (8bit):4.666418817421043
                        Encrypted:false
                        SSDEEP:
                        MD5:FEDCCCD798E11E042E4C4D96897E106C
                        SHA1:40464A636DCBF01E6E3C7EEB9F2286CB7A477970
                        SHA-256:EF093D87908D5570D7716DC8F3E0F58148384448B895C8DE9E435B9CA4D00450
                        SHA-512:FD7BF082F5A7EC16AC689BF82075C4FD2ADA5518C650545EE6C20624BFFEEC8EE1A7255FD06DA89B4D0D82EACC079EDED4254ED04BD54788D9126505CDFADADB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11844" V="1" DC="SM" EN="Office.Outlook.Desktop.AuthXMSDiagnosticErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7092" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="7094" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. <F T="5">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="4" F="XMSDiagnosticsError" />.. </L>.. <R>.. <V V="4294967295" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="4" F="XMSDiagnosticsError" />.. </L>.. <R>.. <V V="4000000" T="U32" />.. </R>.. </O
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):790
                        Entropy (8bit):4.979348876203387
                        Encrypted:false
                        SSDEEP:
                        MD5:2A0B16C54FC327A1603D4EFDB1A38149
                        SHA1:3458EEECDB42C70DB89D18896B496F6421D9C2DC
                        SHA-256:6DE56B9A9676A5162079031B9B4CDDD4E7919A09299FA070CD480E2FC5C4371D
                        SHA-512:534535C30731E72947D56E419155DBF420261D414C045A282CB8DFE55A3A2F1BA66CF97968D8D47E91F35E3A0652881124D20EE91397C93134770C22F6EA383B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11846" V="1" DC="SM" EN="Office.Outlook.Desktop.Rest.RequestExecutorBasicError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9106" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true" N="RequestId">.. <S T="2" F="RequestId" />.. </C>.. <C T="U32" I="1" O="false" N="HttpStatus">.. <S T="2" F="HttpStatus" />.. </C>.. <C T="I64" I="2" O="false" N="HResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4598
                        Entropy (8bit):3.7786855921949014
                        Encrypted:false
                        SSDEEP:
                        MD5:5C21D3E92C8937A5A72DADDB1C66AB59
                        SHA1:9BEAF466964A984EB81FDE704DB3BA327DD9A56E
                        SHA-256:0647BFE6BDBC024FDA2F642E738EF4DE3C9DF4EB458BED1137A2445617441B4E
                        SHA-512:DACA50E52FAE39F0945BB9931A4BAD810D1F231A950761D0125FA84D851CB381B0D52F86E7ED141F64C9E516DE56AE758B60FDDB76F2A654DE1942D2BF9D5108
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11847" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIAllLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10591" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4634
                        Entropy (8bit):3.808741357444101
                        Encrypted:false
                        SSDEEP:
                        MD5:AC02080D31AA991E28F634D542BFFEA4
                        SHA1:6AE27E9022B7F7A6DC4C25DC5BBD8442546E4D2F
                        SHA-256:F1D4BDB3F96DCC7BEF09B48CE156A70A82458F69C0F3F0F20DFBC0B4C38C3E0F
                        SHA-512:AFFDAB80C8B0E3BB8F3D1D04988F3C813600790717EC5FECC20DA203B876804912E2DE7982A48F3ACF667CBC47AAD1065E3BDB9851EB1CB1CD5D2B02353723E7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11848" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUISuggestLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10592" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4607
                        Entropy (8bit):3.790425620953119
                        Encrypted:false
                        SSDEEP:
                        MD5:840B771544EB1794F70C2AFC6B80EA02
                        SHA1:903E6F5EDEDDF7A94A6A1336DC2AF799DC046050
                        SHA-256:1A88B486E30D87D643E68A451D613721298CFED7600EEAF6A5508B5B518FDCBC
                        SHA-512:EF101EB2F01F9AA5D8BD29FB0B6D75EB728A1127099E03ED8A8F476F273DF45AADDA3838571D7A204E6E5F6A668E8E4DF6501AF0623AB331E4BE29FF1D63227B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11850" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIJoinLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10593" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4634
                        Entropy (8bit):3.8047585304954845
                        Encrypted:false
                        SSDEEP:
                        MD5:D11E9438793EA06B2E99EE6B6FB4754D
                        SHA1:47D5A68E57F06F54B668FD7C4725B1F91964076A
                        SHA-256:11D846519EAFFBD9AF3EE92CA3957991656771314F065F7767D73FF2215E838A
                        SHA-512:7A7ECB65B7981F819A2A23D3BD205EC882099289CDC0183B74258DEAB48C76DD02E1CDAF568FC03A334CA07EC112C44F338202119AC621CB04274FDA8F681A51
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11851" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIDismissLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10594" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1694
                        Entropy (8bit):5.088503698783867
                        Encrypted:false
                        SSDEEP:
                        MD5:28CBA06F973AE07D2D5DE90E6E3AFE6E
                        SHA1:158F7E777C4D92BF4B8E89A9E053B480E67AFA56
                        SHA-256:985C667611B33DA1737B99EF8B2787D5C05E6F7A608626A201C0CEDFC3CF31C7
                        SHA-512:58B9A11F9394A44D16AB7CF09EB5E14840C5533A3959F2CC813DDEB26E13035B28F52E27FBCF35070EAE0956B119A5E5388770326FF7DC69EE429D548213B887
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11852" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIButtonHitsRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18018" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="18019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="18020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="18021" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="18030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="18054" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="18055" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="NoOfSearchBtnClicks">.. <C>.. <S T="1" />.. </C>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):625
                        Entropy (8bit):5.035874029828806
                        Encrypted:false
                        SSDEEP:
                        MD5:A5B1C31C7B2B6AB6C0B30869849F32DF
                        SHA1:B4DB6968A5DDF065D59289678FA44A901218A9B4
                        SHA-256:F489D3594494620F0E8E121778256CD97F14FA1FD2E71919A32890DDB7A557E6
                        SHA-512:C32AD303E80F06D4E6242E64556AC80697EE07024B45BA81C112861CC217E565599987ADAA73F36CEA48D9788A356BC5484376D802423186DFF74E444FDB0736
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11854" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateDlgExit" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xgh" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):623
                        Entropy (8bit):5.030376317205087
                        Encrypted:false
                        SSDEEP:
                        MD5:4D50E1EF893A1810E4294A40E73FE452
                        SHA1:9E47994F71F6EC67033B85D7817CAE3EF138F4A2
                        SHA-256:0AA13C740C47CF810E619A42DCF1F48A4CE626D8CF937ED3BFED2365B4F9222B
                        SHA-512:AD5EDDBEEC7B3E33CB6B76A15D3A0655CEAD3FD675F34E021778CA982E0663118E3156B9476B23BDE4280064041AA8F66E03B9CD9C4A57AE4A62E8ADB5966108
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11855" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EditDlgExit" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xgf" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1084
                        Entropy (8bit):5.119538640545281
                        Encrypted:false
                        SSDEEP:
                        MD5:9643EEEAA5AA89FCEB0CF15A7C2BE045
                        SHA1:944840765699F8506C0B35E48EEC665EB27D529C
                        SHA-256:367115A2330B3A7EEC36BA1722B4498100542AABDCED7A0518B9E7C3377022D6
                        SHA-512:E16EF8C73FB18544168FC5C00D499AF2F5AAD00EB2FD827B881A2C4B3C6801E05C3366C111975FEA84247A0363B4F4C74D7B56CAEEBAE9ACA6557AE841C45AD6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11856" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateDlgInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xgg" />.. </S>.. <C T="B" I="0" O="false" N="LanguageChange">.. <S T="1" F="LanuageChange" />.. </C>.. <C T="I32" I="1" O="false" N="PrivacyValue">.. <S T="1" F="Privacy" />.. </C>.. <C T="B" I="2" O="false" N="ClassificationChange">.. <S T="1" F="ClassificationChange" />.. </C>.. <C T="B" I="3" O="false" N="AutoSubscribedCheck">.. <S T="1" F="AutoSubscribedCheck" />.. </C>.. <C T="B" I="4" O="false" N="GroupIdEdited">.. <S T="1" F="GroupIdEdited" />.. </C>.. <C T="B" I="5" O="false" N="NamingPolicyEnabled">.. <S T="1" F="NamingPolicyEnabled" />.. </C>.. <C T="B" I="6" O="false" N="PrefixSuffixEnabled">.. <S T="1" F="PrefixSuffixEnabled" />.. </C>.. <C T="I32" I="7" O="false" N="BannedWordsCount">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1681
                        Entropy (8bit):5.031911578321207
                        Encrypted:false
                        SSDEEP:
                        MD5:29657EC1CB41062647C5D7979F404071
                        SHA1:7DE35DEFDB7FECA804B86D66D6960E3F74CA47D8
                        SHA-256:91367A4F86F4DD9AB94DFD2724302CF70C79E141632FA99688AA0D16955CA2C4
                        SHA-512:147A6227BD7779185C242F2C79192E2D77C61BC9476178441038CC6EF856C7B76B149F19B683AF639A29079BB3A2B4F9A19D07400356A82909DB81A7E2C15377
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11857" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EditDlgInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xge" />.. </S>.. <C T="I32" I="0" O="false" N="MembersAdded">.. <S T="1" F="MembersAdded" />.. </C>.. <C T="I32" I="1" O="false" N="MembersRemoved">.. <S T="1" F="MembersRemoved" />.. </C>.. <C T="I32" I="2" O="false" N="MembersChangedAdmin">.. <S T="1" F="MembersChangedAdmin" />.. </C>.. <C T="I32" I="3" O="false" N="MembersChangedNonAdmin">.. <S T="1" F="MembersChangedNonAdmin" />.. </C>.. <C T="B" I="4" O="false" N="NameChange">.. <S T="1" F="NameChange" />.. </C>.. <C T="B" I="5" O="false" N="DescriptionChange">.. <S T="1" F="DescriptionChange" />.. </C>.. <C T="B" I="6" O="false" N="LanguageChange">.. <S T="1" F="LanuageChange" />.. </C>.. <C T="B" I="7" O="false" N="PrivacyChange">.. <S T="1"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):805
                        Entropy (8bit):5.174600923213037
                        Encrypted:false
                        SSDEEP:
                        MD5:68225C7CA3CEEBE522B8A543D87D8AD1
                        SHA1:CB82B1D650208845E1FFBE4CDEC8C81D150E7BD1
                        SHA-256:A6073057EAFB0D93785278A8C1BFE5D069ADD0D74D3D45097E4EBEBF054C8FEA
                        SHA-512:85C6AA6C05570FDA17ADF74F973AA0D8118099F09412ABBFEB5B87ECE274197DA5DC0103583E5E7DD22480766BD53F25AA6B579A3575A2811A59535D51D6BDA0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11858" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchPaneUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9300" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="9301" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="NumberOfTimesAdvancedSearchPaneShown">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesAdvancedSearchPaneSearchPerformed">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):709
                        Entropy (8bit):5.177355495915668
                        Encrypted:false
                        SSDEEP:
                        MD5:CABF65E8A2364D44532A218A0E1FCFC0
                        SHA1:85877519C55CD224B284B2FB8A5CF80892825F59
                        SHA-256:ADA3510F0DB5CC7661E764C840DDD9B4FF28DC5DFCF866DE19692F30AF8B05A4
                        SHA-512:122AE550AF61B7931F5D2A672618F9D9513193D19BD37128DED68DA8350259C18CEF7877DE19EB10B7D7AA6147E780B492AB8318E6FBD1B84C213312C432886E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11859" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchOptionUsed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9302" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OptionName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AdvancedSearchOptionName">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesOptionUsed">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):711
                        Entropy (8bit):5.1708717056519955
                        Encrypted:false
                        SSDEEP:
                        MD5:96DE31148FBC75BA29A77A21139DB8CA
                        SHA1:67C371BE2133681E0F60B384D897A740C0E9CC75
                        SHA-256:8D251CB71BA7E6CC3E63D123AD75757100578C8070E32A17ED1456A331E4FE2B
                        SHA-512:C9B49483BF9BEFB6A49DB8B764A7FA36181793F682A67AD1FB0E04A558017EEEEA6D2344A25189D36155D67F5F972857C57F549FFF6D92299E145C2549AF0339
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11860" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchOptionAdded" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9303" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OptionName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AdvancedSearchOptionName">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesOptionAdded">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):715
                        Entropy (8bit):5.180933768367821
                        Encrypted:false
                        SSDEEP:
                        MD5:5F59869A6D41F2A3617937BDEAF8E825
                        SHA1:99BA71CBFB4191FC1B80230BAF452D5EE69872F0
                        SHA-256:9F719D920534856227D49E883AB3E1C01279ABD509E94954969EB78633E6A21D
                        SHA-512:1D5F8E0E709C93040539D7DA1A0159505895216C84762341FAFE608CA17B427314ED774FE4170C1160D7FAA1E78FE3ADF9F8092CAB7D72538B9D3E440560BAE3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11861" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchOptionRemoved" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9304" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OptionName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AdvancedSearchOptionName">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesOptionRemoved">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2675
                        Entropy (8bit):4.628239904225048
                        Encrypted:false
                        SSDEEP:
                        MD5:D08C8AF94C5409038C46DAC6C323507C
                        SHA1:6D229ACEA4B7C8BB9A4E00B3292202475723D6C9
                        SHA-256:54FC859A8765843CFF13AEF38ADCFCA9AC0DF3C32FDDFDB8256CCD3D5DFA5BC6
                        SHA-512:6BEA63CF22CBF4E1E417525A1E0A9B3F12765569672937F313F455234FE58D1435EF011DCDB3E78A2F917AB140C7EC28073B117388B0003BA89C326FFDE43786
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11862" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchTellMeSuggestionsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7160" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7161" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="SuccessResult" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="SuccessResult" />.. </L>.. <R>.. <V V="2147500037" T="U64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="SuccessResult" />.. </L>.. <R>.. <V V="2147549183" T="U64" />.. </R>.. </O>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):747
                        Entropy (8bit):5.21287995049897
                        Encrypted:false
                        SSDEEP:
                        MD5:710D9222529239A115762FD302DD28B0
                        SHA1:DF5B11304E78B91E226C9BFFCE601933255311FE
                        SHA-256:FDC5A983E99FC0B20BF510AF8F82D86F8A98EFBF359A427E92F56B92C3B1B4E5
                        SHA-512:E113BB0F2C7F3CB4C9BA46B41BF31E419E349637B039E1F71FCC44F1D4AD698FDF172A38418EA7E5730EC9DB7C66DE619698A8A377E3E02AC0FF8E5796BD8637
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11864" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.SubscriptionButtonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19011" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="GroupsSubscriptionChangeAction" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SubscriptionActionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SubscriptionActionID">.. <S T="1" F="GroupsSubscriptionChangeAction" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):816
                        Entropy (8bit):5.130759637618822
                        Encrypted:false
                        SSDEEP:
                        MD5:4A81778195DFDA6D9367BC18CAAFEF41
                        SHA1:F86365A8B05ECF701F6E1C3304BE3BE68CC52319
                        SHA-256:2FE6D98E9C7E31C72142D855FBADDDD7C3F360CAB03EC2896B9FF045983DEC10
                        SHA-512:8BF5DC098CF7A7B4B61518CA88B242072CDED5F229F4A0F2AA7DB8C63BD9635F4D0A42D0F7FD877291601EFD3999DF1B1A35D066AED58DD09A29497989F81220
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11869" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.Win10NotificationFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23407" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="NotificationAction" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ToastQuickAction">.. <S T="1" F="NotificationAction" />.. </C>.. <C T="I64" I="1" O="false" N="FailureType">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U16" I="2" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1114
                        Entropy (8bit):5.249517661765813
                        Encrypted:false
                        SSDEEP:
                        MD5:E6381445D5F708EB0E67A1043824CBC3
                        SHA1:737D8C6A76D0E491A6FDDF46A074B2BCCB72D331
                        SHA-256:B7D27713A41349EF08D9CE4C89CF02041AF7460B2C3D08E38B46366F595D30BE
                        SHA-512:7346DA00663A90A543DFEC1ED74BECF8AE964EB43DCAC6E21ECCE5801B20CF08C15E2CBD49949A815CE033AE248A52D16F4178C821B98897901BC5BD1D01DA82
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11882" V="0" DC="SM" EN="Office.Outlook.Desktop.LokiSetAuthHeaderMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c9vi3" />.. <SR T="2" R="(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)">.. <S T="1" F="CorrelationId" />.. </SR>.. </S>.. <C T="W" I="0" O="false" N="CorrelationId">.. <S T="2" F="Matched" />.. </C>.. <C T="U32" I="1" O="false" N="FinalResultTag">.. <S T="1" F="FinalResultTag" />.. </C>.. <C T="I64" I="2" O="false" N="FinalResultExtValue">.. <S T="1" F="FinalResultExtValue" />.. </C>.. <C T="B" I="3" O="false" N="RetryRequired">.. <S T="1" F="RetryRequired" />.. </C>.. <C T="U32" I="4" O="false" N="FirstAttemptResultTag">.. <S T="1" F="FirstAttemptResultTag" />.. </C>.. <C T="I64" I="5" O="false" N="FirstAttem
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1085
                        Entropy (8bit):4.619641857199903
                        Encrypted:false
                        SSDEEP:
                        MD5:A78CD05D4968E74803650E9616CB5D51
                        SHA1:7D3B65A63702F71CE3F62D825DC468F09392321E
                        SHA-256:7704B1884E9A26D7716C3DD838B96EABAFA5A5E5D30F14C82855B44DAC636391
                        SHA-512:6F875F47D60B06AE032277760C4C10026D1EF69F3D6E604EF42250C902730B3CACE153F057E4E9CB6C55DA4FA74DAA0BC54C5DF557AA492DA6F7D45473E42101
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11890" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.CCv2InCardNavigation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="daprf" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FoundCard" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="NavigatedToPersona" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_Total">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FoundCard">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_NavigatedToPersona">.. <C>.. <S T="5" />.. </C>.. </C>.. <T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1586
                        Entropy (8bit):4.326350329373209
                        Encrypted:false
                        SSDEEP:
                        MD5:9C8506468A07D06DE59B8AF4D1017227
                        SHA1:739DCD3C5EE7A0F47CFCADDDB93B1D4120563055
                        SHA-256:559578790ADD9E40CE0D7388EACC362FB2FA10709DC5E1700F266F98AC1668CD
                        SHA-512:332DE477C226BBE0D71E1A78434E6890ADFADA9B39C942C92FB4D5E6126FE3B24D88FB5C6ACBEB45ED663C2D896A641B2490E566D506540F60BC5A119F3CB492
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="118916" V="4" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="110234" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. <TI T="4" I="30s" />.. </S>.. <C T="U64" I="0" O="false">.. <S T="1" F="0" />.. </C>.. <C T="U64" I="1" O="false">.. <S T="1" F="1" />.. </C>.. <C T="U64" I="2" O="false">.. <S T="1" F="2" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="1" F="3" />.. </C>.. <C T="U64" I="4" O="false">.. <S T="1" F="4" />.. </C>.. <C T="G" I="5" O="false">.. <S T="1" F="5" />.. </C>.. <C T="W" I="6" O="false">.. <S T="1" F="6" />.. </C>.. <C T="W" I="7" O="true">.. <S T="1" F="7" M="Ignore" />.. </C>.. <C T="B" I="8" O="false">.. <S T="1" F="8" />.. </C>.. <C T="B" I="9" O="false">.. <S T="1" F="9" />.. </C>.. <C T="B" I="10" O="false">.. <S T="1" F="10" />.. </C>.. <C T="B" I="11" O="false">.. <S T="1" F="11" />.. </C>.. <C T="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1167
                        Entropy (8bit):4.469051603181357
                        Encrypted:false
                        SSDEEP:
                        MD5:6216D981DED0031BE61E18533B919568
                        SHA1:83D3BFC747FC6DA322C880176E22BE1217C3C63B
                        SHA-256:69D078EE0E02C71C4DD887182DF9645D32CB1EBADB5FBE8A0E52667307EB9A32
                        SHA-512:17FD052048AD6E887E4D8FAE8A17DD5A955C70FC3E17C450DA24B2BED911609E4B4B610BF151CC49E9EE6BDD82E0DE36295B94E43BAE8A63526948328F086259
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11891" V="0" DC="SM" EN="Office.Outlook.Desktop.Emsmdb.InnerConnectFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4003" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="RequestMethod" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="RequestMethod" />.. </L>.. <R>.. <V V="14" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="RetVal" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ReturnValue">.. <S T="4" F="RetVal"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1646
                        Entropy (8bit):4.501749872221178
                        Encrypted:false
                        SSDEEP:
                        MD5:D917FF305E7259C23AF991E567395B1C
                        SHA1:D22F5F1F395B75B5D5E7401307D8D0B1A65BCC44
                        SHA-256:BDAC19F96453AAFE8A523E7922BE09581F42FB02E2B2047757183BFE8E50A96F
                        SHA-512:BE340F14458623686B50731EF72E570A83660ADA00CF98F971CBFFCA6A086CCC6EC7959DEA745EBF6C98BC22A774337F8BDFA67CB55E87DDFF99FFDDEE1562AF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11892" V="0" DC="SM" EN="Office.Outlook.Desktop.CategorizedAllDayEventsMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="1023" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="isEventCategorized" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="isEventCategorized" />.. </L>.. <R>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):576
                        Entropy (8bit):5.330255518819447
                        Encrypted:false
                        SSDEEP:
                        MD5:99518DAAD956C03B13DC03532C63DAF2
                        SHA1:1E16922BCEE7051DC9A25414120E8E382B744D93
                        SHA-256:C025A9CBFFBE1FAD391806C79187FCB6A169CF6C7639E0A86F29A624B16B9FF1
                        SHA-512:CEF5B1535701DE59535E890A0678C91F543AFBEB100914FBF65445C06E71956C2216AA2F07017F8FFE3097BAA75C9FCA179E5A4042D7C96C8C828B884AC4C7F4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11893" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.DynamicTimeZoneChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22423" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="NumTimeZonesDisplayed">.. <S T="1" F="NumTimeZonesDisplayed" />.. </C>.. <C T="U32" I="1" O="false" N="DynamicTimeZoneChange">.. <S T="1" F="DynamicTimeZoneChange" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):534
                        Entropy (8bit):5.1430052843074945
                        Encrypted:false
                        SSDEEP:
                        MD5:55772A7336D32364E51D4AE140EE9CA6
                        SHA1:9B6B389F2873E6CFAF2124DF599C4F11845D6354
                        SHA-256:BA09732BAFF9BC099B3A29DCC21E11D408C09580C952A5BC5BFFCB4D50C7C749
                        SHA-512:FF88C78BEC91478151C85CC8553B254666E4C4718FE554300EFCC806BC764FCA7D34A04D174E1B00245AAB15AC16DC784581F692F0D8A5AE95A00891FF206892
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11896" V="0" DC="SM" EN="Office.Outlook.Desktop.LogFailedAutoDiscoverAttemptMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b7yhu" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="TotalFailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):822
                        Entropy (8bit):4.819569964284182
                        Encrypted:false
                        SSDEEP:
                        MD5:56B1B613F15F30693DEADD776DABBF69
                        SHA1:FE8EF06949471D77F9EBCA0CE496D88046222EA8
                        SHA-256:86C758F5A712DF27565205857D1F06D3A2B13083AA1D0E7BEE247CE4472E9108
                        SHA-512:DA144E573151F465B217208F0E666BEBAAB5E1135BEC896643C8B9581EC1675FC86D78F41DD1976583F97974F59E66C18D121D38AF77B07CAD436BB3EDBCC46E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11898" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="CorrelationId" />.. </S>.. <S T="2">.. <F N="CorrelationId" />.. </S>.. <S T="3">.. <F N="CorrelationId" />.. </S>.. <S T="4">.. <F N="OldItem" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <V V="1" T="U32" />.. </C>.. <T>.. <S T="3" />.. </T>.. <R>.. <S T="2" />.. <S T="4" />.. </R>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):861
                        Entropy (8bit):4.650072505186062
                        Encrypted:false
                        SSDEEP:
                        MD5:219922D315A8700F1EBD45AAE0627FF0
                        SHA1:5287067A239B32A9D500C90EDB8053DB84A9ED26
                        SHA-256:82980DC97302DC0D426E9CA460802ED71F9B782A5F8DF91FDBD4C22F08FFD460
                        SHA-512:CFC76462ABB9A9B814710AE0708867243B889AA254E1DBEF36A2108B0656875A741F98D27D5D6B68DF1E08D5341B4A1D00F1A1843FD49B77297F25384EE19002
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11899" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ViolationsFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="3" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="2">.. <F N="CorrelationId" />.. </S>.. <S T="3">.. <F N="CorrelationId" />.. </S>.. <S T="4">.. <F N="OldItem" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <V V="1" T="I32" />.. </C>.. <T>.. <S T="3" />.. </T>.. <R>.. <S T="4" />.. </R>.. <ST>.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1574
                        Entropy (8bit):4.634281067119136
                        Encrypted:false
                        SSDEEP:
                        MD5:0C7BDD76EA52B0A2B9C962BD58DD48E2
                        SHA1:129353E9340FF53950998CDDDA055803CA80D005
                        SHA-256:C76BFBCE79BF84FFA297A3D7E32F6720188C4EA06ABEEEA9A009E40A244F6124
                        SHA-512:7AC27B60EF0F05B1677F94E2E62AF71943471B5561A0069824B8B1B732C68F7AED0DC90FFD78CCDC30D116F8C2FFA1EF318F840481BC72C87618D632396EA39E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11900" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15012" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="15016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="ViolationsFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="2" F="ViolationsFound" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <SQ T="9" R="[5][7]([1]|)[8][4]" />.. </S>.. <G>.. <S T="5">.. <F N="Correlat
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1415
                        Entropy (8bit):4.637564044096567
                        Encrypted:false
                        SSDEEP:
                        MD5:CA8331DBFB7D19C4BAF17E0A0F1D446E
                        SHA1:640937C0D445ADCEE2B1B0233B052B7B18288D35
                        SHA-256:FF0E53CC63CD9D6D49F03B312478BBDBF71C5E4D64E8242A718032EC86EF844A
                        SHA-512:675C087703B373B5D001489A072E482F61E810C4E1B757BA49941BBF75D9A070BB74C858CB02839D5518177DF45AC4376035FCF8FFAD5A8B44A35E11B20C8698
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11901" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ViolationsFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ViolationsFound" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <SQ T="8" R="[6]([^[7]]|)[2][3]" />.. </S>.. <G>.. <S T="4">.. <F N="CorrelationId" />.. </S>.. <S T="6">.. <F N="CorrelationId" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):554
                        Entropy (8bit):5.1507704760790265
                        Encrypted:false
                        SSDEEP:
                        MD5:9749168FA208AB7A24D0B98E59E635CA
                        SHA1:4BF21E35C938B92E62F9C6B397A473E8C6973917
                        SHA-256:F8353E611854570CE6833CCC6C25F400E4CBC0E8A890638C92BF22DF80898BA7
                        SHA-512:45CBFCF763AAD9974445244F560CE6E44C4940D6BF4E0F79FEC57D99BBCB4221B3AD9282169B4F189E34629CB340FCBB82A0B674E4D1261CCE274B01F5026CE8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11904" V="0" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentToPACRecipients" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11898" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentToPACRecipients">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):6233
                        Entropy (8bit):4.001327044989029
                        Encrypted:false
                        SSDEEP:
                        MD5:FED9B41C56A578ABEF6D2972A777616F
                        SHA1:DC3AE5D7606B93CA4EEC8B35C9318BC7BB0D2E48
                        SHA-256:261150E06FF0F8AF2F6BEF41429A30450D8758E8300E2E85A133F32B8E2587D4
                        SHA-512:5E9EDABC0223633917F5E80DD1ED79FF56BE4F6154B1A3BEFDF4F54F4D540B1E64EDD5335FBBEB99DB0C2F2E6AE68BD21824006431524D64B247B9D0645D5F47
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11905" V="1" DC="SM" EN="Office.Outlook.Desktop.Sync.ConflictResolution" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="636" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="637" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="1200" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="4026" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <US T="5">.. <S T="3" />.. <S T="4" />.. </US>.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="ContextId" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="ContextValue" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2816
                        Entropy (8bit):4.308213423795027
                        Encrypted:false
                        SSDEEP:
                        MD5:E04E5188D06A5DCF479FDE88D7FFE9A3
                        SHA1:C7920E1F1D33BCF6184E7AECA42399CEA19FA7A4
                        SHA-256:B8D5FB333B8622FE5AEDC29A4785C18EEB9E5DCFE16567EA6A12DC1B30023F87
                        SHA-512:68BDED0CF7C1B030A2C4F74CECDAD4E546A7B116C3484DBF915A05E0DF3349B25258F06A194F09E0E4DC7FDFA73EA8A776019564B0E2B4091A0203DF5E2D93FC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11906" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchQueryCountAndStoreType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7157" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="Unknown" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="Primary" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="OnlineArchive" T="W" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):580
                        Entropy (8bit):5.216588947185266
                        Encrypted:false
                        SSDEEP:
                        MD5:602809311CD117BE9CE311CE8547D2DB
                        SHA1:0E8713CE21627C5B5B4B07FBE34BAEC726DA5A93
                        SHA-256:13C42166E1D220E7DB4CB2B490B501FAF7A4386EF96FABE84E91F60EFC4C722D
                        SHA-512:46295D5C196891EC1B0DCFD8E024AAA168E41C50EFA181D8C0808D0FC59561CA14BF35EA02BDFF1DC083DB3FC1E8E845FEE47D087E77F15BB916BA5416A96CC4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11907" V="1" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentAfterPACMailtipEverDisplayed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11899" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentAfterPACMailtipEverDisplayed">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):902
                        Entropy (8bit):4.965723974647843
                        Encrypted:false
                        SSDEEP:
                        MD5:E95D6B198AB318A4022CE1032FD6DA22
                        SHA1:CDD2E272D9215C2B046172268C63F29C808340C1
                        SHA-256:69FD33B068679D0563DE8B5AAE6194AF911F1EE82D2F34E6E1DAE162845FA439
                        SHA-512:B04491523632F5DA693B54E723DDA5856FDAB93DA514E3AEB8C47DE475F76CA84640F27382165D46B2F8236EAA91CA5A64FD45F98294B756DBC559FF92C3766D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11908" V="1" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentWhereUserFixedAccessibilityAfterMailtip" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11900" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentWhereUserFixedAccessibilityAfterMailtip">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MessagesWhereMailtipActivatedAccessibilityChecker">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):580
                        Entropy (8bit):5.19912151139074
                        Encrypted:false
                        SSDEEP:
                        MD5:279D5AA97B8BBC8F60BB8B9615BFD4D5
                        SHA1:03C1CCAC32BBF2FA9167795E9279CD920DAF8E53
                        SHA-256:115302424908245DCF36B428E136EB7DAF6C1BDEB3FA511CCEAD9DA71A631BDC
                        SHA-512:EA72A76CDE6750F38DF964EDC655501D2C5EC5121BFEEB47B684C8322CA03E06E4B6F3AD1CB606065980F6A4DF6B60E61EE7FC40312664D944FA375076C8AC2F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11909" V="1" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentAfterUserRemovedPACRecipient" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11901" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentAfterUserRemovedPACRecipient">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):778
                        Entropy (8bit):5.143676367809366
                        Encrypted:false
                        SSDEEP:
                        MD5:DD2A4D131FAC16493B0AB0DF2B2B33AE
                        SHA1:0918842F0DC9C21A2417412FCDAC0A58290AF289
                        SHA-256:584E524945D63D44561EDC5BCC6053395466F8A3F6B3FF8667E16F976826091C
                        SHA-512:FA0110365B9EE9E4A8CA1090B3151086BB80E8C21F8003802F4543CF9278678C3FD37172081C9B20C25E43C5C9AF4D0267ECACF99B2C5FCD7ED5C7DA04FE9B70
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11914" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageListDimensions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13107" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="MessageListWidth_Max">.. <A T="MAX">.. <S T="1" F="Width" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="MessageListWidth_Min">.. <A T="MIN">.. <S T="1" F="Width" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="MessageListWidth_Avg">.. <A T="AVG">.. <S T="1" F="Width" />.. </A>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1200
                        Entropy (8bit):5.02429455280933
                        Encrypted:false
                        SSDEEP:
                        MD5:6407316FBAE79C9CB15A6C2FE2C6905A
                        SHA1:133C8FDE49D7FEFF1141A9EDE15D798205807CD6
                        SHA-256:4F4C5E90855BAAD3738DB7FA599A4ACC7FF4F054BD751CA3F0B1FC67CF787FF6
                        SHA-512:0C63F22F74BC89AE070DF18A4A00AE0127C7F41F0B47AF45E40D3EB148755BB01EDF28A33EDF19597BC87B2321C6FF0DDF3D765D7C36ECD7DC02F058381CA16A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11915" V="0" DC="SM" EN="Office.Outlook.Desktop.ExchangeSaraAuthDiagnosticsFallback" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="50" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="2" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="ConsumerType" />.. </L>.. <R>.. <V V="6" T="U8" />.. </R>.. </O>.. </F>.. <TI T="5" I="5min" />.. </S>.. <G>.. <S T="4">.. <F N="LogicalHttpRequestId" />.. </S>.. <S T="1">.. <F N="LogicalHttpRequestId" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError" N="RequestResult">.. <S T="4" F="HttpResponseStatus" />.. </C>.. <C T="B" I="1" O="false" N="SecretKeySuccessfullySet">.. <S T="1" F="SetSecretString" />.. </C>.. <C T="B"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):980
                        Entropy (8bit):5.1221018502271
                        Encrypted:false
                        SSDEEP:
                        MD5:9561D4B433FAF699DB72D0774C93B60C
                        SHA1:F1CDC9E104162B9B22AB73C47617259A1C6D07CC
                        SHA-256:436C65461B2A43AFAAF4EA586464653033E14FDABB8A49EADBBF76927EDD7B5C
                        SHA-512:54112CD0E7B55BDB16D6E40AC3488E0E655B828E66CA2941EDAC94D6FBCD9629B6452D0B016E16DBBAAD8B1835A9F8DA6713CF4EE10C24132865FABA0E3F488E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11916" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.RoomFinder.Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="354" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="1024" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="1025" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="WebHostingPageTransitionTimerFailedTotal">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="AddResourceAttendeeErrorTotal">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="GetAppointmentDataErrorTotal">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2547
                        Entropy (8bit):4.682325925448918
                        Encrypted:false
                        SSDEEP:
                        MD5:888CBE316DACEDEBC303BBE8C2300C62
                        SHA1:1AD5414C2BBEA9B9602FE6ECD04AD829F23DFEF5
                        SHA-256:D108EBFD099EDA0F739C9932D7637E29F8F2B92135D2CD21DA441F7F5925714D
                        SHA-512:B14ED629E5D5160BBE103992D52EE7C4544FFCE9A67286D617FD59813DBE9444BFEF9D243EC4416F9A8934D84BCBA064F3E82944AD600E9883F4FE9F32EBFD79
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11917" V="0" DC="SM" EN="Office.Outlook.Desktop.RopChaining.ParseResponseMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1608" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="1609" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="1612" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="RequestRop" />.. </L>.. <R>.. <V V="163" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="FMatchesCurrentChainedRopInfo" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="NE">.. <L>.. <S T="2" F="RequestResponseRop" />.. </L
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1204
                        Entropy (8bit):5.035353445562176
                        Encrypted:false
                        SSDEEP:
                        MD5:459E1FDC48A71470947341E1BA282180
                        SHA1:8CC1F1C5CD25D3833ECF0778CB9ED7EB26CDF267
                        SHA-256:F5231E381891E32A94884AC9BF10F2D8954BE574C43790837F25725694C313E2
                        SHA-512:8A435BBF0092DD7B76A78B8DC3ECA2AA3871CE122D85B2E602D1BBB220209218FF361714C5062833125E654077C4A36B14CFE114517C46A6DFB2AF62B4709C9D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11919" V="1" DC="SM" EN="Office.Outlook.Desktop.ClassicViewSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13100" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="1">.. <F N="ViewSetting" />.. <F N="ArrangeBy" />.. <F N="PreviewPaneSetting" />.. <F N="PreviewLines" />.. <F N="SpecialFolder" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ViewSetting">.. <S T="1" F="ViewSetting" />.. </C>.. <C T="U32" I="1" O="false" N="ArrangeBy">.. <S T="1" F="ArrangeBy" />.. </C>.. <C T="U32" I="2" O="false" N="PreviewPaneSetting">.. <S T="1" F="PreviewPaneSetting" />.. </C>.. <C T="I32" I="3" O="false" N="PreviewLines">.. <S T="1" F="PreviewLines" />.. </C>.. <C T="U32" I="4" O="false" N="TotalFolderS
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1033
                        Entropy (8bit):4.706841329449731
                        Encrypted:false
                        SSDEEP:
                        MD5:60101A2A5A97F01D44D6A95CDB2C2662
                        SHA1:497D6F714144ECC69FCC5C6748BBE6B7C05020F4
                        SHA-256:50328565B12D6087B7F1EAE0C799664670DF61AC948699C5FB1845EFA0538283
                        SHA-512:61137413016481CE9A7CF97B154BF10A1C6097B205F5CFB7BCB3E076DE49ECBF7C1AAC7E338DA960747E827D5853AA71FDBBA7EACBB674846A45990F9675DA4C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11920" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.RESTCalOptInOutUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="210" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="isREST" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="isREST" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="OptInCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="OptOutCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2453
                        Entropy (8bit):4.076699783445814
                        Encrypted:false
                        SSDEEP:
                        MD5:6021C9F2F4155A66791BD1B399544EED
                        SHA1:E2606D61E40772D8CCBD8F5BB2B0B28E5051F34C
                        SHA-256:D5766B3FF3AFFF8D2804D1A605E305DD752AC9748EBA1787B4F44272B54CC076
                        SHA-512:920397ADB0E650831A9FEF638E7451F4196E7FDEBC1F83E4219A8DA165FF346CE5FB0B89278F48DAB80A2D149BAE1ACC2837EAFB2B2A08B670F7673608D6F562
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11922" V="0" DC="SM" EN="Office.Outlook.Desktop.CountDifferentAccountsUsedInRNCards" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dd9jp" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <S T="1" F="CardIsInOutlook" />.. </L>.. <R>.. <S T="1" F="IsReactNativeSupportedForContactTypeAndTab" />.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <S T="1" F="hasReactHost" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="IsCardCustomized" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="3
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2618
                        Entropy (8bit):3.9553280275926457
                        Encrypted:false
                        SSDEEP:
                        MD5:C7D1DCB899019DB1444BE9F52891422A
                        SHA1:BE8A2CBF117D187726DF6B4A75D33175C4B68660
                        SHA-256:1DCE0C9C67250A679D639D0B6D87B8D514B5F4EE85139804803BD6BDF7DD62F9
                        SHA-512:0FB55B815FD30A43F81627373346D26E42A65DA2759AF79175B9C3740FAA70A29FCE0305658D039A422F9669A0D451F26E5C890B8FDA9570CFC9BC308957808F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11923" V="0" DC="SM" EN="Office.Outlook.Desktop.CountNoReactHost" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dd9jp" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <S T="1" F="CardIsInOutlook" />.. </L>.. <R>.. <S T="1" F="IsReactNativeSupportedForContactTypeAndTab" />.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="hasReactHost" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="IsCardCustomized" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1513
                        Entropy (8bit):4.487551712145366
                        Encrypted:false
                        SSDEEP:
                        MD5:A5FCD6B63CBC703D6613068D76DA505F
                        SHA1:2A9B7FCE63665DEFA1F34A5605565AB5B58FECDB
                        SHA-256:3C2AF55ED9C8A88BE582D879A360248BDF9EFD7CB947B4B931A9A92C1208731A
                        SHA-512:DD1FCC0F8887F73373CAEE4B695B0A6946062C47463BD10F5D5F0890D6A540FF3F999CB6CAFC4C8F7096F2250513F04AC9E36AF66C6A235BD685814775BD4B79
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11924" V="1" DC="SM" EN="Office.Outlook.Desktop.CountCausesFailedToOpenRNCard" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dd9jp" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="CardIsInOutlook" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="IsCardCustomized" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="IsReactNativeSupportedForContactTypeAndTab" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="hasReactHost" />.. </L>.. <R>.. <V V="false" T="B" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1363
                        Entropy (8bit):4.743779778491043
                        Encrypted:false
                        SSDEEP:
                        MD5:B64E2BB5D1950451902BAD92260B79C3
                        SHA1:08F6CB3BFD9FD34E769ECFA927B4CDB6A2D1617A
                        SHA-256:B5A8607750E30DADA2B0A4952DC6FACA9930F8823923CB54D6274E903CEF2F9A
                        SHA-512:E3091675047978868F90CB7CA75498601C6576841EC433CE87130767B3A72D94D2A8A47737CE3619606FCBA6972C155D1AD3C02F7829907B84A5F62CB3E182FC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11925" V="8" DC="SM" EN="Office.Outlook.Desktop.OPX.TransitionErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="350" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="OR">.. <L>.. <S T="1" F="IsFinalWebHostingState" />.. </L>.. <R>.. <O T="GE">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="2" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="2" F="WebHostingSessionId" />.. </C>.. <C T="U32" I="2" O="false" N="Result">.. <S T="2" F="Result" />.. </C>.. <C T="B" I="3" O="false" N="IsVisible">.. <S T="2" F="IsVisible" M="Ignore" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):704
                        Entropy (8bit):5.122881156884214
                        Encrypted:false
                        SSDEEP:
                        MD5:EAF46BFFF22ECED66E92503F502A8990
                        SHA1:C3B70641B475370A70E773B31B7D3E5C5BE5A639
                        SHA-256:3556F97DEA588A60A205BED670A72CF72E30208D17B48924DF3F89B1E6B77EE5
                        SHA-512:090587CCC3AB505D774A508BFA2E2F4982C08AB251AED900914D5E4879AC20999593FA668A7CFC10BDE8F034CADDCCA78E08FC18C46403103272B28D842AC5C5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11928" V="0" DC="SM" EN="Office.Outlook.Desktop.OutllibDialogETW" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13200" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="1">.. <F N="DialogID" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DialogID">.. <S T="1" F="DialogID" />.. </C>.. <C T="U32" I="1" O="false" N="TotalDialogsInitialized">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1212
                        Entropy (8bit):4.305751169482486
                        Encrypted:false
                        SSDEEP:
                        MD5:CB85564EFD221EA611E0CB0E4DC0B4F4
                        SHA1:DFCC5D8936EAF3CECEF5CE9206EBAEE5621F6FE5
                        SHA-256:D94AEF86117BC93E5FF076CDCE1765DF5478AE7DB14F5372761B883522A1F0FA
                        SHA-512:BE02D932409309E5750E6FC3312671A5A1A5E80967280D84C368F6290D669CD691ABB6A9D518A7CFB96C4F5063B6AED458C2F288491337A5A572D19E688A4AD3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11930" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="dfds5" />.. <UTS T="2" Id="dfds6" />.. <UTS T="3" Id="dfjbr" />.. <UTS T="4" Id="dfjbs" />.. <TO T="5" I="30s">.. <S T="1" />.. </TO>.. <A T="6" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Id" />.. </S>.. <S T="2">.. <F N="Id" />.. </S>.. <S T="3">.. <F N="Id" />.. </S>.. <S T="4">.. <F N="Id" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError">.. <O T="SUB">.. <L>.. <S T="4" F="TimeSinceEpochJS" />.. </L>.. <R>.. <S T="1" F="TimeSinceEpoch" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="falseNoError">.. <O T="SUB">.. <L>.. <S T="2" F="TimeSinceEpoch" />.. </L>.. <R>.. <S T="1" F="TimeSinceEpoch" />.. </R>.. </O>.. </C>.. <C T="U32" I="2" O="falseNoError">.. <O T="SUB">.. <L>.. <S
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):569
                        Entropy (8bit):5.08920233705384
                        Encrypted:false
                        SSDEEP:
                        MD5:9AFF37E01EB10E158F597EA6E1200EE8
                        SHA1:C4264A3DBFC3AD5405E12F04F281C2D33D412AEE
                        SHA-256:05FA8A5BC0784F487B1706D63380E2B3B0F34AEE574674D310078D2DF8AB7C61
                        SHA-512:44116B0E2AF4F5EFE16A1CF57BF24B40680743888B1EDA11C9370E18E35A9EB9DDAEBA6BCB63FE462C72FDD913174ACC6A257155B153400862FF5619FDC6AE99
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11931" V="0" DC="SM" EN="Office.Outlook.Desktop.RNCardTimeToRender" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11930" />.. </S>.. <C T="U32" I="0" O="false" N="TimeToRenderInitial">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="TimeToRenderContainer">.. <S T="1" F="1" />.. </C>.. <C T="U32" I="2" O="false" N="TimeToRenderPlaceHolder">.. <S T="1" F="2" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3232
                        Entropy (8bit):3.668625032816456
                        Encrypted:false
                        SSDEEP:
                        MD5:558FA25A780A9E5DE8ED13A75878734B
                        SHA1:1C145DA0088A919E275021518112AEA0329590E4
                        SHA-256:341A12CAF0766CD590E3928288C2CECFE1F1141428CB74A429A51FBA348716F6
                        SHA-512:0F2376926E2BFEFA007BE39B5199D63EF0CFD0FA50DC170F5E1C1AC9203D5B0D73A0465475EABEA5F3E74C2BBF3BCA2EC3D2EA54424CAE97A74F611A6F75397E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11932" V="0" DC="SM" EN="Office.Outlook.Desktop.RNCardTimeToRenderInitialBucketed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11930" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3343
                        Entropy (8bit):3.7999978378778105
                        Encrypted:false
                        SSDEEP:
                        MD5:D8461954EBFB716661E5BDF2FCAECA18
                        SHA1:B332465A784172E7FAFB36D8104D516C91216B7B
                        SHA-256:EEE0C229D39D77830C70AA685C3045446B05CA060542B7FA9DD596A230115833
                        SHA-512:D6FF65A7CF38783130FCAA5BF6EBD891777E77167F16A39647FC8D2A62322D48B86B853B301AC11E1399F715A3F31AB1DD895DD3659901E140F5379B2E2BF36D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11933" V="0" DC="SM" EN="Office.Outlook.Desktop.CCV2TimeToRenderInitialBucketed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="dfds4" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="Milliseconds" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="Milliseconds" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="Milliseconds" />.. </L>.. <R>.. <V V="250" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):692
                        Entropy (8bit):5.118026988954907
                        Encrypted:false
                        SSDEEP:
                        MD5:43012D6BF297C1BFE84236A092004A50
                        SHA1:4F23B57FAB8E45C815A98BD6D565FD35CA0136AC
                        SHA-256:B8C191C64060AF6E32A9AE559CEE97260FC5F27DFA8FFE3C2F30454A11B3AA47
                        SHA-512:73B349A9E341591FE0F2840A64C9C6C6AC4F682F62EE2AB06203CAAFE69572FAF441D43F27389A9341184659DE1C9942EB2FA2CB0372ADF6694CEA1FAF5C9E66
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11935" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CLPGuestsDisabledInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="93uka" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="GuestsAccessDeniedFlag" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="GuestsAccessDeniedFlagType">.. <S T="1" F="GuestsAccessDeniedFlag" />.. </C>.. <C T="U32" I="1" O="false" N="CountGuestAccessDenied">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):654
                        Entropy (8bit):5.237577883627452
                        Encrypted:false
                        SSDEEP:
                        MD5:6C4CCDD0E1B3D064B84446263F132472
                        SHA1:24C266C590E93F235753F777853BAE022C3A50A4
                        SHA-256:DD0AE757A8831C13355CB95D6D282E99782E08D6FAB2B85B5BC6FC54B11A391A
                        SHA-512:BC34F98E3DB482142BD6057ACCCE22BA9A1BFD6360F9E99F2EB1981C9AEF47868D39FB854A356A3B97F8945C00E5F8C8B1B225974BE952870A79E84476A3A23E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11936" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CLPSensitiveLabelInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="93uj9" />.. </S>.. <C T="B" I="0" O="false" N="ClassificationPolicyEnabled">.. <S T="1" F="ClassificationPolicyEnabled" />.. </C>.. <C T="B" I="1" O="false" N="SensitivePolicyDataExists">.. <S T="1" F="SensitivePolicyDataExists" />.. </C>.. <C T="B" I="2" O="false" N="SensitiveLabelsExist">.. <S T="1" F="SensitiveLabelsExist" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1456
                        Entropy (8bit):4.609599678025888
                        Encrypted:false
                        SSDEEP:
                        MD5:D3FA94873D89CAF3E0DC512160ABB784
                        SHA1:B0456568040EE18730406D0A9A5F5D401C0863E0
                        SHA-256:3D62586F1F73D22EBF85CAE417F5F0E4C9D127172850F458699D7361082B2CA6
                        SHA-512:4A7777B75390ADB600CB079B36AF61C3D4E5E9063874D45AED4C975CA8B212E3FB74C15D3EF2CC704430EE131006802995D08F16744A54185DEE74D38DB3AA48
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11938" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.JoinOnlineFromToDoBar" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1026" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OnlineSessionType" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OnlineSessionType" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="OnlineSessionType" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountJoinOnlineButtonPressed">.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):410
                        Entropy (8bit):5.24802525642993
                        Encrypted:false
                        SSDEEP:
                        MD5:29B4742E3E9098FBBDA01AA24762F903
                        SHA1:2188097389FCFE2AF0A7E39D3BE58A78AEBA44CF
                        SHA-256:83836DD02393239B51B179D9AC516EFA1416AC5292AA09BB49454645535DD458
                        SHA-512:DD119321EA9B63CD3092D06118C70F1F0E45DFEB505021E7F7DE4D60335B31A149427C12EA9DB73778B9569FC7156E1D056E003A78F348162B13AEB0247AE838
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11939" V="0" DC="SM" EN="Office.Outlook.Desktop.CCV2TimeToRenderInitial" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="dfds4" />.. </S>.. <C T="U32" I="0" O="false" N="TimeToRenderInitial">.. <S T="1" F="Milliseconds" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2564
                        Entropy (8bit):5.120412466327161
                        Encrypted:false
                        SSDEEP:
                        MD5:666C483A33B473397C31C2AE9D2FBDB3
                        SHA1:6B1AC0C817939DC0068E13DC2A1FC93B61F81E76
                        SHA-256:6774161A7D5651F86286A6D45A568735C244ACAFDF9D2EECEE2D01BD75B0524F
                        SHA-512:B6236647406E9A2A16F216DA3E33DFECE2FAF577F20F59A55517E3DB0F58643DB9864D42F1F14C73C81BF9F1BC14195F5B3B66DBB09F6FC2CC2BD25FB4834E57
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11940" V="7" DC="SM" EN="Office.Outlook.Desktop.OPX.Performance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="356" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="1" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="1" F="WebHostingSessionId" />.. </C>.. <C T="I32" I="2" O="false" N="CreateWebViewElapsedTime">.. <S T="1" F="CreateWebViewElapsedTime" />.. </C>.. <C T="I32" I="3" O="false" N="ConfigTokenAcquisitionElapsedTime">.. <S T="1" F="ConfigTokenAcquisitionElapsedTime" />.. </C>.. <C T="I32" I="4" O="false" N="TryNavigationToNavigateCompleteElapsedTime">.. <S T="1" F="TryNavigationToNavigateCompleteElapsedTime" />.. </C>.. <C T="I32" I="5" O="false" N="TryNavigationToGetConfigElapsedTime">.. <S T="1" F="TryNavigationToGetConfigElap
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):781
                        Entropy (8bit):5.09359922095744
                        Encrypted:false
                        SSDEEP:
                        MD5:BAEC21F0C30BF264FF26C8A5751737B3
                        SHA1:15C8990C1AF86CBEB35B63D8D889723CD45E11C9
                        SHA-256:6BF02A41126C4937EE480E567059DF3C1F55B3AB4C5317163DEC0BC5780A7AB1
                        SHA-512:BBFC6C00B323AA7BBE2A5CEB3EBB6B1652C9F7D59A5FEE56FEAFF45F7ABEF8F3532BDAD537F4E33836E513221BA2B25CE8942DE6C5A5B84115B89D2F43EAEA53
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11941" V="1" DC="SM" EN="Office.Outlook.Desktop.Mapi.ProviderDllLoad" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="633" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="KnownMapiDLL" />.. <F N="SCODE" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DllEnum">.. <S T="1" F="KnownMapiDLL" />.. </C>.. <C T="U32" I="1" O="false" N="SCODE">.. <S T="1" F="SCODE" />.. </C>.. <C T="U32" I="2" O="false" N="DllScodeComboAmount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):756
                        Entropy (8bit):5.202160271633777
                        Encrypted:false
                        SSDEEP:
                        MD5:E1122B57E287C1877FA5315D9BBF69A6
                        SHA1:3074795ABA811348349F03B901612F6DDAD5AE13
                        SHA-256:7D1688B0D9262DF123FD483568DD0E57A9DD41C943524CF57863B04CA7D4DED4
                        SHA-512:8E5FA31DEB789604CE517D998815350704001F8E6425A15607326E468AC57BD2338479CFCA872250EE2CDA48601B5945C89B29F120BEE2970B6289579BA3ABA0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11942" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EditDlgMIPInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9348a" />.. </S>.. <C T="B" I="0" O="false" N="ClassificationPolicyEnabled">.. <S T="1" F="ClassificationPolicyEnabled" />.. </C>.. <C T="B" I="1" O="false" N="SensitivePolicyDataExists">.. <S T="1" F="SensitivePolicyDataExists" />.. </C>.. <C T="B" I="2" O="false" N="SensitiveLabelsExists">.. <S T="1" F="SensitiveLabelsExist" />.. </C>.. <C T="B" I="3" O="false" N="SensitiveLabelsChanged">.. <S T="1" F="SensitiveLabelsChanged" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):631
                        Entropy (8bit):4.405615805083732
                        Encrypted:false
                        SSDEEP:
                        MD5:25254D7ABE472DE6031DE7BD706A418F
                        SHA1:7BB1C3AC2BE6A9D24C1D58F7EA991ADFDC66EAFD
                        SHA-256:99FB31F55785E7EF651718044BF81F08980F60612E46DBE2656D790B2DF9B33D
                        SHA-512:F8959DBD060099798EC3314C86AEAB9C4E7EEE6477ABD98FDED76282A17D33E647A1AEF6BCD6FC5457B514D15A85E294855B2FCD3F20B74EABC9483446CF3AC2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11943" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="a1dp6" />.. <UTS T="2" Id="a1dqe" />.. </S>.. <C T="W" I="0" O="false">.. <S T="1" F="ScenarioName" />.. </C>.. <C T="W" I="1" O="false">.. <S T="2" F="ScenarioName" />.. </C>.. <C T="U32" I="2" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1087
                        Entropy (8bit):4.862865929474717
                        Encrypted:false
                        SSDEEP:
                        MD5:FF81F3CA8A56494C6A3E5D4565AC8516
                        SHA1:B45684CAA68938A6060041DA1738A405A1CDCAA6
                        SHA-256:05D0BE526FEBB984EC3EBC8217364E10F5A119201E3CBA9A9364168B8698FED6
                        SHA-512:339F02B5A5E4B992D7B7C0661900A20E742E04D0A6EE19AAFF5369B0F16B20A0CE89CE635277D5B5D32100F8A4B3948D62796446835D58656C0AE40CDA1BCB8C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11944" V="3" DC="SM" EN="Office.Outlook.Desktop.OPX.WebView2Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="357" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="ControlId" />.. <F N="WebHostingSessionId" />.. <F N="Result" />.. </S>.. </G>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="4" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="4" F="WebHostingSessionId" />.. </C>.. <C T="U32" I="2" O="false" N="Result">.. <S T="4" F="Result" />.. </C>.. <C T="U32" I="3" O="false" N="TotalCount">.. <C>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1029
                        Entropy (8bit):4.709873309115686
                        Encrypted:false
                        SSDEEP:
                        MD5:9E5FF3D3F1E264B2A77BB1183A5330FA
                        SHA1:C584EC185628FAE3633C066080907C20C138ECFD
                        SHA-256:D8EC66E15E8C9049C48032559B04B95E1CEEA42396097B95E5CEEB10C774198B
                        SHA-512:FB7421E1BE697AC637439FAA36B8ABBA408684A67DCB4ED4F286CD3AAD3C43A9287D690E04A9BF130FC26F70441AB8542E7E2F78C6455732A4E0C2335CD5A476
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11946" V="0" DC="SM" EN="Office.Outlook.Desktop.OABBrowseAndSearchUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3402" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="isOffline" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="isOffline" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountSearchOABOffline">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountSearchOABConnected">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1286
                        Entropy (8bit):4.941151920409955
                        Encrypted:false
                        SSDEEP:
                        MD5:CE9B8DB9494922C8E502F0C849945E4F
                        SHA1:D1483FA4700903E0F8E99810F361EF8BC2621340
                        SHA-256:B15CE7950544B1699E8390054CC55E8D0F95DDBDECD043C1D16E22D2326AAC6D
                        SHA-512:BDC7FC89783ED7D1E12E19CAEA8CF94B08A83FB649579C7DD278385B8887397AAB497BD12F7227543978657B8AFAC5F6DE1EB5A94BACD328343E7FD829739282
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11950" V="0" DC="SM" EN="Office.Outlook.Desktop.Ndb.OpenedStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="800" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ErrorCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="2">.. <F N="LocalStoreFullFilePath" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="NdbVersion">.. <S T="2" F="StoreVersion" />.. </C>.. <C T="U32" I="1" O="false" N="FileTypeMagicNumber">.. <S T="2" F="LocalStoreFileType" />.. </C>.. <C T="U64" I="2" O="false" N="FreeSpaceInFile">.. <S T="2" F="FreeSpaceWithinLocalStore" />.. </C>.. <C T="U64" I="3" O="false" N="FileSize">.. <S T="2" F="LocalStoreFileSize" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):610
                        Entropy (8bit):5.238735860448927
                        Encrypted:false
                        SSDEEP:
                        MD5:2EE4B1704D2B9448D7D668E8B6DAE167
                        SHA1:8811A1C2BA5FBEF5C0554B37470AA04D274A5C90
                        SHA-256:838E64973E4A10B67D3B0A1A94F9826E799F1427FD48431335B5000B6D5F41A0
                        SHA-512:7839B4F312011669342EBD5EB2C3A3D3B3E95F26F3D46E7C258B16443C2EC0A8D525575D8E38CF22129DD28B5B79034F77E4DEC9C7225EEC74F21C408718A175
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11952" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.ConnectionErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="358" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="1" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="1" F="WebHostingSessionId" />.. </C>.. <C T="I64" I="2" O="true" N="Result">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):487
                        Entropy (8bit):5.215584085516877
                        Encrypted:false
                        SSDEEP:
                        MD5:F623887B1E1DE93617A4F8D5FC5311EC
                        SHA1:9547D43413583997D31AE8026DFC56F6EF83908C
                        SHA-256:B850FC4A6D9D777B2BD0F1AF86C0745C23459902263C869A420D45CACF012E91
                        SHA-512:A525411A0CF47E1D76634DCDBE044C31D4435A09E35EE88E2D2F1786B1EC2640399A6424D6F35B62617E710E91B18E6E3E07C12DEF4D397C84599A989720A84D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11959" V="0" DC="SM" EN="Office.Outlook.Desktop.CountOfAddGroupMemberDialogGetDpi" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zwv2" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountGetDpiCalled">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):9172
                        Entropy (8bit):3.925558248923313
                        Encrypted:false
                        SSDEEP:
                        MD5:FA851A2B33EDD754B355B8B4F81D6B12
                        SHA1:1FC7E50DE3F59A6FAD36D36E04286FC0579D98C9
                        SHA-256:8D829F4CB237FCA8FB3CBE49F58F45681BBE844A7149F24A631C79D82E4DCA21
                        SHA-512:A63E963FEDE605EE0F2E742D62752D323FE88E820C461EA7B2C107409F530436D0CFF399BD5D2B4888F1EF2B3FD35A1169791E3F678D8BA5581156EE1A9A90E6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11961" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsLogonHelperErrorCodeResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2066" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="GE">.. <L>.. <S T="1" F="HResultRun" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="4"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):8429
                        Entropy (8bit):3.9531412413732308
                        Encrypted:false
                        SSDEEP:
                        MD5:230BC7859C03FBB09F24EA9FDF3F93F7
                        SHA1:E366F4D2FE911930801D2C86D16C2D318D599CE4
                        SHA-256:79A45A8E36F2A2FCCB967E5B1C328945DEF848F313BEB90A224AE9844348204E
                        SHA-512:670E3F124BD4959B346C899766BAC13F3AF16DF59219331DF2EE790B979A4154B4092A8733D377205BBE148C0211D20E71F72F97D79566EDC6E516C43879D8D9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11962" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsLogonHelperEcGlobalError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2066" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="EcGlobalError" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="4" F="ulStoreInfoDataBytes" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):725
                        Entropy (8bit):5.253946454742253
                        Encrypted:false
                        SSDEEP:
                        MD5:3BE3BA16A95DF160733E232316647C6F
                        SHA1:17A57D2D4EDDA899CCFA0B7BC5D6170EC30268DA
                        SHA-256:6B37EC6FCC1C2661F7982799F452F3AD97299B9DD64AC1C263FEBFC669753069
                        SHA-512:766731FCED3B205E31CF9D2B3ADEE6232948793D477CAAB1D285AAF2A2798DF247D6542110F8CEB2A00610C35B102262CF7B5EBFF46E927B70C9D4A3BF56AF65
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11964" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8g" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="U32" I="1" O="false" N="DescriptionLength">.. <S T="1" F="DescriptionLength" />.. </C>.. <C T="U32" I="2" O="false" N="GroupType">.. <S T="1" F="GroupType" />.. </C>.. <C T="B" I="3" O="false" N="IsByDefaultAutoSubscribeOn">.. <S T="1" F="IsByDefaultAutoSubscribeOn" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):506
                        Entropy (8bit):5.286616073715708
                        Encrypted:false
                        SSDEEP:
                        MD5:DB54B30581DD2DB341E2B3586346D231
                        SHA1:879A7418F3B8E295882506CF1243416FDC50AA89
                        SHA-256:232A05CF9341D7181092A5AF1552469F1AD925B21A7FBDBAC76D9CFE60024253
                        SHA-512:C2071EA18C026A1FD3356407DD410A15883B32D29B77702823445D19AC020BBE8B6C8165A216DDF00DD026A3B60CCF72303F442475D1FBEE96EA5BB34D4A1287
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11965" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8e" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):521
                        Entropy (8bit):5.284810778509163
                        Encrypted:false
                        SSDEEP:
                        MD5:D552E7B4F302A1D60E65CF54581A09ED
                        SHA1:CF197B29FF87811BDACF1408375549A38B482657
                        SHA-256:CF0679FF2CCD262B41E632ADEEA82BA3140D9FC7FE5F2FC188E33B5FF37C6CE2
                        SHA-512:96FD4B5FB7F4DC265E815614862EE5E9029A64D018AA3C918ED4CF056EC2A09439783A8A310C0CF3361B9C60B5A512B3F6CD5109548BE5472F76664E516D376D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11966" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogServerResponse" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8d" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1012
                        Entropy (8bit):4.693424474775187
                        Encrypted:false
                        SSDEEP:
                        MD5:04D7FB0C5837D3D88EE00714E91C3C36
                        SHA1:1CD948BB0F911B97A339427CE48C990FAA7EE38D
                        SHA-256:C8DBCC9687A2D76DC57E9D289926F5640EDA624E7419F23C6EA14BAA83446075
                        SHA-512:1ADC7946FF4AFED0A8C8D88D1AF1BD3740B42E7624574E6945369C412D0589CD97E97B36E54BE66D99F5E8EE1310DAD4D29ED9A393961C531DF94E0986F1F589
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11967" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogAdvancedSettingsHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8c" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsSucceeded" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsSucceeded" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Success_count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Failure_count">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5915
                        Entropy (8bit):3.8679735216721216
                        Encrypted:false
                        SSDEEP:
                        MD5:29863DB9317D0807F97B869B8A3010E1
                        SHA1:19B84334C40BEBCCE0C0C4EFBD75040EDE4463F3
                        SHA-256:3C5F1DABFD0C7E405510556B4FAA36ECCB2A20E31A9FA15E9D56BD2CC42F6F98
                        SHA-512:E07193831ED8F100147C144DDEB952DEDC53DB1AA0297B65C6970E3D05B167C4F78C20E088477A246D12D52E68DE8316B4A3714C2590371FB4E93BB88D224FD5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11968" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogDialogDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8b" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):655
                        Entropy (8bit):5.099623030102572
                        Encrypted:false
                        SSDEEP:
                        MD5:61D604FE9C10A79D895445C388AEF8ED
                        SHA1:99F1790396119C8BC4623E8496D95BBA8CD69476
                        SHA-256:D3CC089E9610A61E4D025180E0D5B4203FFBACEAB493746DD3685696FE61A7AD
                        SHA-512:4C201A724CE48F0D29D48990A9947F8B8FEDE1E3BB6562B6C7802E631EA3463EA58BABD630F7BFA2603788DA119852C6CF2F747DB1AB98D4D73A0929A05FE51C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11969" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogExitActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8a" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):785
                        Entropy (8bit):5.133376137351738
                        Encrypted:false
                        SSDEEP:
                        MD5:DD91A12BDA190B323116AA48DB4AD9B0
                        SHA1:FB22048F433031D02E411A7C04BA2B28D3C4118C
                        SHA-256:2D09AB06E29F58A711DB98A92F8CDA1C274D4C973E1DCC621F83C022A19AE721
                        SHA-512:0D4C6DA6A2167A62F0DE202EE6FB757B7B9B93F830AA9003752D0E822EB314C9ADCB07CE2A8D1268FAE1340790BA9D9FEE225B2A931661075B8E1121C00137CC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11970" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogClassificationUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg78" />.. <UTS T="2" Id="9zg77" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ShowDialogSucceed">.. <S T="1" F="ShowDialogSucceed" />.. </C>.. <C T="B" I="1" O="true" N="ShowClassification">.. <S T="2" F="ShowClassification" />.. </C>.. <C T="U64" I="2" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1120
                        Entropy (8bit):5.155222805182783
                        Encrypted:false
                        SSDEEP:
                        MD5:080F8B0FF36E8B69CF754D2D69DE4D67
                        SHA1:1EB72E631B5E4FB7800DBEA205AA2C9200213320
                        SHA-256:1B842848ED8923C151CE45C25676BEEF93F2737ED77B57B52C02BF720B4DC99E
                        SHA-512:70AFC546556EF2B049B8955E7CF163DBB1C849B54A355904092F47E382FFA4BE15ACB8E1723C39DF0024B0CA40A04E6D034629B72DFA7FAF5DD81E0EAD954C32
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11971" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogGroupCreationInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg79" />.. </S>.. <C T="B" I="0" O="false" N="LanguageChange">.. <S T="1" F="LanuageChange" />.. </C>.. <C T="I32" I="1" O="false" N="PrivacyValue">.. <S T="1" F="Privacy" />.. </C>.. <C T="B" I="2" O="false" N="ClassificationChange">.. <S T="1" F="ClassificationChange" />.. </C>.. <C T="B" I="3" O="false" N="AutoSubscribedCheck">.. <S T="1" F="AutoSubscribedCheck" />.. </C>.. <C T="B" I="4" O="false" N="GroupIdEdited">.. <S T="1" F="GroupIdEdited" />.. </C>.. <C T="B" I="5" O="false" N="NamingPolicyEnabled">.. <S T="1" F="NamingPolicyEnabled" />.. </C>.. <C T="B" I="6" O="false" N="PrefixSuffixEnabled">.. <S T="1" F="PrefixSuffixEnabled" />.. </C>.. <C T="I32" I="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):5907
                        Entropy (8bit):3.864357021842609
                        Encrypted:false
                        SSDEEP:
                        MD5:B0C9F347594B94FBC48B49F15E9CA0E2
                        SHA1:844BF589FFE0A5634759EE427006780BEF940026
                        SHA-256:4732E5257F4E2F14245B5343D52E90076FDD7C9C42D336FF1CBBC782AA14E8DB
                        SHA-512:A67DBED2FFBA44CBC000EE8AB2BC71510C8749B741E0DCE49334B17F2915CADE006E848E5425B865AE12283FD927865191F1D0C12B92EB0314E8F1CDBE6A1D8D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11972" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedEditGroupAfterCreationDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg73" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.. </O
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):941
                        Entropy (8bit):5.094054980247312
                        Encrypted:false
                        SSDEEP:
                        MD5:531E6081F18CC5320370AC8586CB9220
                        SHA1:586FBC63288A8433928D0BB960BCA2F34EBFB812
                        SHA-256:C1C6D813B9E969A0C6FAA8170C905808D193EE50013E7903806E93ED27960593
                        SHA-512:730ECAB3E963A2149C0381D5691227536C04ABA95D096C9032EF3BB756DBAC14547419525E3C28F5434F144C2C1DCE59D5C3EB09C92A605B92AD13794DD2E545
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11973" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7y" />.. <UTS T="2" Id="9zg7v" />.. <UTS T="3" Id="9zg7z" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. <S T="3">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ShowDialogSucceed">.. <S T="1" F="ShowDialogSucceed" />.. </C>.. <C T="W" I="1" O="false" N="DialogType">.. <S T="1" F="DialogType" />.. </C>.. <C T="B" I="2" O="true" N="ShowEditPrivacy">.. <S T="2" F="ShowEditPrivacy" />.. </C>.. <C T="B" I="3" O="true" N="ShowClassification">.. <S T="3" F="ShowClassification" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):626
                        Entropy (8bit):5.2687844045623775
                        Encrypted:false
                        SSDEEP:
                        MD5:6DB84A1957751410766FC2EB671391F5
                        SHA1:431D04E45FC4DFF05690234ADA6A33FD669E1F45
                        SHA-256:9CB015C8FEAA90824E8E3992684170576C73C5ADCD2656FAB9EDA8116C0F4652
                        SHA-512:1DB706C5FF842C0CB22A71CE474CC46CCBBD8AE61662022F63BC70C76E912545EF68D1452236E9C1A2ED4D3130939915EB58BE14D8148CA61B3ABF52E317B010
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11974" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogBulkAddGroupMemberActionData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7w" />.. </S>.. <C T="B" I="0" O="false" N="ActionSucceed">.. <S T="1" F="ActionSucceed" />.. </C>.. <C T="U32" I="1" O="false" N="EWSErrorCode">.. <S T="1" F="ErrorCode" />.. </C>.. <C T="U32" I="2" O="false" N="MemberCount">.. <S T="1" F="MemberCount" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):658
                        Entropy (8bit):5.109562528870546
                        Encrypted:false
                        SSDEEP:
                        MD5:26320703594403DA31BABF5692F2D842
                        SHA1:044B79B6A0CCFACDED71767DA2F1A866F5306330
                        SHA-256:F6A14666B64A961D2E3A37D0B06288606266380F017AB2D0E1C9F875F9D8460E
                        SHA-512:2D539C4A77A86907431CF50F1FC4A40544194DB0B128032035FBD38DBF726EEA7151F357EA02CAFD46BBA8F5B01E0081116C0E528D9AF8D278548FBCA622B55E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11975" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogExitAction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7t" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1277
                        Entropy (8bit):5.069243664148278
                        Encrypted:false
                        SSDEEP:
                        MD5:10C3B32210DC96137147105352EC3C0F
                        SHA1:3CCA9701D40E56411F96680418B890C1DCB6D503
                        SHA-256:633BBEB3BECBFD43320EEE5FFBCF1AF7AD23B03ECDBF391D94E6BE974D15C027
                        SHA-512:9FBDD3AB23C4322156DD216ED4079F8D36F7E812AA59114A06380F88FEE78B359ABC68C2EDE9BFFDDB0E2C45F76BA80DE0C9D5A9A08FA1405EA6D2A34364A4FE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11976" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogEditGroupActionData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7q" />.. <UTS T="2" Id="9zg7m" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="B" I="1" O="true" N="AccessTypeChange">.. <S T="1" F="AccessTypeChange" />.. </C>.. <C T="B" I="2" O="true" N="NameChange">.. <S T="1" F="NameChange" />.. </C>.. <C T="B" I="3" O="true" N="DescriptionChange">.. <S T="1" F="DescriptionChange" />.. </C>.. <C T="B" I="4" O="true" N="AutoSubscribeChange">.. <S T="1" F="AutoSubscribeChange" />.. </C>.. <C T="B" I="5" O="true" N="LanguageChange">.. <S T="1" F="LanguageCha
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):872
                        Entropy (8bit):5.126905660124621
                        Encrypted:false
                        SSDEEP:
                        MD5:833BDF9FF151747B2E2F8CEDC1BDFA2B
                        SHA1:CFBC8A5B48B47D2F9507B74C9D6CC77D8A7C18A0
                        SHA-256:E3C1C251FBA2940EC9F340F2998137AF98999FCB2B5EAACFB46FB975CF6A0737
                        SHA-512:0B2C402EE1B6792B0072962EACB83F0397C343074FF5D3F7D9B99852DE6023DA306482D0D219FDD35D5ADBCA54C6B3A5FA8325257AEA33517D8E4B0740D31977
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11977" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogEditGroupMember" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7p" />.. <UTS T="2" Id="9zg7l" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="W" I="1" O="false" N="OperationType">.. <S T="2" F="OperationType" />.. </C>.. <C T="U32" I="2" O="false" N="TotalChangedMemberCount">.. <S T="1" F="TotalChangedMemberCount" />.. </C>.. <C T="U32" I="3" O="false" N="GuestCount">.. <S T="1" F="GuestCount" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):956
                        Entropy (8bit):4.868383145752248
                        Encrypted:false
                        SSDEEP:
                        MD5:D5D0D6FB40B55FE7207BDD1261715FDF
                        SHA1:41AA942B5F85D47DC685A1258175BE88920698A5
                        SHA-256:55D282F4A5A3FE83F02D12465E266757FDE286AC15610BB6ED6A3578EB7E9F2F
                        SHA-512:AA799F051F7058A422235BE6E3AE2D50F9A2F584EDDD3C3803DE6838D1F5D00D3157189B192D2A6CBB19CF6ACFFE3835BF169A1F5B709FEAA5A477301B6C3578
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11978" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogAddGroupMemberEmailValidation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7j" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ActionSucceed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="GuestCount">.. <A T="SUM">.. <S T="1" F="GuestCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="FailureCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):752
                        Entropy (8bit):5.0180794961343524
                        Encrypted:false
                        SSDEEP:
                        MD5:D246744886F012EE5E32F94A6783D0EC
                        SHA1:73F1B96C797D85CBED01920C2BAF4B5406766B23
                        SHA-256:D9B93901326A5782EFDEFAF82D2632804ABCC1A75B1ACD13C8AF1AE04CEC5F42
                        SHA-512:D5768241AD6A786067BD28305E7C2B1DFBB5A2D7A7A7E1E23395A8E624FDFCACB21849F5A485A409278D36B66D5AE074170BDFC367FDA6ED229A25F6E7790F6F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11979" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedDeleteGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7h" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. <F N="ResultCode" />.. </S>.. </G>.. <C T="I8" I="0" O="false" N="Action">.. <S T="1" F="Action" />.. </C>.. <C T="U64" I="1" O="false" N="ResultCode">.. <S T="1" F="ResultCode" />.. </C>.. <C T="U32" I="2" O="false" N="ActionsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1107
                        Entropy (8bit):5.00784820344696
                        Encrypted:false
                        SSDEEP:
                        MD5:2E1FBF3A1C0C423AD11151651544A55D
                        SHA1:5E6D59971529DC0103C8E8484283250F39D6D19E
                        SHA-256:77C89E571062F497E4799AE6D65D4F349D0534E21A422290635CF73C3C45C1C3
                        SHA-512:6A2FF06D21BDE9CAD21772FCE4F255B5D09DAE675BBE59984502CC90C9CA8CFB7D6A1BF89A0E841AA3322C7D63272869761FB149DC123655540760BD25E9BBE1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11980" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.UnwarrantedDialogsLoads" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalExperimentation" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="9zb0h" />.. <UTS T="4" Id="9zb0j" />.. <UTS T="5" Id="9zb0l" />.. <UTS T="6" Id="9zb0n" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfIllegalCallToUnifiedGroupErrorDialog">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountOfIllegalCallToDeleteUnifiedGroupDialog">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountOfIllegalCallToCreateUnifiedGroupDialog">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="CountOfIllegalCallToAddUnifiedGroupMembersDialog">.. <C>.. <S T="6" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):487
                        Entropy (8bit):5.203053398959187
                        Encrypted:false
                        SSDEEP:
                        MD5:8507C9CED3B6414E8F14B25E1555927B
                        SHA1:86A1E9B5331695D595BB7E4200DDCEBA6158709F
                        SHA-256:E0D836D4FA2CDB90B7D8930B43142500BA226A8D95EB91C238ED0396433F3CA8
                        SHA-512:0BD8108426058B10051B1BB679AB8D7BA0AD2ADBAA92F689751DD2B24DC19072DA1BB6E5733A4BB986F34227F236A6063D1BCF14D4A175A51B942E567BEBA979
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11981" V="0" DC="SM" EN="Office.Outlook.Desktop.CountOpenOutlookPropsDialog" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zwv1" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountOutlookPropsDialog">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):895
                        Entropy (8bit):5.150260960535219
                        Encrypted:false
                        SSDEEP:
                        MD5:9A129952A56076F0520EBD235195DC7B
                        SHA1:F5DA019E82A8B0C7F702553951B497504C173CAF
                        SHA-256:E5CE06758483C0F4C7FFDB0F8EDF6CA03B7C8FE0CADB45C786524FB2C5DD07CB
                        SHA-512:49921F6EE711B3F66F501746C8D89DF7715EBB46734BF275DE40ED010132DD397866EB650D08AE5C89AA4891BD2DBA83929579B824C6CA0A13F6744621452202
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11987" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentPreviewPerformance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4307" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="AttachmentCount">.. <S T="1" F="Count" />.. </C>.. <C T="B" I="1" O="false" N="IsOfficeFileExtn">.. <S T="1" F="IsOfficeFileExtn" />.. </C>.. <C T="U32" I="2" O="false" N="AttachmentMethod">.. <S T="1" F="AttachMethod" />.. </C>.. <C T="B" I="3" O="false" N="IsSuccess">.. <S T="1" F="IsSuccess" />.. </C>.. <C T="B" I="4" O="false" N="IsReadingPane">.. <S T="1" F="IsReadingPane" />.. </C>.. <C T="U32" I="5" O="false" N="ElapsedTime">.. <S T="1" F="ElapsedTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2151
                        Entropy (8bit):4.471184011582431
                        Encrypted:false
                        SSDEEP:
                        MD5:393632731A4B18D83A19046C47F5B765
                        SHA1:714CF03294CE099D564627CD2FE5719E685B577E
                        SHA-256:FE9BC082E9804C2BC60099D34AE67605CB9574BB4E4073EA486DDEE002A62516
                        SHA-512:6401E3C54F405F260725F9CAC5FD04A501308AD692FC243A0B7FA03D72BA7D9D8F89C1C4ACFACD82D28540D2E697182BEA7D2741DD2FAA99AF7DE574FE4D03DE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11988" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.EventPeekOpenUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="430" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="607" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsMeeting" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsMeeting" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="IsMeeting" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):700
                        Entropy (8bit):5.2050849295587565
                        Encrypted:false
                        SSDEEP:
                        MD5:A6C4CF6994B6E5731403968AC85C282D
                        SHA1:6D2C8CC03EABE3162A4D0D6FD624337B971908FB
                        SHA-256:CE604316D3B48AF632D17E4E8DE9D769AD33E0D958A0BE8B2E0A0FCC98F05A09
                        SHA-512:556B01FB783C6E1D163509B4305E499199DCD246434147DF2F76192415509245A8B1277C7A7C8F305301D7DC41136A234E6C9AE8765C6B4509F80FFB3129F72D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11989" V="0" DC="SM" EN="Office.Outlook.Desktop.NDBCorruptStoreRuleSampled" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="319" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="U32" I="0" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="U32" I="1" O="false" N="NdbType">.. <S T="1" F="NdbType" />.. </C>.. <C T="U32" I="2" O="false" N="Version">.. <S T="1" F="Version" />.. </C>.. <C T="U32" I="3" O="true" N="CreatedWithVersion">.. <S T="1" F="CreatedWithVersion" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1044
                        Entropy (8bit):4.993396824578967
                        Encrypted:false
                        SSDEEP:
                        MD5:D45E832799C97EF7C7F009C9B4253BA6
                        SHA1:36449FD50540496200125065B00BB287BD247FC6
                        SHA-256:FC91BF1DE6C4FFD3B2911459174B86AF2A7267C1380366A1C29F1BA29ADCACFC
                        SHA-512:56809D8E610F1F30A14C47937E57C38A8D0C176C00A9DFFDDCE9959775BF1265736FE330A57191333835F232B40DB04B51A12D8A23716ED2E4584D581FB53F22
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11990" V="1" DC="SM" EN="Office.Outlook.Desktop.ReadSendMailEngagedUser" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19045" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19046" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="AccountUID" />.. </S>.. <S T="2">.. <F N="AccountUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <O T="COALESCE">.. <L>.. <S T="1" F="AccountUID" />.. </L>.. <R>.. <S T="2" F="AccountUID" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="ReadMailCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SendMailCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1899
                        Entropy (8bit):4.862540150008505
                        Encrypted:false
                        SSDEEP:
                        MD5:83B1DA95E45E4F977BF1242B8E3CFE9F
                        SHA1:5D0628F1D7DAE6CAE095AA48F08607EB03AC6B16
                        SHA-256:2E0ACFFAB4675F886DBF1891CDC2C896E30276353668252A29B9A0F98576FDB9
                        SHA-512:37C33E0AA9882A281A5F6CBDC1C6740C93FE7C42EC96032599FF1C1C54585BCB587C48D71B13AC1B7663A10F5D2929CE6A542911A650988790AF17BCEA6E30EC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11992" V="0" DC="SM" EN="Office.Outlook.Desktop.EmailTranslatorMgrMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9y3sq" />.. <UTS T="2" Id="9y3sp" />.. <UTS T="3" Id="90jqt" />.. <UTS T="4" Id="90jqs" />.. <UTS T="5" Id="90jqr" />.. <UTS T="6" Id="90jqp" />.. <UTS T="7" Id="9y0my" />.. <UTS T="8" Id="9xohn" />.. <UTS T="9" Id="90jqq" />.. <A T="10" E="TelemetryShutdown" />.. <TI T="11" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="NeverTranslateLanguageStampEmptyErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="AddNeverTranslateLanguageErrorCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TriggerServiceTranslationRequestErrorCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="CheckTargetLanguageEmpty
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):860
                        Entropy (8bit):4.960956486784933
                        Encrypted:false
                        SSDEEP:
                        MD5:BB9DDC2E6CD1B7BFDE7075C9CE7A08F4
                        SHA1:DBD0DA74E5CE7789D607DD411A5178E5592557FB
                        SHA-256:54457F58DBECE89DEDAAA3590F5509C6F0AA64614589EE9076B43A83BBEE8D64
                        SHA-512:AD1428922AC811982685DF415A275EE326345C96B26416CCC81DF8D4DFC124839AEA65B1B500915CA3828E4ACC8A3593EBE1EC050001811885A189843D89AE3D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11993" V="0" DC="SM" EN="Office.Outlook.Desktop.EmailTranslatorMetricsCoreMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9x7n3" />.. <UTS T="2" Id="9x7n4" />.. <UTS T="3" Id="9x7n5" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="LogOperationFailedToStartCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CantStartTelemetryCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="LogOperationFailedToCompleteCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1025
                        Entropy (8bit):4.931847309173289
                        Encrypted:false
                        SSDEEP:
                        MD5:B4C156D0C2FD62D147879749E23C1AE5
                        SHA1:AE6FDD3FB575C91B8078B8AB92224296CEAB550A
                        SHA-256:5D4203C453A7A707FBC55CBD76388BDCCAB9D5A155F9426939BCF7497D76D01A
                        SHA-512:7B77F91D07A1B4A023FB4F3BBF8C348482FED952239EAD583E9096D89701218204F1A81E2D8DE5DCD88159E5A0DB4F5F73279023E1FF1DC9B12753D79E187611
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11994" V="0" DC="SM" EN="Office.Outlook.Desktop.OlkTranslatorCloudSettingsMgrMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9y3sb" />.. <UTS T="2" Id="9y3sc" />.. <UTS T="3" Id="9y3si" />.. <UTS T="4" Id="9y3sk" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="TargetKnownLanguagesFromCloudCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="UnknownExceptionReadingJsonCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TranslationModeFailedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="SetCloudSettingsFailedCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="5" />.. <S T="6" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1998
                        Entropy (8bit):4.787853391214786
                        Encrypted:false
                        SSDEEP:
                        MD5:F54E3E5401E75B3B203737E67A1ADEA8
                        SHA1:9D16ADE5DAB0009BD17557F0C58A399E3BAD535E
                        SHA-256:C96EB4511421CC58A0C382EF74F909059AB4CE41AFD6DA70A2C34D06CF08BA55
                        SHA-512:7183C22A760357B5071D666450E3DDB3EEF2B80661F54A8D35567C60DD382C8609A1E5F9008A9DD32C56BC9B44EE7DBD5DB401CFBC9FCBF0777F2E8E9A3D2725
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11995" V="1" DC="SM" EN="Office.Outlook.Desktop.TranslationInfoBarUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9ze0i" />.. <UTS T="2" Id="90kwx" />.. <UTS T="3" Id="90kww" />.. <UTS T="4" Id="9xohl" />.. <UTS T="5" Id="9w7ob" />.. <UTS T="6" Id="9w7oa" />.. <UTS T="7" Id="9w7n9" />.. <UTS T="8" Id="9w7n8" />.. <UTS T="9" Id="9ujt1" />.. <UTS T="10" Id="9ujt0" />.. <A T="11" E="TelemetryShutdown" />.. <TI T="12" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="OfficeCenterOpenFailedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InvalidEmailTranslationStateCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="HandleSetSuggestTranslationStateTargetLanguageEmptyCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1346
                        Entropy (8bit):4.879166875723504
                        Encrypted:false
                        SSDEEP:
                        MD5:968FBBA18A6C2E60D0327882D8AD5F84
                        SHA1:023FB10815905A9FD23F1F58AC885D16F0D3613B
                        SHA-256:795B4FEEC00C6097D86F6B68C840DB03D24B96BDDC6C7188CFAC0C755F36E159
                        SHA-512:445FC05175CCE0383D79CEFF23895FC3DEABE582E15410C6A0B65DB53341BE21EFF46A96C69E792981992454EC08FFD6F91C93E18F87C203C44F711F3C42D34C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11996" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslatorSettingsMgr" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zh7y" />.. <UTS T="2" Id="9zh72" />.. <UTS T="3" Id="9zh71" />.. <UTS T="4" Id="9zh70" />.. <UTS T="5" Id="9zh7z" />.. <UTS T="6" Id="9y3r8" />.. <A T="7" E="TelemetryShutdown" />.. <TI T="8" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="SupportedLanguagesFailedSessionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SupportedLanguagesFailedFromOgmaCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="AddKnownLanguageUnsupportedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="SetKnownLanguageUnsupportedCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="false" N="PreferredLanguageUns
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):965
                        Entropy (8bit):4.89769768385691
                        Encrypted:false
                        SSDEEP:
                        MD5:A30ED30F074DBFD1415267263B941EFC
                        SHA1:8CE63E9213BC9D85EE086B273E38404BF06FD3D9
                        SHA-256:27DF729E076E5E328D24D310E1CEECB5FC98D560544A4E8497CDACD9CD861F1A
                        SHA-512:58A41FFF6E724E297A1B982D4916E31E6DC0704305D95E2198D9DA588E7CB6BB492309C90318BC43152440BCE19AD4A095346B6B248896A757CCEBFBEFF34219
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12001" V="0" DC="SM" EN="Office.Outlook.Desktop.RopChaining.ParseResponseReplaySize" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1612" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="163" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="RequestSize" />.. </L>.. <R>.. <S T="2" F="ResponseWrittenSize" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="WriteStreamExtended_RequestSize">.. <S T="3" F="RequestSize" />.. </C>.. <C T="U32" I="1" O="false" N="WriteStreamExtended_ResponseWrittenSize">.. <S T="3" F="ResponseWrittenSize" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1028
                        Entropy (8bit):4.877012501918166
                        Encrypted:false
                        SSDEEP:
                        MD5:32C176C66F4FE4F6B802C6C36394013B
                        SHA1:3BF4833ACCF528812601D2A93A5BD0C24732DD0F
                        SHA-256:C44D6C6C90B628261055ED022BE65B4AB140DAFE5050322B904EB049DB673B55
                        SHA-512:2392A8FD1B11B498A77BB4ADAF624026A36FEF44170E65F27B053151D8891A1F718FE92FF6CD8CB4008AA9BDD9277534EE2C6A58D3ACA534AE77ADBBFB389537
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12003" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationDataMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="94el1" />.. <UTS T="2" Id="94el3" />.. <UTS T="3" Id="94elv" />.. <UTS T="4" Id="94elt" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="SetTranslationStatusPropErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SetTranslationDataPropErrorCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="ParseTranslationDataPropErrorCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="ParseTranslationStatusPropErrorCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="5" />.. <S T="6" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1170
                        Entropy (8bit):5.017256271785813
                        Encrypted:false
                        SSDEEP:
                        MD5:DF1CEB3A2429615C0120AFCCDBD70DBD
                        SHA1:8E15CE922A2D7DF794F23AD5B124F78FB3729C4A
                        SHA-256:34AD2CD8C31F37CFD6BE485BA7296C810423FFE3A86D7005F86D4590CAE8CE87
                        SHA-512:E4EEF8F6252F12C199DE3976621EE9E0CE1B273A45A6DF4E670A0C50E832962AA45262EE1023057608BDBD141297B367D77C14F918598DBDB0FDAEEDC9087AD1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12004" V="1" DC="SM" EN="Office.Outlook.Desktop.AutoDv2.ServiceRequestOutcomePerScenario" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3894" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Scenario" />.. <F N="BestEffort" />.. <F N="Succeeded" />.. <F N="ResponseStatus" />.. <F N="O365SettingsCheck" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Scenario">.. <S T="1" F="Scenario" />.. </C>.. <C T="B" I="1" O="false" N="BestEffort">.. <S T="1" F="BestEffort" />.. </C>.. <C T="B" I="2" O="false" N="Succeeded">.. <S T="1" F="Succeeded" />.. </C>.. <C T="I32" I="3" O="false" N="ResponseStatus">.. <S T="1" F="ResponseStatus" />.. </C>.. <C T="U32" I="4" O="false" N="Count_Results">.. <C>.. <S T="1" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):694
                        Entropy (8bit):5.072560269547965
                        Encrypted:false
                        SSDEEP:
                        MD5:B65E778D0867CF13D611163172DD1250
                        SHA1:2924989C8CD2B2A6742035D544C7453523E8826B
                        SHA-256:8FCBDB5FEF2333D719367199FBF2836205E1C238FF8B79F2FBD87C6C1039B3C6
                        SHA-512:48FEF5483984668717BCC18C3EBF0F83C7FE7D41DC7CF3FAB7FA657C8987CFB2A96F8AABAAF183470D5BA30021AC85B02E7A3061EC37256C63287C57DC20C154
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12006" V="0" DC="SM" EN="Office.Outlook.Desktop.EmailTranslationStateMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9w7n7" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="EmailTranslationState" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="EmailTranslationStateCode">.. <S T="1" F="EmailTranslationState" />.. </C>.. <C T="U32" I="1" O="false" N="EmailTranslationStateCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):684
                        Entropy (8bit):4.999114195125101
                        Encrypted:false
                        SSDEEP:
                        MD5:8B713BDC4B5966D0971AE7C5C6553FBC
                        SHA1:B91C9ED85B343B8A26B7B5AF25562AD1BCDF4364
                        SHA-256:401E2042D7FFFC0196B56B5CE3304397F1642E971AF5E62C63C159713EBCB7C1
                        SHA-512:E0924C6F1D7CFF1014C6407C8C947BAF5C05A7FC11D06CFBE2FB60B0633C391B71B0BB1BA933DA41C01BA408F0C0D0279C5F3E96C2894FD4A4B978685438B52C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12007" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationContextMenuUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9w7oc" />.. <UTS T="2" Id="9w7od" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="TranslateClickedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ShowOriginalClickedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):999
                        Entropy (8bit):3.7018389810195864
                        Encrypted:false
                        SSDEEP:
                        MD5:0847565B252C325B0F3F4B65DDBF8CC2
                        SHA1:BBAE496C74DD0952DE4CFC8A2F86FD0A8A9BB3B8
                        SHA-256:0534C65211D5503B490BEED86790EE243C5DA900EADA1B419D593C90EE082A9E
                        SHA-512:D53981BFDDF765CA9E4544744A234B7FEF266DFA85700E51523E52D784B4EE955A670DA22A549EE53BCCDC4D2CE5A9007EC793A732202AB143DB6F27317C98FB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120100" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryStartup" />.. <A T="2" E="TelemetryResume" />.. <TI T="3" I="30s" />.. <R T="4" R="120100" />.. <TH T="5">.. <O T="GE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="2" F="TimeStamp100ns" />.. </R>.. </O>.. </L>.. <R>.. <O T="ADD">.. <L>.. <O T="COALESCE">.. <L>.. <S T="4" F="TimeStamp100ns" />.. </L>.. <R>.. <V V="1" T="FT" />.. </R>.. </O>.. </L>.. <R>.. <V V="864000000000" T="U64" />.. </R>.. </O>.. </R>.. </O>.. </TH>.. </S>.. <T>.. <S T="1" />.. <S T="5" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2180
                        Entropy (8bit):4.4661937782352386
                        Encrypted:false
                        SSDEEP:
                        MD5:0BB16110449C6AD9F7E87A10F5B5976D
                        SHA1:907AFA5DAEA114422780FB2906930CB30017B450
                        SHA-256:C0513E3644466F11FE50B1434090E96D07966030BCD00E293506C763B6C6B7C9
                        SHA-512:8528BDB42A797D656FDA2F2BD061FDAAD38F74C4FF40FE79023E196A120D4A521C8C4375E91A3CE668DFAF3F2A0EA5C69A481DAB4F38C91AB31EBB9E7551F592
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120107" V="6" DC="SM" EN="Office.System.SystemHealthDesktopSessionLifecycleAndHeartbeat" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Lifecycle" />.. </RIS>.. <S>.. <UTS T="1" Id="awjb7" />.. <UTS T="2" Id="a14x3" />.. <SS T="3" G="{68442bc6-3519-4b08-a80c-e0a68fc8cda3}" />.. <TI T="4" I="Hourly" />.. <TR T="5" />.. <R T="6" R="120107" />.. <F T="7">.. <O T="NE">.. <L>.. <S T="1" F="Event" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="Time">.. <O T="COALESCE">.. <L>.. <S T="2" F="SessionStartTime" />.. </L>.. <R>.. <S T="5" F="TimeStamp100ns" />.. </R>.. </O>.. </C>.. <C T="U8" I="1" O="false" N="State">.. <O T="COALESCE">.. <L>.. <S T="2" F="Event"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1012
                        Entropy (8bit):4.7979606654893825
                        Encrypted:false
                        SSDEEP:
                        MD5:EF1D0AD755895588ADD7990A34BF5E96
                        SHA1:F084B03C5AEE3FD758DC41F60C5009E65307B9CA
                        SHA-256:68A4BA764A5160151D1742ECD989F845C99D913B1C6482B1706FA72C7C8F9C19
                        SHA-512:8A0AF04E08A873A2C5E046B19E858E4D1E46B5639BB6AF7E3E9BE3BABCE2264CB509B4684382D66C475166C4F1F3F2D21579CAC8F18D4DF8E9B23A4419744A7C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120110" V="4" DC="ESM" EN="Office.System.SystemHealthEssentialMetadataAllIdentities" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="4v5ai" />.. <R T="2" R="120100" />.. <R T="3" R="120110" />.. </S>.. <G>.. <S T="1">.. <F N="IdentityUniqueId" />.. </S>.. <S T="3">.. <F N="1" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="IdentityType">.. <O T="COALESCE">.. <L>.. <S T="1" F="IdentityType" />.. </L>.. <R>.. <S T="3" F="0" />.. </R>.. </O>.. </C>.. <C T="G" I="1" O="true" N="IdentityUniqueId2">.. <O T="COALESCE">.. <L>.. <S T="1" F="IdentityUniqueId" M="Ignore" />.. </L>.. <R>.. <S T="3" F="1" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):707
                        Entropy (8bit):4.925273258562081
                        Encrypted:false
                        SSDEEP:
                        MD5:9304104F8C87FCEC2DB52A8C8042FC9E
                        SHA1:EC55DC4144677CB28A90ADE379D0C1AC73F9ECF1
                        SHA-256:64082DD943016E01DCDAEE511DA17ADC5B9F8AD29C3FD7A929365D366887FD4D
                        SHA-512:E15DACA1D32B05D45A98AD89EA3697DD1CF7A32959F9001DABAD25257169583D4AD44277B01FDB9081A58CA2F4B44DBA41F76870D2C4AB2D59DED5C5F15C54D2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120112" V="1" DC="ESM" EN="Office.System.SystemHealthSessionStartTime" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <A T="1" E="TelemetryStartup" />.. <R T="2" R="120100" />.. <R T="3" R="120112" />.. </S>.. <C T="FT" I="0" O="false" N="SessionStart">.. <O T="COALESCE">.. <L>.. <S T="1" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="3" F="0" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. <S T="3" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1330
                        Entropy (8bit):4.555072319833569
                        Encrypted:false
                        SSDEEP:
                        MD5:502142DA94231A63C8DDA56CABB73744
                        SHA1:523E38AA9296209FC88DCE6E36210B58CE5B4557
                        SHA-256:0AB960FF92024AD83697E463441B9C44AC129D5EFE988A5099C1D7A56D86BAB2
                        SHA-512:1A695C552B00DB8C697E754FCA14A9543F47000A5695417A72874B55FDAA48C304A565F4F651244B914AA46741643118F61777E43FF2DCA64D801961020AA1E3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120119" V="0" DC="SM" EN="Office.System.SystemHealthRollbackSessionMetadata" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <R T="1" R="120100" />.. <UTS T="2" Id="awjb7" />.. <UTS T="3" Id="a14x3" />.. <R T="4" R="120119" />.. </S>.. <C T="W" I="0" O="true" N="PreviousBuild">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="PreviousBuild" M="Ignore" />.. </L>.. <R>.. <S T="2" F="PreviousBuild" M="Ignore" />.. </R>.. </O>.. </L>.. <R>.. <S T="4" F="0" M="Ignore" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="true" N="InstallMethod">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="InstallMethod" M="Ignore" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):861
                        Entropy (8bit):4.821523960139548
                        Encrypted:false
                        SSDEEP:
                        MD5:8D39954AFC108812A81C00AA5376FAB6
                        SHA1:C439F0F0D35E2B22D0C5146D52F4054ACC9EC197
                        SHA-256:B262EBD864E32F4C8BB835DD2FA444CB526AA48C0A7920D6D0F52FF17F8250F4
                        SHA-512:40CCABA74CA166AE729DA5497831B410B40023BD58E0FF002E4BB09F550BF25061CEB761B0C5E6674C7452201707266045479141D43A588704226E740BD9E579
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120120" V="0" DC="ESM" EN="Office.System.SystemHealthEssentialIdentityCount" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisbj" />.. <R T="2" R="120120" />.. <R T="3" R="120100" />.. </S>.. <C T="U64" I="0" O="false" N="ValidIdentityCount">.. <O T="COALESCE">.. <L>.. <S T="1" F="ValidIdentityCount" />.. </L>.. <R>.. <S T="2" F="0" />.. </R>.. </O>.. </C>.. <C T="U64" I="1" O="false" N="AllIdentityCount">.. <O T="COALESCE">.. <L>.. <S T="1" F="AllIdentityCount" />.. </L>.. <R>.. <S T="2" F="1" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):935
                        Entropy (8bit):4.629259990506597
                        Encrypted:false
                        SSDEEP:
                        MD5:979E3FF46A7D2602886C228E39D2595E
                        SHA1:5D982F346BFF2E5F2107BDD34F299BABD1C26E1A
                        SHA-256:C98FE8CC8AC28470223B863E007BEDA512346337DB24026E07D4141A59872CC6
                        SHA-512:A7BD4589F36478412A256F4405E6E1FBE8820CDB86C807A640506A5E7B08F222CF22F9347F3F8268FFC4476F83E622A6C20E681B14C2A372EE31C45EB7B266A9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120125" V="0" DC="SM" EN="Office.System.IdentityChanged" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <R T="1" R="120126" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <R T="3" R="120127" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="0" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false" N="IdentityChanged">.. <V V="true" T="B" />.. </C>.. <C T="B" I="1" O="true" N="TimerDetectedChange">.. <S T="4" F="0" />.. </C>.. <T>.. <S T="2" />.. <S T="4" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1660
                        Entropy (8bit):3.4777365974062833
                        Encrypted:false
                        SSDEEP:
                        MD5:01FF27391C5C91A0302D567138A2FF6F
                        SHA1:F4BC4EF3E41DF635589E8E67A4BE15041C92C11A
                        SHA-256:761B7BE0A558FDF74491FBEE8458DADAFF42943660AEA8F118FFE4C7F5AD0AC1
                        SHA-512:E92B3B25EB103CC8CED1A4EFC5FC2F24CCD9D55065157A43D0F550BFD08FCAAAA3098C5CD7BA8C675E3F00FB161CD5946EF62CAAE573CE9493D5DC64EB7CC4DB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120126" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="b14a4" A="awuw3" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <V V="EventProfileAdd" T="W" />.. </L>.. <R>.. <S T="1" F="IdentityEvent" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <V V="EventProfileRemove" T="W" />.. </L>.. <R>.. <S T="1" F="IdentityEvent" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <V V="EventProfileSwitch" T="W" />.. </L>.. <R>.. <S T="1" F="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1172
                        Entropy (8bit):3.719006786338845
                        Encrypted:false
                        SSDEEP:
                        MD5:A71CA3F2C426C3F3F8DD5CE7BDC8FC49
                        SHA1:4D478FE45EDF72F679225C68D40963E31348A62F
                        SHA-256:83C74EB9B3BB7FD30EA3114ABFFAFDFF9F1E9CFB33223EF7B86AB8A3F2C36FBA
                        SHA-512:E26A68B9F08EEB3389CF258CE9D9AB2703256F95056F06312F5D87558F518B31F2AB1BA9BF51DDFB00A9E0C8F6C86D7B7352DF01D1A164CAC8D4F8F1A29E0240
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120126" V="8" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="a3wen" />.. <UTS T="2" Id="bhq2o" />.. <UTS T="3" Id="cc3ox" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="UserDecision" />.. </L>.. <R>.. <V V="1" T="U8" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="UserDecision" />.. </L>.. <R>.. <V V="2" T="U8" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="AuthCategory" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </L>.. <R>.. <V V="ActiveIdentityChanged" T="W" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1177
                        Entropy (8bit):3.9234314786976854
                        Encrypted:false
                        SSDEEP:
                        MD5:ED13EBF74891256A27A40043EA092AF8
                        SHA1:DBB348E21C4594D671532454F9C13B37CB3829B9
                        SHA-256:B1E34D9BBBCA1E5686F5996E126986F2B8D511CA6AC28835C1DB5E79D16E2E1D
                        SHA-512:B8BECC70F271BD970752EF9DF7E7DBA7568ACE680A285ABB6663C700978542D96A54A5BA2C4057F6EC0C9200E0040D4D43117EB0334D97A6F61D21A01A5E2EAE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120127" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <TI T="1" I="30s" />.. <A T="2" E="TelemetryResume" />.. <R T="3" R="120127" />.. <SS T="4" G="{1a6b5bd0-2f17-420c-8ba0-ee01132ee441}" />.. <R T="5" R="120100" />.. </S>.. <C T="B" I="0" O="false">.. <O T="NE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="1" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="4" F="UserCid" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="4" F="UserCid" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="W" I="1" O="true">.. <O T="COALESCE">.. <L>.. <S T="4" F
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):657
                        Entropy (8bit):5.176719630355306
                        Encrypted:false
                        SSDEEP:
                        MD5:ED758634CBCD2030942B20CEC7235E2E
                        SHA1:03DA3F778A321C513CE21A82C0C2835C17AEFD03
                        SHA-256:671FBCE6FFD82EED19F5DC867435A92FAD7D92290F3632195992B0E39F2CC3DE
                        SHA-512:369503745FFDE8EB0BA57B660E5D7DF8A0D80382A72E6F276332C227995D192C3E20B6C950ACA4A74FDFCA5AAC3FCE272C081E35CBF47DFBEF6C36510BBF4E7A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120128" V="0" DC="SM" EN="Office.System.UserChangedDiagnosticLevel" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="c4qbn" />.. </S>.. <C T="B" I="0" O="false" N="UserChangedDiagnosticLevel">.. <V V="true" T="B" />.. </C>.. <C T="I32" I="1" O="false" N="OldDiagnosticLevel">.. <S T="1" F="OldLevel" />.. </C>.. <C T="I32" I="2" O="false" N="NewDiagnosticLevel">.. <S T="1" F="NewLevel" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2849
                        Entropy (8bit):4.395501028116881
                        Encrypted:false
                        SSDEEP:
                        MD5:3D5BFEDF8BFF08FC1FD30CFD1FDEAC72
                        SHA1:4BAE9BA25B0C1B71B01DA4C55D3CCE747260C7A0
                        SHA-256:B703EE5EC52A956EE64A68B0FB744245E6782ECA8D7091A2A35EB1D7974D47BC
                        SHA-512:D84CBC7625E204CB976F2D8321512F0AE07287645B0BB7B9BA962680A3AC05EF2BE8959A541F4BB4DCD797A01C7C99BB56871B77090F3650ED45192E50DC9720
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12014" V="0" DC="SM" EN="Office.Outlook.Desktop.FreeBusy.AddressLookupSuccessAndSourceMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="27129" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FoundSmtpAddress" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="FoundSmtpAddress" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="LoadedProps" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3083
                        Entropy (8bit):4.403352684363651
                        Encrypted:false
                        SSDEEP:
                        MD5:145B9F6DDA1A8391E1BE436203A04976
                        SHA1:DDE04509A01ACD2690A14B8DD7DC3A13987085EA
                        SHA-256:E789B7C98BC4D61281659D384C9A01009D48DCB759DB19B3470457A3C30B24D2
                        SHA-512:BD4D0FF91FA40E2B39E2131D16D656173AD356994FF1362C18B8F7495EFA3F3F9DD3909D2A47CDA74CA48ED47FE14BBB3BFF47D5823DCB45EC8FE5EC71F9FBE2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12015" V="1" DC="SM" EN="Office.Outlook.Desktop.TranslationDataErrorOutput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Hourly" />.. <UTS T="3" Id="94ely" />.. <UTS T="4" Id="94el9" />.. <UTS T="5" Id="94elr" />.. <UTS T="6" Id="94elv" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="TranslationDataPropEmpty" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="3" F="TranslationDataPropEmpty" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="6" F="TranslationDataPropEmpty" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1297
                        Entropy (8bit):4.59458386608663
                        Encrypted:false
                        SSDEEP:
                        MD5:8974B169D2882FF799B09DF1B6A1B336
                        SHA1:9F88221565B3A83CC042B8857707FF1F2261E23C
                        SHA-256:D64931BA1749F3964201C9A6989E36722791D706FF54144EF11DA094EFD2DD86
                        SHA-512:1CA6F252ADE67FCC666C5B375B4F7956F59561B733C7C173D0CD5FF258926202F985DBA7267593024EE90861BA4F054E38373905FBC1BBBE46878035C76A1656
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12018" V="1" DC="SM" EN="Office.Outlook.Desktop.RopWriteStream.FailureStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="363" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="45" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="163" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="Result" />.. </S>.. <S T="5">.. <F N="Result" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Failure_Result">.. <O T="COALESCE">.. <L>.. <S T="4" F="Result" />.. </L>.. <R>.. <S T="5" F="Result
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3816
                        Entropy (8bit):3.60180606792738
                        Encrypted:false
                        SSDEEP:
                        MD5:B557233CC8A2123D0D7819B3EB935A10
                        SHA1:B44B6DBA5591617D012A00178F4DCA4811A1E6A3
                        SHA-256:B15B0D6B64FB488FCE0A853F9789D2390543ACCDDD822076B2A37DB62B98F6CB
                        SHA-512:B03F13FAD4E04CF90483D833C1B446056E74984F6C9B9B9C25382FD737655464CD70C60A81E9AD598FAD4C44D7796413B13A6782D10088BF133AC5174ACCEFF1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12019" V="1" DC="SM" EN="Office.Outlook.Desktop.Pst.FileTypeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="802" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="Provider" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="Provider" />.. </L>.. <R>.. <V V="256" T="U32" />.. </R>.. </O>.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2640
                        Entropy (8bit):4.9348078745429325
                        Encrypted:false
                        SSDEEP:
                        MD5:F999CB328321A7D4F1AB28F60CFA1595
                        SHA1:A4DCAB4B0B8A7A07A722574792E11D03772ED2F0
                        SHA-256:37CC50DCC7D7707DD913FFAF7AF093F0C06EC1E091E10C205724D4EF416141A5
                        SHA-512:DA89B1710740ACFD1DEAD546C7863C682004772F4CAF620C854C19D6DC0BD59C8403A2DB00882FAA9737053A510187D9B6082EBAC5869E2FB1063F1A4039A6E5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120201" V="14" DC="SM" EN="Office.System.SystemHealthUsage.ClickStream" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalUsage" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Usage" />.. <RI N="CommandUsage" />.. </RIS>.. <S>.. <UTS T="1" Id="bb9uz" A="bb9ve bb9vg bcijr bcijp bgmnl bgmnr bgmnt bgmnx bgmnz bgmn1 bgmn3 bgmn5 bgn2k bgn2m bgn2o bgn2q bgn2s bgn2u bgn2w bgn2y bgn21 bujz1 bunl0 ide6g b0mo1" />.. <UCSS T="2" C="Command Usage" S="Medium" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_Category" />.. </L>.. <R>.. <V V="Scope Summary" T="W" />.. </R>.. </O>.. </F>.. </S>.. <G I="true">.. <S T="3">.. <F N="ScopeInstance" />.. </S>.. <S T="2">.. <F N="UserActionID" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="StartTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="I32" I="1" O="falseNo
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3029
                        Entropy (8bit):4.783329374973241
                        Encrypted:false
                        SSDEEP:
                        MD5:D368219CDF254E91CB793F73251F4B0B
                        SHA1:F9AA8AB421EF6C3BEAD105EA6047194D83C70F15
                        SHA-256:451FA7E073B8BC6AB481CE14F2FA487701033BA564E9669476094D7CCAA0BF95
                        SHA-512:18D86D448B75CEC121BCBC91EAB5FC54000816F08503A66CDAF54DB7A50C0E26C5032AC6452580FE258CF51371A882DCD3C0DD0FA9522CE280542F21A527E9B1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120205" V="11" DC="SM" EN="Office.System.SystemHealthUsage.NonTCIDClickStream" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalUsage" DCa="PSU" xmlns="">.. <RIS>.. <RI N="CommandUsage" />.. </RIS>.. <S>.. <UTS T="1" Id="bb9uz" A="bmmfb bb9ve bb9vg bcijr bcijp bgmnl bgmnr bgmnt bgmnx bgmnz bgmn1 bgmn3 bgmn5 bgn2k bgn2m bgn2o bgn2q bgn2s bgn2u bgn2w bgn2y bgn21 bix8b bix8d bix8f bix8h bix8j bix8l bojix bk8ux bcss8 c5n49" />.. <UCSS T="2" C="Command Usage" S="Medium" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_Category" />.. </L>.. <R>.. <V V="Scope Summary" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <V V="" T="W" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="2" F="TelemetryId" M="Ignore" />.. </L>.. <R>
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1103
                        Entropy (8bit):5.081116538822298
                        Encrypted:false
                        SSDEEP:
                        MD5:67F53BA2499E56DA352E2C2EFD8437CA
                        SHA1:7DC5E335AC07D8C2D1D5398ACD835A8AFF90B312
                        SHA-256:54E201B18A1CCBDCEC63388EED110DCA398992E33213F1DD8A280C8015063958
                        SHA-512:467543DDFF11BB43A8C1E548C825A4BE46BA80E66E640B2D163720F896354EB70BC3DC7A9F7AE4E462E997F1CC1FB7FDCD65E425B1D819A0338F56A17E25FFFA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12020" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.MIUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="908" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="356" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <G>.. <S T="1">.. <F N="DiagnosticId" />.. </S>.. <S T="2">.. <F N="WebHostingSessionId" />.. </S>.. </G>.. <C T="G" I="0" O="true" N="DiagnosticId">.. <O T="COALESCE">.. <L>.. <S T="2" F="WebHostingSessionId" />.. </L>.. <R>.. <S T="1" F="DiagnosticId" />.. </R>.. </O>.. </C>.. <C T="I32" I="1" O="false" N="CompleteLoadToUpdateResultTime">.. <S T="2" F="CompleteLoadToUpdateResultTime" />.. </C>.. <C T="I32" I="2" O="false" N="InsightsCount">.. <S T="1" F="InsightsCount" />.. </C>.. <C T="B" I="3" O="false" N="RetryMode">.. <S T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):819
                        Entropy (8bit):5.14360472471183
                        Encrypted:false
                        SSDEEP:
                        MD5:6640500C2D446B3AD9F910BA0D1CB52B
                        SHA1:0C104506BA45EE5E5A0C6ED26C58F4D28025B5EB
                        SHA-256:E054602ACC0F456434EDA7F786F76954BB8E196376EDABDBEC42722358BFD107
                        SHA-512:7665C4416715F71EE59858C8BA5FBC594EB29E1E1AE2D29B6BE7B0910FEBD7E7DDDBD83D0E177E7319DFE7107940831986C996680B277A355DAD8F1166AF9146
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12026" V="0" DC="SM" EN="Office.Outlook.Desktop.HomeRealmDiscoveryLookupResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="639" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HrdResult" />.. <F N="FromCache" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountIdentityChecks">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="DeterminedIdentityType">.. <S T="1" F="HrdResult" />.. </C>.. <C T="B" I="2" O="false" N="IdentityFromCache">.. <S T="1" F="FromCache" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1037
                        Entropy (8bit):4.719768372527338
                        Encrypted:false
                        SSDEEP:
                        MD5:5A1A55F9AB590A554C379440E390C440
                        SHA1:B7F766CBF58B4B75EA4C37E06A929427A22A2564
                        SHA-256:CF5123EFC558D9CB658BD2E85C68616F4B6C9765EE0BF79F9F2B59C13DDCEBD1
                        SHA-512:5140927D079E9782951641420267DB422FF268283D02F7C522BA65EBFEBF5676EAFEAE6843C9F266D77B9B9C2BDD72A8758DC1FE62E74BC85FC1B7A587CE0736
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12027" V="0" DC="SM" EN="Office.Outlook.Desktop.NegotiateClientAckHeader" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="743" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ValidAckHeader" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ValidAckHeader" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountValidAckHeaders">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountNotValidAckHeader">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1003
                        Entropy (8bit):5.035943950062749
                        Encrypted:false
                        SSDEEP:
                        MD5:ACBE3C99DEF2187CF360D010FF6DE411
                        SHA1:8B7C96CB493208F331337E3C66E698DA4193B3EC
                        SHA-256:8CBB76E5C9410A2D25628D8FF58BF63CEBB4A537D6AF29A8CCBDB53E5B9A808D
                        SHA-512:4E8C8234A2A6F39379DED45995C371EFF7BB424F8F47989432DEAA536DA222B8BECBF9B57A9FBF43803BE950AE155928336FC67FEC54DE994AA41ED06B292748
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12028" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroupGeneric" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19036" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OpType" />.. <F N="HRESULT" />.. <F N="IsOwner" />.. <F N="CountOfMsg" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="OpType">.. <S T="1" F="OpType" />.. </C>.. <C T="U32" I="1" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="I32" I="2" O="false" N="IsOwner">.. <S T="1" F="IsOwner" />.. </C>.. <C T="U32" I="3" O="false" N="CountOfMsg">.. <S T="1" F="CountOfMsg" />.. </C>.. <C T="U32" I="4" O="false" N="DragDropEventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1305
                        Entropy (8bit):4.616495117342903
                        Encrypted:false
                        SSDEEP:
                        MD5:3D5CC7261BEB03DF98E09805E92AB8BC
                        SHA1:51DE75F2E4ED56F633B8E0AFC2DC952A8ED76C0F
                        SHA-256:3FB69863D20FE36A95700B8B1A91DE48029C4B677B9B0E5712CDD41A103CF832
                        SHA-512:3F86FB08D12CA9A584710EB974E875259E1F198D88F881315EED7B96C366E237544883433AD55B7C983EC014307DF476393481706CDD438B5553D577E797020A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12029" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingAttendeeGrid.ExpandCollapseUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1028" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="GroupId" />.. </S>.. <S T="5">.. <F N="GroupId" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="GroupID">.. <O T="COALESCE">.. <L>.. <S T="4" F="GroupId" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):961
                        Entropy (8bit):4.4482435960164395
                        Encrypted:false
                        SSDEEP:
                        MD5:3787458C2166D70089625D4295174043
                        SHA1:28BB8699390C79FCB6E9CC0E6CCACF33986AB27B
                        SHA-256:712F1F4EECEBA02722D95218CC8CD1388D39EB59312D47560F849E8B817389AA
                        SHA-512:FBDB5FE328998F24270192E27A6FD7E379CF4EBB9ECB8A0EE94CD17F6B095A3F5E0F2F69AD2EE4EA198AB0573337A33A9B6A3ECD2B56DEF4FFB855763C7BCB09
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120300" V="3" DC="SM" T="Subrule" xmlns="">.. <S>.. <UACS T="1" S="Unexpected" />.. </S>.. <C T="U16" I="0" O="true">.. <S T="1" F="ETW_EventId" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="ULS_Category" />.. </C>.. <C T="TAG" I="2" O="false">.. <O T="COALESCE">.. <L>.. <S T="1" F="ETW_TrackbackTag" M="Ignore" />.. </L>.. <R>.. <S T="1" F="ULS_Tag" />.. </R>.. </O>.. </C>.. <C T="I32" I="3" O="true">.. <O T="COALESCE">.. <L>.. <S T="1" F="ErrIdOptional" M="Ignore" />.. </L>.. <R>.. <S T="1" F="SH_ErrorId" M="Ignore" />.. </R>.. </O>.. </C>.. <C T="I32" I="4" O="true">.. <O T="COALESCE">.. <L>.. <S T="1" F="HROptional" M="Ignore" />.. </L>.. <R>.. <S T="1" F="SH_ErrorCode" M="Ignore" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1453
                        Entropy (8bit):4.684191125363692
                        Encrypted:false
                        SSDEEP:
                        MD5:3919CC7F5FE2DFF74BDD02FBD0483AEC
                        SHA1:19F386B069290EA2DDF22993722DBE4C99C7F29E
                        SHA-256:8392211A244794F86556E3D17415175079B96D7D33D72A6E905D3FB73B91C3BD
                        SHA-512:DC71343A2FC50FEB3722F24C495DF03AEB77F8849CA05455E6FBA2F584610FA2D3B68416A972416D6987C33B6A279268FF70C424317BAD1E03CF062DD4EFC4A5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120305" V="3" DC="SM" EN="Office.System.SystemHealthErrorsWithTag" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Error" />.. </RIS>.. <S>.. <R T="1" R="120300" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="6034006" T="U32" />.. </R>.. </O>.. </F>.. <TI T="3" I="10min" />.. <A T="4" E="TelemetrySuspend" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="2">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="EndTime">.. <A T="MAX">.. <S T="2" F="TimeStamp100ns" />.. </A>.. </C>.. <C T="W" I="1" O="false" N="ErrorGroup">.. <S T="2" F="1" />.. </C>.. <C T="TAG" I="2" O="false" N="Trackback">.. <S
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1249
                        Entropy (8bit):4.749564309320366
                        Encrypted:false
                        SSDEEP:
                        MD5:5A306F55B8BE6297FA735159DF791E43
                        SHA1:AF012DDBC1DBCAB6888769225A720289972038BD
                        SHA-256:89E8A3E12159A3000300FDD5EFBFD646FF4AC951F39D6BE243061E40D9CB1105
                        SHA-512:3189327E37645477AA59D358E24730EFEABBA38DEA4A4770217B426EA826127DD25426B4EB1F0B72DC3187D24F1F596462596826469BCF2094CF2317422F257D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120307" V="1" DC="SM" EN="Office.System.SystemHealthAsserts" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" DL="B" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Error" />.. </RIS>.. <S>.. <UACS T="1" S="Assert" />.. <TI T="2" I="30s" />.. <A T="3" E="TelemetrySuspend" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="ULS_Tag" />.. </L>.. <R>.. <V V="508441857" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="5">.. <F N="ULS_Category" />.. <F N="ULS_Tag" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="EndTime">.. <A T="MAX">.. <S T="5" F="TimeStamp100ns" />.. </A>.. </C>.. <C T="W" I="1" O="false" N="ErrorGroup">.. <S T="5" F="ULS_Category" />.. </C>.. <C T="TAG" I="2" O="false" N="Trackback">.. <S T="5" F="ULS_Tag" />.. </C>.. <C T="U32" I="3" O="false" N="
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):790
                        Entropy (8bit):5.066114171630968
                        Encrypted:false
                        SSDEEP:
                        MD5:82EDF3245A18BE14633A08FF2669CE66
                        SHA1:7A30FCC4B62792AD1B6B199A8D4E1D6CC2E8E7AA
                        SHA-256:AFB6DF9AD06596A2A657BAB39DEF302E2D87498B2D85EBE50B618BAC0863CD91
                        SHA-512:EF7C5ECC21C9C8D1911CC28F4062468339AA15977E66FF7A6E32E9F0C2254A01D23FCC91564F3649E16A64696B3B83A80AF9CA0F69FD33F9E5EBA42D704FC569
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12030" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingAttendeeGrid.UpdateAttendeeType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1029" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="From" />.. <F N="To" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="FromGroupID">.. <S T="1" F="From" />.. </C>.. <C T="U64" I="1" O="false" N="ToGroupId">.. <S T="1" F="To" />.. </C>.. <C T="U32" I="2" O="false" N="UpdateAttendeeTypeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):652
                        Entropy (8bit):5.062451879967685
                        Encrypted:false
                        SSDEEP:
                        MD5:1D5536237275326B5AC0E005CE32C5AE
                        SHA1:3AA4BBA942C81B315EB0A580B8046514266C4759
                        SHA-256:024531FCE9538B88C7E4000E07E9E873A5CEC5389691F2932DCFF11001DBE4C3
                        SHA-512:F3210FF95CC91106AD5A6091400EA2E0CB7CA02BFCA74234A40CF6C82623A36C6728D59B55B4EE11D423932F42657A2E8928AD3061ABBBC4940E2448374A45FA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12031" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationRibbonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9t591" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="RibbonInvokeActionCode">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="RibbonInvokeActionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):692
                        Entropy (8bit):5.146636101488893
                        Encrypted:false
                        SSDEEP:
                        MD5:C2531E60CD2D5A0FE6E61334C8F8E1CC
                        SHA1:818368D9D0D43A78BB4A278173A1CCFD8536BF8B
                        SHA-256:D483B579DEBB420807041F14848F45546BFBE7D6FF5DBBDEF3DE9B43D0AED4EA
                        SHA-512:B4804439697777CD4B244F7D8EBD1AF3652B1875752132680A8F895623089F9D4F2ADF88516AA5AC569EAAFC519B0BA5B8F959DC5521980AD70DCAF1FFDA16F7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12032" V="1" DC="SM" EN="Office.Outlook.Desktop.OlkTranslatorCloudSettingsMgrHResultErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9squ3" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I64" I="0" O="false" N="GetCurrentAccountErrorHResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="GetCurrentAccountErrorHResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2467
                        Entropy (8bit):4.218494123729328
                        Encrypted:false
                        SSDEEP:
                        MD5:23E79EA4B5CFF67F704A6D0D21B7BEDF
                        SHA1:C1B2D11601C0D966E9D28EDCD5F051D120CF4F80
                        SHA-256:5E21DDC819BEBE7D9574474C0A7126FA0C4635CD8016074D7FA49C33822D0191
                        SHA-512:739B3BB95F8922D68ACDE537E66BCEC47A699AB1E07099FC88E6F6FB09EA99CC1E3261212962EC99411B4E0FCE61602F4A140CD13E38F2A5CAB5A047CC497E07
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12035" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.IsExchangeAddressBook" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9trqk" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HasAddrBook" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <S T="1" F="HasAddrBook" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="LoadedSearchPath" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <S T="1" F="LoadedSearchPath" />.. </L>.. <R>.. <O T="EQ">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):775
                        Entropy (8bit):5.124181478867032
                        Encrypted:false
                        SSDEEP:
                        MD5:6260C679EA48A67F6C8099EC8845CEF7
                        SHA1:EB98BC722730EC7D53ADAF59602A800051A51CF4
                        SHA-256:8FF1C62B23B62C8C06008EC19F28EEC86B18CAEB899B4D09D8180399F12D8145
                        SHA-512:94A51D5237F9847758A99E7E71946AF9FD2DF8AC94BA479AB63AAD2ACAA3A26C37D02393DBE1891FC0B9F5164A640C8D7C66DFE173F0FFBFAD8B584ED722D2C8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12036" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.PrefetchandRecurrence" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6127" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6128" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="PrefetchResultShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="RecurrenceDataCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3787
                        Entropy (8bit):4.955693169986947
                        Encrypted:false
                        SSDEEP:
                        MD5:5B2225D394303EEAD121834886DEF8CE
                        SHA1:6F1A7E6379A0B17DF6269B744564C85B853C27E3
                        SHA-256:05A0A5628BEA491A045AE43C66D2D1F377145214E11F596B95F60AD7B889B3CF
                        SHA-512:36E56D0E1408AF2764DE788221ADA49971B08F76D00DDD793AB2CD36F13FFA0077EBC1F7C1A23F26DF277DD684475729541DB00F7F3455C50DF16A90B16B391C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns="">.. <RIS>.. <RI N="Crash" />.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="824rc" />.. <SS T="2" G="{68442bc6-3519-4b08-a80c-e0a68fc8cda3}" />.. <TR T="3" />.. </S>.. <C T="FT" I="0" O="false" N="DetectionTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="1" O="false" N="CrashedProcessSessionInitTime">.. <S T="1" F="CrashedSessionInitTime" />.. </C>.. <C T="G" I="2" O="false" N="CrashedProcessSessionID">.. <S T="1" F="CrashedSessionId" />.. </C>.. <C T="U8" I="3" O="false" N="CrashType">.. <S T="1" F="CrashType" />.. </C>.. <C T="W" I="4" O="true" N="PreviousBuild">.. <S T="1" F="PreviousBuild" M="Ignore" />.. </C>.. <C T="U32" I="5" O="true" N="InstallMethod">.. <S T="1"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):663
                        Entropy (8bit):5.099263620692954
                        Encrypted:false
                        SSDEEP:
                        MD5:C3092D3B811AC7FA0EFD684200A9590B
                        SHA1:28EA34D0EBDF0984B7D37EE55EE9B79A91371A5E
                        SHA-256:24C9F91FCABC7853FA3510FF0511D65853D30A6BB204E1F4A15D90A24598EEBF
                        SHA-512:D786BEAFD6CDD7ACB61F134F6D4B311250737B1E6E0752842A70F442FC7542590E60CBFBD03DD0E853B405DA12BD87CD0C5660437F5A80B5B6CF9FE0EA6E21C3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12043" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationInfoBarFlexUIHResultErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9sqvv" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="ErrorTag" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="FlexUIErrorTagCode">.. <S T="1" F="ErrorTag" />.. </C>.. <C T="U32" I="1" O="false" N="FlexUIErrorTagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):743
                        Entropy (8bit):4.990664509358685
                        Encrypted:false
                        SSDEEP:
                        MD5:F14F9A0EB8A7410AA025D156961DF7A2
                        SHA1:49A93444CE4429B7A7A34E33B35893B366ED38EE
                        SHA-256:777AE1E18ACCCB59C1C5C4F41AFC705F362AADAC8BBC2E234DF2A71BBE17737F
                        SHA-512:6F56937AC04B1869C45E5BA757681910B96FA7B72666544CAC5A9D609DF979B114DCB058DEFB004D39C1B1413F903EED61AA6E9B40ADC263687405230181E8ED
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12045" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.CountCardType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="crzmp" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CardType" />.. <F N="IsHosted" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="CardType">.. <S T="1" F="CardType" />.. </C>.. <C T="B" I="1" O="false" N="IsHosted">.. <S T="1" F="IsHosted" />.. </C>.. <C T="U32" I="2" O="false" N="CountCardTypeAndIsHosted">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1690
                        Entropy (8bit):4.748737190020795
                        Encrypted:false
                        SSDEEP:
                        MD5:FEA20A72BD4FB9A9AFF5563D7859382A
                        SHA1:2D9E361B1CA6FD6377A2A74A0C3F3E84379F0AFB
                        SHA-256:128CD2AC3F3953D28C8773F4734FCF17EF7C9BF2EFE438979561A437409B9963
                        SHA-512:B24F0B7DEF9759EB0DC9DDD09F31421350488E2D510A156896569962F14E3A96DA02BDA48032DB290280636435504C7BD7D6EB3B4A7E6C9AFDBB3D6F8B874907
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12046" V="2" DC="SM" EN="Office.Outlook.Desktop.Calendar.JoinOnlineOnCalendar" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1030" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="OnlineSessionType" />.. <F N="JoinOnlineLocation" />.. <F N="AccountID" />.. </S>.. <S T="4">.. <F N="OnlineSessionType" />.. <F N="JoinOnlineLocation" />.. <F N="AccountID" />
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):619
                        Entropy (8bit):5.027977889714664
                        Encrypted:false
                        SSDEEP:
                        MD5:43E5D7CDC5F02DDEF3AA8170021D4AB2
                        SHA1:8A16729FBD2E1284E1BE8ED04CCF8003C15B2FC9
                        SHA-256:532DF1D02C4E3F272A90CF9B50D51C94BE53783FEAB97BC15DB694563409AF8D
                        SHA-512:9C4F3752BC4AF3025D0AEDD82C231CB3BADF946E24BA307E78357B08BE04B386202E73ECEE69B3F526572418C9251999090B76A658E135F9020DB92957845A78
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12050" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.LpcOpenning" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9s74g" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Source" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="Source">.. <S T="1" F="Source" />.. </C>.. <C T="U32" I="1" O="false" N="LpcOpeningsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):759
                        Entropy (8bit):5.103131962399642
                        Encrypted:false
                        SSDEEP:
                        MD5:02ABDF2616BA2A23A1306F1B266D33AC
                        SHA1:F8B306457E1C428EA1FEAB1EFC3840D68AFE2294
                        SHA-256:91152E7AB658B26F69FF4B731283507141F9CDBD4F3D20B337D4A04C7BA1AFEB
                        SHA-512:B6E882BDAEF6623E4054C8F4019AEF8378AFA4AE7140E1D62C9F900FF96A9EF663D479F57D7BE5FC2EDF170CDB40D22A27E5E215AC3E58BC2DB2A40F112375CE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12051" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateGroupGetGroupSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uax1" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CreateGroupGetGroupSettingsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):755
                        Entropy (8bit):5.108187898032485
                        Encrypted:false
                        SSDEEP:
                        MD5:088E9768342AF72158DCF7B62AD7912A
                        SHA1:56D34F57EAC7742B6EFD4F070313EC17DB9B8532
                        SHA-256:A39641CB1942E938790245D3BC0650B36FF3B7D6DE88B98BB040C6F67BF99CF2
                        SHA-512:F3B7CAB0EC0B10D7F0690595F5A0E641C1F908B42EEC2FC78504A64F6A71C7838226B76EE410925C4907A2B1C319767328BF367618D95519D9BC797509C3D68D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12052" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedEditGroupGetGroupSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uax0" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="EditGroupGetGroupSettingsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):751
                        Entropy (8bit):5.110882330608996
                        Encrypted:false
                        SSDEEP:
                        MD5:07487D6B44AFA1AF380E65BBC5367474
                        SHA1:C7D7F16F5EDB8FFB715B2DA773DE5A9001D56F86
                        SHA-256:99AB9B8310391F678BEE2358D75C62FDE661B35D5ED010DC93945225526D3FC8
                        SHA-512:7942117D615B6960005DDB9D5A8A698D2F19F4660EF04C9D66F085ABD024BF117B71BDC97FC78EF971DA2ABEE47DEB4D26F24E32D7FCF538EE1F8E435D1216C8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12053" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedGetMembershipTaskResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uaxy" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="GetMembershipTaskResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):755
                        Entropy (8bit):5.106600457843894
                        Encrypted:false
                        SSDEEP:
                        MD5:86ADED024E71BFC513174DBEBA697BCB
                        SHA1:E67EDF048C9D98B6FA499EDC39C329C54A426FCB
                        SHA-256:E9C3DCBA31D341FFDE6B0363750FEAF151960B1104F49EEEC2E1ECDE3A9BE8A3
                        SHA-512:EB382CB2AABC71BAEF560BDD157E5EF378FA244FB7E73A9637C00F8FE1E0463076F868D19B538E46C4BF919EAD1D9202E14E2055A8A83F43FF416AD8D873B847
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12054" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedGetGroupDetailsTaskResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uaxz" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="GetGroupDetailsTaskResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):670
                        Entropy (8bit):5.113702506511761
                        Encrypted:false
                        SSDEEP:
                        MD5:EFD4F950979DB9E888C3629DF0DF113F
                        SHA1:365ED92368E8AF71358AFD735ED517906707D599
                        SHA-256:C34684A334E8C966327C7BA0DF09D8F1F0EA65E9FCE7E2E1AFCD55824CA6FA48
                        SHA-512:2D06D35461176F4FA3747C0A2C1ECC0AD167BC0EA3C277349E71968A6BC91A5C1941206703A7DD8BBAFE757AF17D7AF69E536CC68AE08C5BF6B8E5E1925CE1B8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12055" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.MediumCardOpenedFromTimerOrChevron" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9ma03" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ChevronClicked" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="ChevronClicked">.. <S T="1" F="ChevronClicked" />.. </C>.. <C T="U32" I="1" O="false" N="MediumCardShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4781
                        Entropy (8bit):3.8026096011369317
                        Encrypted:false
                        SSDEEP:
                        MD5:4FDD7E5642D1441098146B4F17D739F6
                        SHA1:FA3092438C0DA5C3FB83DA4C77EAE312195415B5
                        SHA-256:D63E03EAC8F1365C389C2C0B981914FDE793ED7C12178886172C7E2DC3E2D23B
                        SHA-512:CCD56C4F362860988BCC41176C19BA3244D8AFB6AB6E4B3F0A783EE952A6287700BE3B11809D9D4BAE7E01808F5E2BD74088F19693F4018288B0D106F11F716D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12058" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.NativeMailUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="910" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="LoadTime" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="LoadTime" />.. </L>.. <R>.. <V V="1000" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="LoadTime" />.. </L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):995
                        Entropy (8bit):4.961679196780908
                        Encrypted:false
                        SSDEEP:
                        MD5:F85E6CC629072DC5F6F4EE8D9792116D
                        SHA1:C2EFDD2423D483A43418497F29B987A030C08DC1
                        SHA-256:36E3E1EE6B90B1515C1622D4273FECEF054ED79010CAB73C96690B781339D79E
                        SHA-512:8C209363281F463A76E6030B5B8D857B73700FB6619498B045B23BDBD2F50AA50CC50FE8AC0E5F2E7AA25660AD212A1A00FFD720CAEB13D4E50ECAF540A069F3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12059" V="0" DC="SM" EN="Office.Outlook.Desktop.EwsAccessTokenFallback" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="354" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="ConsumerType" />.. </L>.. <R>.. <V V="7" T="U8" />.. </R>.. </O>.. </F>.. <TI T="5" I="5min" />.. </S>.. <G>.. <S T="4">.. <F N="LogicalHttpRequestId" />.. </S>.. <S T="1">.. <F N="LogicalHttpRequestId" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError" N="RequestResult">.. <S T="4" F="HttpResponseStatus" />.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <R>.. <S T="5" />.. </R>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2979
                        Entropy (8bit):4.991513830301989
                        Encrypted:false
                        SSDEEP:
                        MD5:F4BFD86F423200624CFA7666B17EECC5
                        SHA1:92C7C980BDE67E323AB603A9858FF24809731289
                        SHA-256:97D1DC756F573B50991802038087FAF9BA0C977709F86E2816DD481ECF01F861
                        SHA-512:9E773A74D4AE6E3285192F4B41A31CD14A93D47AA5E37CDA31E952C0805E7A868F19CE7F20EEFC65D62E56C6D09F0AE03ED2AB59447A45AA184DBE52A259B701
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120600" V="4" DC="SM" EN="Office.System.SystemHealthMetadataDeviceConsolidated" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <SS T="1" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" />.. <R T="2" R="120681" />.. </S>.. <C T="W" I="0" O="true" N="ProcTypeText">.. <S T="1" F="ProcessorArchitecture" />.. </C>.. <C T="U32" I="1" O="true" N="ProcessorCount">.. <S T="1" F="ProcessorCount" />.. </C>.. <C T="U32" I="2" O="true" N="NumProcShareSingleCore">.. <S T="1" F="NumProcShareSingleCore" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="NumProcShareSingleCache">.. <S T="1" F="NumProcShareSingleCache" M="Ignore" />.. </C>.. <C T="U32" I="4" O="true" N="NumProcPhysCores">.. <S T="1" F="NumProcPhysCores" M="Ignore" />.. </C>.. <C T="U32" I="5" O="true" N="ProcSpeedMHz">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3341
                        Entropy (8bit):4.997102990206506
                        Encrypted:false
                        SSDEEP:
                        MD5:4D044861F6A92FC6F38F5C9A7805896A
                        SHA1:4468FBBCE74A3F076BEC8007AC5B316E881BE5E9
                        SHA-256:B5CBCCBA164E2157ED98CE01790C1D5ADB6AFB544676E5907657A02A8F770A64
                        SHA-512:3EB41A3706196B5CABF659BB5A748BC383041320CA81C3E25249457FC58F4D64B2FD53C92A3BF3D6A10733E8C2E652357B7DCAC472B73262CF4BCD44364F4190
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120601" V="3" DC="SM" EN="Office.System.SystemHealthMetadataOS" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <SS T="1" G="{3cb9b55e-dede-4e53-a8fb-237e71d0c1ad}" />.. <SS T="2" G="{233c7b3b-96db-42f9-9cd7-2a3dc93947e8}" />.. <SS T="3" G="{8ab2d942-dc47-4076-8a16-0c8b6874be27}" />.. <R T="4" R="120100" />.. </S>.. <C T="U32" I="0" O="true" N="OsMajorVer">.. <S T="1" F="OSMajorVer" M="Ignore" />.. </C>.. <C T="U32" I="1" O="true" N="OsMinorVer">.. <S T="1" F="OSMinorVer" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="OsBuild">.. <S T="1" F="OSBuildNumber" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="OsBuildRevision">.. <S T="1" F="OSBuildRevision" M="Ignore" />.. </C>.. <C T="U16" I="4" O="true" N="OsSuite2">.. <S T="1" F="OSSuite2" M="Ignore" />.. </C
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2590
                        Entropy (8bit):5.075257657360688
                        Encrypted:false
                        SSDEEP:
                        MD5:BDF7A85D77A7A9A08217C0CB325CE529
                        SHA1:FDB99B6FCFCB3A1FADC7F2BF3FA732066DCA7CCE
                        SHA-256:DE6571CE52A60192E70D8E4C643DFEE986D4E2D6C5CA9CF023DC5F257AD8A41C
                        SHA-512:7DB95EEEA4A3A4C8AED6201E79B0D816AEC9A92833E70252AB29D665F47D0D192BB8BB3AF0F425099341E9B7587386017EC54BD05520E5D0668EB984B08AEE61
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120602" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAndLanguage" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <SS T="1" G="{68442bc6-3519-4b08-a80c-e0a68fc8cda3}" />.. <SS T="2" G="{8e685dc2-78f7-47e1-9a99-6a636773669a}" />.. <R T="3" R="120100" />.. </S>.. <C T="U16" I="0" O="true" N="Click2RunPackageVersionBuild">.. <S T="1" F="PackageVersionBuild" M="Ignore" />.. </C>.. <C T="U16" I="1" O="true" N="Click2RunPackageVersionMajor">.. <S T="1" F="PackageVersionMajor" M="Ignore" />.. </C>.. <C T="U16" I="2" O="true" N="Click2RunPackageVersionMinor">.. <S T="1" F="PackageVersionMinor" M="Ignore" />.. </C>.. <C T="U16" I="3" O="true" N="Click2RunPackageVersionRevision">.. <S T="1" F="PackageVersionUpdate" M="Ignore" />.. </C>.. <C T="W" I="4" O="true" N
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2230
                        Entropy (8bit):5.090316412928055
                        Encrypted:false
                        SSDEEP:
                        MD5:C2A4ABFDD24022353511FF1DFA07D76F
                        SHA1:974905183127597728B513519A44F20E912C511E
                        SHA-256:1877E128F35F857DA624F829894397A1C70D2B9CF10854445F1F34252AD9F835
                        SHA-512:41D08B73CE5B1C31805AEFB165D34580D9642AC65189EEAD7E1A0AD6F603EABA667A0EE1BDF70A5FFF1EAEB90C3960E6743BA56CF7486F699B13AB45A47AC4A5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120603" V="9" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <SS T="1" G="{c3d2f3fc-0f86-43ac-b7a3-007bf524f38f}" />.. <SS T="2" G="{1f59c07e-f223-4c7f-aa23-df28da66734b}" />.. <SS T="3" G="{dd5250a9-3404-43b0-9b7a-6f4eaea6497d}" />.. <SS T="4" G="{1a6b5bd0-2f17-420c-8ba0-ee01132ee441}" />.. <SS T="5" G="{6b5515e4-c848-4ef0-92d4-747ecc491c7b}" />.. <R T="6" R="120100" />.. <R T="7" R="120607" />.. </S>.. <C T="FT" I="0" O="true" N="FirstRunTime">.. <S T="1" F="FirstRunTime" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="Alias">.. <S T="3" F="Alias" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="IsLabMachine">.. <S T="3" F="IsLabMachine" M="Ignore" />.. </C>.. <C T="B" I="3" O="tr
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):424
                        Entropy (8bit):4.591118413981684
                        Encrypted:false
                        SSDEEP:
                        MD5:96AB38CED32FE5BC21C378A66F08532E
                        SHA1:41753CBDD215BAE6A1C7545F09176774206BB394
                        SHA-256:9AC1918D35B0D3EBB5234BF4506EC6CA554563D973F97747FEC09F08A43E7443
                        SHA-512:33482117C8E464E9AB8FD24C21897BD855A61B9299F53713FDF561B31EDEDF2247CD6E3288199E7CEF99239C6EBB68FF84096BEEB51D42ECB2A794CF45A45472
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120604" V="1" DC="SM" T="Subrule" S="1" xmlns="">.. <S>.. <SS T="1" G="{1a6b5bd0-2f17-420c-8ba0-ee01132ee441}" />.. <R T="2" R="120100" />.. </S>.. <C T="W" I="0" O="true">.. <O T="COALESCE">.. <L>.. <S T="1" F="UserCid" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):876
                        Entropy (8bit):4.651543954286572
                        Encrypted:false
                        SSDEEP:
                        MD5:04DBBB154D35DB709278DA22934FBD28
                        SHA1:31B5F7D46DB191C41E617AA1CEABD7F1B14105CA
                        SHA-256:79064CF51492A1089C52A3D89442A724A9B9C728F57BE750CF94B25BD8F14B06
                        SHA-512:CDFD76800A394B58BE52044E2370C13C1C11248D0C7F5D0F467151087C01F3774E1E79E7F47C55120D09DA330785F8C103B1055CA97914F82F3FDC758FBBD7E5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120605" V="0" DC="SM" EN="Office.System.SystemHealthMetadataDelayedLogin" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" S="1" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <SS T="1" G="{1a6b5bd0-2f17-420c-8ba0-ee01132ee441}" />.. <R T="2" R="120604" />.. <R T="3" R="120125" />.. <TH T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="2" F="0" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </L>.. <R>.. <S T="3" F="0" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="true" N="CID">.. <S T="1" F="UserCid" M="Ignore" />.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):203
                        Entropy (8bit):4.878690652619822
                        Encrypted:false
                        SSDEEP:
                        MD5:DBB52AF4488BAB09B2089BE57282F58F
                        SHA1:4CB6B84A9A211030C1E6E97A820BF4C16CDF0941
                        SHA-256:FADB57E240685960C16DC6A779DA5F9510DCB56A878F73FF2903E96A1AF5DB62
                        SHA-512:674AF27936D4739C00FBEF4797722C65B1C1DDB85E7EF38927744902A6E0779D4F2B35F80530C1D6B30FF14E1170127D57C5504141A7216AF79A08CB342DCC77
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120607" V="1" DC="SM" T="Subrule" ER="120603" xmlns="">.. <S>.. <UTS T="1" Id="bbpzs" A="940tc 9x5js" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2159
                        Entropy (8bit):3.9073233641894265
                        Encrypted:false
                        SSDEEP:
                        MD5:7867D966455B59074A704388D170319D
                        SHA1:264B4219FB6D879E05333D12A9D395D5F78DD59B
                        SHA-256:8A1104C088B17EEE6640EB6408993729A1758AF2AA1346E1826E55BC362F52A1
                        SHA-512:1AB68121782297C19EE112D15DFDC2EDD0C0367769057B7CCD223C7A5CBDCAF7F167A59E21054AF279EC4EA5140117D1098BB8BE61436940B8962DB9464CB34F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120608" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="120609" />.. <R T="2" R="120679" />.. <R T="3" R="120610" />.. <R T="4" R="120612" />.. <R T="5" R="120614" />.. <R T="6" R="120616" />.. <R T="7" R="120618" />.. <R T="8" R="120620" />.. <R T="9" R="120622" />.. <R T="10" R="120624" />.. <R T="11" R="120626" />.. <R T="12" R="120628" />.. <R T="13" R="120630" />.. <R T="14" R="120632" />.. <R T="15" R="120634" />.. <R T="16" R="120636" />.. <R T="17" R="120638" />.. <R T="18" R="120640" />.. <R T="19" R="120642" />.. <R T="20" R="120644" />.. <R T="21" R="120646" />.. <R T="22" R="120648" />.. <R T="23" R="120650" />.. <R T="24" R="120652" />.. <R T="25" R="120654" />.. <R T="26" R="120656" />.. <R T="27" R="120658" />.. <R T="28" R="120660" />.. <R T="29" R="120662" />.. <R T="30" R="120664" />.. <R T="31" R="120666" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):407
                        Entropy (8bit):4.6572794887278315
                        Encrypted:false
                        SSDEEP:
                        MD5:65B69E5A3B7F2A8B6F88821E1E123C35
                        SHA1:62D4EB4D1E8B5B0BE1F757ED53E860AA8B65D078
                        SHA-256:14577CC263D559DFF7390FB015A4589C20B911EE43D00E9B6E005023BF0A3BE2
                        SHA-512:184DA76286B0CB195AB067055F9A75D81893649BE4A9DFB2E7F0A7D49B4CA0214C4CB3813C9A76C1D3777FCE9B7AE00114CA0DE2E5D4F267EB6F65D892DE7B3A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120609" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120682" />.. <SR T="2" R="^([Dd][Ee][Ll][Ll])">.. <S T="1" F="0" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="0" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):473
                        Entropy (8bit):4.205975317519947
                        Encrypted:false
                        SSDEEP:
                        MD5:06E0531C2FB1D1F39CDB8D7AD05D6408
                        SHA1:B3096D90E1FAD9B8D7F50B7FCE122051074BBB5C
                        SHA-256:EF4969810EF7F911935B3AC916E727643C20AACC4B483ED331FFC0DFE9D58E45
                        SHA-512:C118B9644C50BDB6AAD81CEBF6B870D4404F815A48A127D960631FBE9507B5DD7D7CB55A9D956924F5890FEA61CD00DBA3235D0CD16F032A8BE5AC26CBFD23BA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120610" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120609" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Dell Inc." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):414
                        Entropy (8bit):4.674386030617272
                        Encrypted:false
                        SSDEEP:
                        MD5:339C1D489F7328CF786AF8E671978A2B
                        SHA1:BBB21DFF74E109C1E5A72CC28750ECA3EDC6C06B
                        SHA-256:BF551F2EB7D335B2F871675231CE845D9F4F58E581420338D0359B95628AD821
                        SHA-512:0A9A1D0610CE60D613B11FA6D3B79981A207C3A1D6F6A82DBA41BA2826D444AFDBEBDAEF8C40DA69762F3973F0BA192CC06DE6B5B105109928E4A8B8C7293476
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120611" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120609" />.. <SR T="2" R="([Ll][Ee][Nn][Oo][Vv][Oo])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):470
                        Entropy (8bit):4.1951580617514095
                        Encrypted:false
                        SSDEEP:
                        MD5:412318ABA58BFAAE19C99C7E2746E2CC
                        SHA1:1C5A03125695AB61229AC5F2B1571A006D69E279
                        SHA-256:7E2DEAE7BC8BE274D0B75A233102FCF1D5B5487C18CC2A3A8ED0A54C96D35114
                        SHA-512:E6A3E16B9265DA2C008387675E0BB8C893DD20FFBA9A51FD0CEDF6CC2567400B01B593D613BFFEE3CC5C4374320824FC9A83881CF41C88762A683A434E390CA0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120612" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120611" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="LENOVO" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):631
                        Entropy (8bit):4.603788936312325
                        Encrypted:false
                        SSDEEP:
                        MD5:4348787B7D3D0DC035A61705FB5AB249
                        SHA1:22EC17C43B0A9D97F023FDD74279266A6E582396
                        SHA-256:EEA55FD50EDE40F4BB8362A61357E0DEF8A77EADFDB20738FE27F8CCB2743411
                        SHA-512:1BFFBB7A1218D5227AFD4D5850124A54E72F79057F0F1B7A772D1290D3CA402B06A338C48E66162960B0E9A406039F950F2144A17DB3B78F25079966128E4440
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120613" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120611" />.. <SR T="2" R="^([Hh][Pp]([^E]|$))">.. <S T="1" F="1" M="Ignore" />.. </SR>.. <SR T="3" R="([Hh][Ee][Ww][Ll][Ee][Tt][Tt])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <O T="COALESCE">.. <L>.. <S T="2" F="Matched" M="Ignore" />.. </L>.. <R>.. <S T="3" F="Matched" M="Ignore" />.. </R>.. </O>.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):466
                        Entropy (8bit):4.193004288778686
                        Encrypted:false
                        SSDEEP:
                        MD5:35DFCC791A845C64421189331497A661
                        SHA1:B45B4BE4F4C71516B536858A710588EC10DF8820
                        SHA-256:BE994BE8685B883E806FEAEDADD305F1E1949824AFD110A16EAFB57F185A91AE
                        SHA-512:2DAE5627BF694FF59CFA77DD5DB117787DBA5F0877D2376D7798244C8506D2E937970197069B542663E3B7328F2CDC70F086E0D62D45CECC5180D8C8A638A63A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120614" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120613" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="HP" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):406
                        Entropy (8bit):4.632533717029051
                        Encrypted:false
                        SSDEEP:
                        MD5:B90B9BE6A7BAC1711DEE5CE232B2E94D
                        SHA1:3F10EF69424146FECBBEC7CA150C2ABA2012CDD0
                        SHA-256:8A0E4470CD864756A275B4AA1031DDC5DA5F23EE15F2F32E7471486706D4FAE8
                        SHA-512:D8BADD17C6E79D0CB5C2587E2E2AF6AE6CC953EB37A6528275F2E4ED27FFD061B17533A84F7191D1E2F8DDCEE41060C4D8BF0A5B574DF92CDA4B1D7EDED50F97
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120615" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120613" />.. <SR T="2" R="([Aa][Ss][Uu][Ss])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):485
                        Entropy (8bit):4.281880348798365
                        Encrypted:false
                        SSDEEP:
                        MD5:334B45B484EF7619670897201178FF58
                        SHA1:92674C780644457811D5C0748A7E6CF17A394F43
                        SHA-256:8502269A6109E7711E54421F93715711FED5F5E74F1BA6D5157E78915DAFD734
                        SHA-512:09E6EC5C530580ED452119A5BAE9C14416568CF988FDB1632473DE03ABAB49830E437F5EABD9CA2CFAFDFFE8E8C041DC0DD3B09F4D9397DA7E982548995D8D76
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120616" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120615" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="ASUSTek COMPUTER INC." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):426
                        Entropy (8bit):4.6962448377654304
                        Encrypted:false
                        SSDEEP:
                        MD5:35CCEEFF000C954D410A77F453065D1F
                        SHA1:A5D63E155A10144704F5822B953709773FEBAE0D
                        SHA-256:20597533B501F8FAB7839E02D8ABAFB80FC5A2E285DD1F0B9B0DCF545BE5BCB7
                        SHA-512:C01928FAAC7B9418B30BDC7966596C9D88F337E4F08C668F45A422F6B1466A7963CF34AB8B4B42B0BC6DC325F1073F4A056DA254988932EB50AF731A51A56B3E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120617" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120615" />.. <SR T="2" R="([Mm][Ii][Cc][Rr][Oo][Ss][Oo][Ff][Tt])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):485
                        Entropy (8bit):4.287410652563269
                        Encrypted:false
                        SSDEEP:
                        MD5:8EC027165A3E21C727E80EBB9ADEF71E
                        SHA1:2FB79913DD54B1E38DD01AD6BB040D7A9DECF42E
                        SHA-256:05A4D3224EA1A9B60AF8EA460F3988CB56B2F3CF2121C62736481F758337532E
                        SHA-512:AB39A98C3DD6F7679545DC2606223AA9EBC8F9C3774F826B7421C3D7C8F3C84575E85EF09796A56BCDFC7C8DD139BE50D12C1D164E516E7D79D5B0EC02D5D814
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120618" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120617" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Microsoft Corporation" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):406
                        Entropy (8bit):4.633591499154347
                        Encrypted:false
                        SSDEEP:
                        MD5:625C289C6B0A50FD422D53F793C4F597
                        SHA1:A4357A9ADAE1D7E4915F81D9D581DF6FF543EACC
                        SHA-256:DB26E84F2CAC5797F3A6B7BD1FB0F301008423B54B1A79DC4744AAF22AA5E048
                        SHA-512:4FF6AC58278A0EEA07CDF54A25F75EECDC4C5099B70B8BA78AE7F0E7AB706749162A3288E3A06ED2423B1E125D28722612B45B0FE1DF92F940B5340CB9896F21
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120619" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120617" />.. <SR T="2" R="([Aa][Cc][Ee][Rr])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):693
                        Entropy (8bit):5.143120097477506
                        Encrypted:false
                        SSDEEP:
                        MD5:5DAA798D410B091C6CF0840ACC4CC2BD
                        SHA1:5A972054C3E8D49592D5B0C698387923BDF0471D
                        SHA-256:D15E7C265B8ABFC52EB5C7D7305EEB22DFD6CCC08B3AFA0A24CA4F015334D720
                        SHA-512:0AE4CE4E96A2365FD22CCE81C44041999819DEA854CF5180ABE6DB8D196FA0BE95A6E4BA44F0AFB6C8736333F76817860B4E422EA3043510560B7A43C5968154
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12061" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CMLFailedMemberKeyboardDeleteUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18064" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="CommandID" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CommandID">.. <S T="1" F="CommandID" />.. </C>.. <C T="U32" I="1" O="false" N="DeleteCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):468
                        Entropy (8bit):4.197261472236799
                        Encrypted:false
                        SSDEEP:
                        MD5:71F0951EA15173C7F0362D810E28E45E
                        SHA1:4681933089B96D3BF09DDF0A11F191639714C27D
                        SHA-256:D32BFEA2695F8C52DCED0B1583B6DA03F3561AD437DC7D3896CBDC1313056E0F
                        SHA-512:533777EF483C956D1CC3B1288149509BE583D2D5C03C758D0270F080B4AAA9220078ACF6654C3384848DC6AA4F9C45403945A719B109C34D68B9E256DA4B24EE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120620" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120619" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Acer" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):414
                        Entropy (8bit):4.6783364461327315
                        Encrypted:false
                        SSDEEP:
                        MD5:60DEA6CE841CA8AD4E0A211CD7C8F3FE
                        SHA1:F6044230BD4EAA87E303A8527B8395C20B1B8FF0
                        SHA-256:27C2722C7C0B0E8FED81EC83F94FDFA1BC571988669A4761CA4B59471C06A980
                        SHA-512:AA566E937684DFDCD58DFAAAE445C7B039662A1449CCFD55CD0E2A4AF1A9FDB1E7570A840075423900DC61D0D4F7F79A045DBC8564B49BA6CC8B12D66AA02021
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120621" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120619" />.. <SR T="2" R="([Vv][Mm][Ww][Aa][Rr][Ee])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):476
                        Entropy (8bit):4.22811572036184
                        Encrypted:false
                        SSDEEP:
                        MD5:457A5F976AD0282D508FBAA9324E16F5
                        SHA1:434D3D156E72AD480DBD83408B06BDE55E2AE01B
                        SHA-256:DD56C1A606CFA555EB57ED376CFF096AF210EBFB7BC8D094BC7E95D0894D8FC0
                        SHA-512:F99EF62DBC972435E225B40D6606872327CE51BCEA8D645FBED3B5E16FF867D85601E1BF14B513843F7B78C1BDD2ADBA5C655C2B7E60435730B32016055C5D1C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120622" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120621" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="VMWare, Inc." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):463
                        Entropy (8bit):4.859532001229515
                        Encrypted:false
                        SSDEEP:
                        MD5:ADFDBD75CD4297F4916B242437984D16
                        SHA1:4C59415E8603DAE74C028057634D2DC2452A6E4F
                        SHA-256:04D8B5A7D49D78082BF9434934088AB48A38F6E1F1C5CEEDAA88A0B645EDE628
                        SHA-512:357C78B743883DD850721C1647927FD56941CA5F05F53631C0A7589D14D906F2ACC9E7C7F2CDDCAC03722C0D618F61F9BA635B2DC7371F23ABE78E1DE5CE2126
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120623" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120621" />.. <SR T="2" R="([Gg][Ii][Gg][Aa][Bb][Yy][Tt][Ee] [Tt][Ee][Cc][Hh][Nn][Oo][Ll][Oo][Gg][Yy])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):493
                        Entropy (8bit):4.34368899482594
                        Encrypted:false
                        SSDEEP:
                        MD5:6173E239BAE8292FF4A8B7D6A40DB87E
                        SHA1:6CF1E1A370A6F0965F41B8FDC9425D04A9D2EFC9
                        SHA-256:5A5A6A4BDB9AD830B86F333C8257E6D9375E2444E877A3FE21893990967F7443
                        SHA-512:E4AC2B71A31AF04BD9C85CDA66F8E868CA0990169F27835D7F6AFFC851D40530882DA1DDC77632D9FFC9B533B1A6BDCD5044042F1997B1A1461D97B843FB2212
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120624" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120623" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Gigabyte Technology Co., Ltd." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):4.702556538492113
                        Encrypted:false
                        SSDEEP:
                        MD5:D71CA7D8B97E449623026F230F079473
                        SHA1:2736A1021B8AF2656DAACE091A0F982B8D89C1B4
                        SHA-256:B4921EB7824423DF397715D79C428FFD8D23AB405DBB92C659416B3CC3A53B30
                        SHA-512:D8636EC84167B21C580A6431C1322EA8F2C538AF9DFB5E2872DAFF50F6CEB6074C1CDA531D71F628C35E045A78702F310A6D55ECEB666846FFD8DBE7C597A9F3
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120625" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120623" />.. <SR T="2" R="([Ff][Uu][Jj][Ii][Tt][Ss][Uu])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):471
                        Entropy (8bit):4.2151970758641175
                        Encrypted:false
                        SSDEEP:
                        MD5:2DE20824474537B2E8A85EA357D90492
                        SHA1:7494791D147401A2996D5EC109070D93F95F8887
                        SHA-256:C260B953131FBFAD78D6B49BAD60C1D6AAA19E74AFC582196267F671056CB040
                        SHA-512:684EB49FBAADBDE57279AA3890E5758ACEE4650A77CB9E6DCD978081185D355DA05E00C893A611416A3EAAE761A1A715B8B5D08CD1FF671F07379E2A2308A6BE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120626" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120625" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="FUJITSU" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):403
                        Entropy (8bit):4.631780153299309
                        Encrypted:false
                        SSDEEP:
                        MD5:01C88E2F782367845E4E7395BC3D2537
                        SHA1:F9AA242A7859B16154E046F588985D6E3D80F865
                        SHA-256:D0925652D807E5EC2102F8E47DA2349FEFC7C83F268C1E26E6929FF78017BA97
                        SHA-512:C55E91C6B3D51560DAA09CD67929F10F4A4DEB0852E9237F050FF32834BCB1332A8D8493F26EA4E97499F0CC75D8D4CDC99483C975BB2B1D0ECEB35FC94DD4B9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120627" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120625" />.. <SR T="2" R="^([Nn][Ee][Cc])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):467
                        Entropy (8bit):4.1917245890453705
                        Encrypted:false
                        SSDEEP:
                        MD5:8D088B54B9F32F643B010C2F6B858CF3
                        SHA1:5DB7CEAE0D040422482716205933D12B25D91F5C
                        SHA-256:924E64EA08D415C28726E8908BDE4866296A1D03CB55CCB1E409B3C832039549
                        SHA-512:F5DDF23CADA4086090CD06458CDCC3167CE0AB0FA8BFD9946C35D2647E026CC51DA95B14BB62335CEFABE30218398FF1EF7B2070941B83D83392378F88C74021
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120628" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120627" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="NEC" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):427
                        Entropy (8bit):4.713873502277379
                        Encrypted:false
                        SSDEEP:
                        MD5:EE4C19262BE1A2F7E324C8FFF43711B9
                        SHA1:58CEB1B10D33FE7817B15B80A7115235ED3290CD
                        SHA-256:E3D4343C911A7EB6162D9A9D6CC24E22C3FD894474779980EAAAA41DABAE3600
                        SHA-512:74CF7E1C550781EB797A07404DA0C4E71049FDB49181BCEFC6A6DAE29C8CC20BF7382E82B41B0FCC34945163E0EBDFCC6099168C536C8E399CE1E001B0C047D6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120629" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120627" />.. <SR T="2" R="([Mm][Ii][Cc][Rr][Oo]-[Ss][Tt][Aa][Rr])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):798
                        Entropy (8bit):5.106575275345922
                        Encrypted:false
                        SSDEEP:
                        MD5:CB3575788FD780D9ADBA679665B99724
                        SHA1:8573FBB9491507ECB12FAE5EF03300BD8015A443
                        SHA-256:A288725A69DBA63AD7512DDEAF7B6A79432E7638F4FD132A9DF4BA1B150FBBC1
                        SHA-512:F91C8980C45E8160F126143517975261B0D6252BACFB2A14B023078C87E03B94B597FAF489DB5B6DD8BA6647A8D9328A4840D8F64C08CE4BC9B141CF0E71A0A0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12062" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CMLDisabledKeyboardDeleteUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18065" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="CommandID" />.. <F N="GroupOwner" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CommandID">.. <S T="1" F="CommandID" />.. </C>.. <C T="B" I="1" O="false" N="IsOwner">.. <S T="1" F="GroupOwner" />.. </C>.. <C T="U32" I="2" O="false" N="DeleteCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):498
                        Entropy (8bit):4.345033521110774
                        Encrypted:false
                        SSDEEP:
                        MD5:D445E71093654D819977E92DC1BEA4C2
                        SHA1:901158B6E16C9F5D5994EA7D28E1142D2260E56F
                        SHA-256:8AAC5DA12EB3F5E56DB27B5E3B49877B48326F03B88ED1ABC86DB4ABCEEA3DC8
                        SHA-512:860F8AE95A6E10EFAF4B09780F7E9D6437F2A2B271FE1F3A1EB546CB8785E0E1ACCA5BBB132C1315DE5DF150C57D0FF90E68321E2A2039C568A2DCA528D30A45
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120630" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120629" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Micro-Star International Co., Ltd." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):414
                        Entropy (8bit):4.70636739252088
                        Encrypted:false
                        SSDEEP:
                        MD5:F8B67D9C7C80D0D5D068A522E04E5BF6
                        SHA1:103AEFC92BB1A6CBFF1A46ADB42C74771EDB3A98
                        SHA-256:74A788D9C988ADBA00D44600C5054F0B8E8D1B139BA193EC6445909AC5AB69EB
                        SHA-512:809C658285594DA9B975E67947181CEB8B8A14C7A23BFDE991324631374D8CDCBE81A20EB4D4ADD62F16B4AECE5148AA23D0A2BA22545EC3C52D3A2120F60C78
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120631" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120629" />.. <SR T="2" R="([Hh][Uu][Aa][Ww][Ee][Ii])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):470
                        Entropy (8bit):4.217477689401777
                        Encrypted:false
                        SSDEEP:
                        MD5:E4E868C0E60BB02708992DEA649E5BAC
                        SHA1:E1CF851199026C708ADE0249FAB6BA8CFA767018
                        SHA-256:671CACE304C2BEC09797E274613F8B225C0C89BDCA91095D9E97C0AB823217F6
                        SHA-512:A7A633225A37E40C1053993D35C73A2681010327DB0F371D25590059D88F292598457B57CA59DAFFF6FA1FBB73C64AD317BCFB9AD2F5B30F6EFD329794FBDA19
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120632" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120631" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="HUAWEI" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):4.700127252839735
                        Encrypted:false
                        SSDEEP:
                        MD5:A56B19D1694E86279834868C5DC09EFA
                        SHA1:ED3E3DB45A05E081EDEBE051058260554B95DE28
                        SHA-256:AE3B4B604106C31492B441C81152261475FAA95AA6DA53E08154D89578F3628F
                        SHA-512:F0F334BF4ED3769D3E25EDD45F3EC5223EE97FEA5445CAEEA06053183F34080668428C94450212C76BD36CCB2A7D43B3063733A56BC429E4143F535C0097518A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120633" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120631" />.. <SR T="2" R="([Ss][Aa][Mm][Ss][Uu][Nn][Gg])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):493
                        Entropy (8bit):4.332049884367182
                        Encrypted:false
                        SSDEEP:
                        MD5:14EE1EFB404CE2961819E9910D32ED8B
                        SHA1:E9E158E6EA2E1E38439EBA77888F544C15E99586
                        SHA-256:7B906996183CB27453AD418974873EEE72F3385F63BF571858F6401F4093497B
                        SHA-512:BEDF9CADBFB05ADA560339F92402BD2AEA272F4EA7B9DF63866F6AA7239C16BC5815CB0DADB63AC8D62D562DBBC95124CFC34952E3DD8CE57D95D78F663522B4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120634" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120633" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="SAMSUNG ELECTRONICS CO., LTD." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):419
                        Entropy (8bit):4.7271483641341145
                        Encrypted:false
                        SSDEEP:
                        MD5:0DA9C9196DB899170854B41E3D5D9EA1
                        SHA1:F35DF3B9FA5E5EA4125973611151E7FDF66A18F9
                        SHA-256:77A606F82D7D37FBF6679EABA8550675C187CA8DD43BB8ECE5382CD28FD0F1C4
                        SHA-512:B952BA986CD4D7628959D6C1737045117B695D5442C4B5432BB503A9506362DD95377AAEF493589159B3920A4F2B795F998207BB9672BF05F745B86149268385
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120635" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120633" />.. <SR T="2" R="^([Tt][Oo][Ss][Hh][Ii][Bb][Aa])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):471
                        Entropy (8bit):4.226895111966722
                        Encrypted:false
                        SSDEEP:
                        MD5:8764070AC93EBD90F9E7C690517236B7
                        SHA1:D19E8910B34675FA3EEEF92CB742362716A79F08
                        SHA-256:C9F519FC70242D36AC6D806B2E877C1BD0D599C332040F2AABF278987B43F6A4
                        SHA-512:EA193A3AFBC7CBBDF25332B331CE489EA7F9280A955C635BAABEB9EA8650D21A55D0091E8A4DD147A53BAE8C60E9134FE5C8D09B39A0FA1E11A12CE6DA32F14C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120636" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120635" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="TOSHIBA" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):426
                        Entropy (8bit):4.756492284193415
                        Encrypted:false
                        SSDEEP:
                        MD5:0522754CBC09F4BCF7CDEC0E0359C7E4
                        SHA1:35C4F8F09CB6E6F5281E29EC798EF53507D3A10D
                        SHA-256:EFE5DB7DEC50EA1B141774CF86C7707F9A1BCE19FEB9ED6C2EDE41FF727970C0
                        SHA-512:BEE66938D1820952A05B44E5B8E5C5AE67419991028C9E0FCAAEAFF72C4212A223EB13BE002E86FBAAE629B60BEBEDC57C6ED7599307A3CA37638DDF45FEE4C5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120637" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120635" />.. <SR T="2" R="([Pp][Aa][Nn][Aa][Ss][Oo][Nn][Ii][Cc])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):485
                        Entropy (8bit):4.301937212475881
                        Encrypted:false
                        SSDEEP:
                        MD5:FB9DDD7E46A95AED4C5BE420754B48EB
                        SHA1:FE1F580D8B327B933B84BC554C96B9B7FC347EA0
                        SHA-256:18DDC54D834DF8DCA9BE7940CF1E8A5706732944EF103AC52E1F21AD5C5913E0
                        SHA-512:B015208B4A69D92240806E0255BF9178C8BB23A8664A1BAC7455DF8A8F55A2FD17CCF2D0C7EEAC71B722B1F6743012116238184D6EEB3F9640ED361CD2044CEC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120638" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120637" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Panasonic Corporation" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):422
                        Entropy (8bit):4.771127070886058
                        Encrypted:false
                        SSDEEP:
                        MD5:7A5D67D05CD72B274C23CF3EEF0F653C
                        SHA1:44FDFFC7634F0DF843D033E80ED7B1C14776C1D7
                        SHA-256:3F12D3E39D535DC2185CE9B3942146DF746EA074456BFEC310E1ED340DB4664C
                        SHA-512:0F2A5381818725E847A66CF24E38CE73DE4B5891F874C97323A5325E7F103273D0BEAB589ADCE7153B9C721F6E655D2F7C3FB68EC72FC0EE8072819341FBD9A5
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120639" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120637" />.. <SR T="2" R="([Dd][Yy][Nn][Aa][Bb][Oo][Oo][Kk])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4434
                        Entropy (8bit):4.705975145017496
                        Encrypted:false
                        SSDEEP:
                        MD5:D7E113D342A5FFF3DACFC3029D8483BE
                        SHA1:B4143CC29AFD31746B5962362FC15BA70E3EC6B5
                        SHA-256:B3F5618B7F282D5F063223893A24084DBFCC484DFCA74233AB4E981317B87ACA
                        SHA-512:DF6D26ACF263CEFFA7DCC8AB9425F9657DA1F8BFB02433B14560A7278D17E8E10CE9BB16AE9A198543DCD28484C960B1543077161FFB1DEA2EFDF2490D9BC609
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12063" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.CalendarViewAndAQVMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="421" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="422" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="423" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="4" E="424" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="5" E="425" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="6" E="426" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="7" E="427" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="8" E="428" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="9" E="429" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="10">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="SessionType
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):477
                        Entropy (8bit):4.268621150243774
                        Encrypted:false
                        SSDEEP:
                        MD5:575301E7E80AC0FAD0AF834F7B6051BD
                        SHA1:40FB99A34E0B1C807D97488C6B2897BCCAF75CA9
                        SHA-256:8B3086A1691172CDD2E12026DB925E9CF55D306C930E382FD500DFC3AC911FDC
                        SHA-512:0B021CFABCC2ACE9EEE61AB0B4B5E45F77A35303091E4EA12B8E5B6C5D99B1D8F65D2C3D2134F5064AA0110F3CF43F50C4185184ABE6E716C7B06BF6B04F1975
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120640" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120639" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Dynabook Inc." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):403
                        Entropy (8bit):4.623684876186324
                        Encrypted:false
                        SSDEEP:
                        MD5:2323C68E5DE03C8B831C142721147791
                        SHA1:5575D8249002DFE272E7C99A2912BF1DDF975812
                        SHA-256:D3F070C572A1F9BFD734B0E09C7E6D024FB518FEE891816C0BCE1FAC0A7B275C
                        SHA-512:CB639F40AE119D0057F45B7317A8A3F012D4C110CD198F0FB745068A99CAD342F06EA2393836A73C5D708D008295E3B53155B024033BFAE23D1A2E4D9632CB80
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120641" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120639" />.. <SR T="2" R="^([Mm][Ss][Ii])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):467
                        Entropy (8bit):4.187138487439212
                        Encrypted:false
                        SSDEEP:
                        MD5:F662A632E0A48D2C905371F0545FE504
                        SHA1:80099C09B78D1F5B1ED2D9E2E2E6FE2946E3AF6B
                        SHA-256:A76F84F9547880B7EA450BA5D68468FDB359AE02431BD1C51C55AECD57EFF02E
                        SHA-512:E22FC23F817B6799C8F4F05D145F69981368E4DF8347CF5DFED984AB1297B59A1AAADF20237D9D4B36F055B1E6010C925FBC7FB12C41006772C00AAA7FF10512
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120642" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120641" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="MSI" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):399
                        Entropy (8bit):4.613799768302636
                        Encrypted:false
                        SSDEEP:
                        MD5:371E6A35FDF963315CB8B9E2D97A093B
                        SHA1:209DF896D2B1C94E4328E38352C6814759F97043
                        SHA-256:53DA042EB7E13F11ABB14B622E5BAE2C3C11205C085D017637E782E97338B956
                        SHA-512:7EFE9DA76691B9DB3927B1A92833287880D1B27155A7FCB090F9B2136E66E785ECB90551099E263AF7415E59D94C5F8B735816219ABFD6DACD26FA59E6F5BC71
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120643" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120641" />.. <SR T="2" R="^([Ll][Gg])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):478
                        Entropy (8bit):4.262064656349606
                        Encrypted:false
                        SSDEEP:
                        MD5:471C35C7165309D2A1164AACB5E6A5D4
                        SHA1:14BF0CE7DC09CB415363576BB11FEFB99EF1CDAA
                        SHA-256:6D213FD39ECFEE579F497F350718908DA386ECF37BA25F18F830493EBB94FA14
                        SHA-512:D9ADB18CEF8E43C3DE0DBAF9B4BD198EA4E01EF2290B3D9E42459CBFDDBBBE7A91FFBFDA95D0DACFF6C1DE77E4D3588EBEF9DBAE94B05099ACB2A64B525B9568
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120644" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120643" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="LG Electronics" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):424
                        Entropy (8bit):4.74950451521939
                        Encrypted:false
                        SSDEEP:
                        MD5:E23F9F2DD52948A8552AAFB6B65FBD01
                        SHA1:A5064569D0DF2AB58AF45863AB39CB04F9A5F504
                        SHA-256:542A4A4D551B5781CAC32464BDA8895A8875AEA02C6D0EAD1F558EBA21CE0125
                        SHA-512:5DD281D77EB90F836FB8C428A937D7D43BB65CF27C781AD343BFF6F293F131FF3E6FFAFB5398B83553FF63DD7B8B806CFB358A9C95CD8DC659F4173507ED022B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120645" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120643" />.. <SR T="2" R="([Aa][Mm][Aa][Zz][Oo][Nn] [Ee][Cc]2)">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):474
                        Entropy (8bit):4.242917853424237
                        Encrypted:false
                        SSDEEP:
                        MD5:B19BDD7E42D575E46883717A50AA3E7E
                        SHA1:19B7504AFF0769AE6D6E041E7112DB67370E9E7E
                        SHA-256:0D7D953A7528B80C23AAE758A033AA030DD5A810E25FE6EBD3BF10D5AB6AB902
                        SHA-512:888B2B4F6B8A5201C1BB68DF65DD020DD248DD73C6EEBACD21E6B43D0F23FABDB02E4B2FC153291C405729EAD4CECB2D7625B32DA8F129CF14E9F0F990BD4376
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120646" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120645" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Amazon EC2" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):447
                        Entropy (8bit):4.822977286433141
                        Encrypted:false
                        SSDEEP:
                        MD5:E83F63B14A2EA144C0BAEE761B558035
                        SHA1:7C8966F696D9CFB6E207E1AF49DE87840F8C5955
                        SHA-256:C7AB1D8055D48AADA457034C6AA388BAF7ECFD645D9A4DB0B7CEF68F75056237
                        SHA-512:36EEA746A12C311B1CE1813EE7C74D035D8F259AC7EB16C2CE068574ED78DEC6E503284EFCA456340FB5869B626736E732C799DD954D14290CB09F79F52B7922
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120647" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120645" />.. <SR T="2" R="([Aa][Pp][Aa][Cc][Hh][Ee] [Ss][Oo][Ff][Tt][Ww][Aa][Rr][Ee])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):490
                        Entropy (8bit):4.336439364850335
                        Encrypted:false
                        SSDEEP:
                        MD5:78F1691BB705D39901D63A21F709A7D8
                        SHA1:E53EF3006A4C4417CF4153BBA83491D4F26CA5F2
                        SHA-256:0822E3264AADBC30AD7D40C2C36BD4ABEAD1A56E5B5FE8B655F9965B5EAD6834
                        SHA-512:CA52A3AD7436C286A878A5BF07F3D7420510A0EA4E3B9AEAC9F506893CEE11FC1A7E322A2A06F95977ECECA5CCA72D19A876A46B4DC94486C98D8BB99ED56603
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120648" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120647" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Apache Software Foundation" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):415
                        Entropy (8bit):4.708166014987959
                        Encrypted:false
                        SSDEEP:
                        MD5:BC9E42B9A99F058C7B3170BD17FE6D2A
                        SHA1:A32457536F4A6FD802E7F2D1040725E11CCBE243
                        SHA-256:A9B18AB2FEDA77C6F9DE4DDCEDF4901FBD7E0B1C80F016D67F8D55B4705432BD
                        SHA-512:44CE4B6A3B5D1044AE876CF2D541F720BFAF61D9AAD6FE78738FD59F3D0D203004DBFFA0F201BCF7A0BB9D00B3E09AB2DCC633AAEEA713F741F1CAF735C191DB
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120649" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120647" />.. <SR T="2" R="^([Ff][Ee][Dd][Oo][Rr][Aa])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):575
                        Entropy (8bit):5.181682163491506
                        Encrypted:false
                        SSDEEP:
                        MD5:25133C96CF7B58B378EF4C1A2B742E56
                        SHA1:524A0B35803ADC1157DFA3EA275AE69AD4BCAC54
                        SHA-256:4E6667DBADE804E2954C4350734A2741885F6AFD7E0328CA8B2CC411BC7E48EF
                        SHA-512:8EC1B6C64BE31BA7054E660C7BF27A4EE29311C5D2D741E1E7B65120CEF85CC001265008C4C5F5FF9A45CE933FE197DB50A2D82BB521E4227163DF08A6F13DBD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12064" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.CalModulePeekShowCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="431" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountCalendarPeekShown">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):478
                        Entropy (8bit):4.271258224632099
                        Encrypted:false
                        SSDEEP:
                        MD5:B080B4F31D24832210050A0126DE2375
                        SHA1:53A1147DEE8667765B7E909C332FCAE31009DD72
                        SHA-256:A39959229CA246F51B29DBBF1869018534980C7A42302CF7ACB1728C49FAC781
                        SHA-512:643E4506764AD4B649E5C414C49B2620B6DB119936FE220C7519A4BF9B84625761F3FEA0EED86D2ECF1D21E4D96747677A8868CB7B329DB4F68D1238048C7A2E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120650" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120649" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Fedora Project" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):414
                        Entropy (8bit):4.692996362198924
                        Encrypted:false
                        SSDEEP:
                        MD5:AD8027EE582EC74CD5F7CAB0CB6D7EC7
                        SHA1:3C6DD7A985E65379659E91BC4BA960EB73221AD6
                        SHA-256:28943F1B43815E9580C0D9ACA2919FB5CCF02E0DBD01E1A5E69836DDF8AF880B
                        SHA-512:7DEBDAB161639A537FAA8040561719A5B73F68E86716B9614C9C5043EDF2027FDBB4F412EB44F4A72BA936E3BDE9DA41BBBABDACAF2CF9A971EE5FD15F1C45A7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120651" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120649" />.. <SR T="2" R="([Gg][Oo][Oo][Gg][Ll][Ee])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):470
                        Entropy (8bit):4.2089329821017705
                        Encrypted:false
                        SSDEEP:
                        MD5:0BC50B7C4F04174F769738A4FBD1F6BD
                        SHA1:30F4DD9CED236135AC1D8536E95F35C0C3124BDD
                        SHA-256:D78F1070801506EA7EE61D157BBAC8731A7CC4BA05DC7E32CFCA8435B63B6F15
                        SHA-512:D6A2350B173235AB598BB78165313408572DB9B524907A5FAED9036BC03C2F3F19C256A0E1F22F2B44B28D3EC8493735839AAA8917041A8097195E8EBACD0207
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120652" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120651" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Google" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):4.707441332702557
                        Encrypted:false
                        SSDEEP:
                        MD5:5248BF652511D9BCCE0BA286DCC65C81
                        SHA1:E82239EA7EC5F71D754BC08354048177101BA015
                        SHA-256:ADA1BBF488324F9465B40D4783D24AC20111C4D3370474BABCC811D9E678484D
                        SHA-512:2A350872D1AF6A2D6145643EA978A11DAB1813BF2F3EDD9E254CFF17ACC7ADBCC8DCF3A28556A7754A678D2DDFFD6C55BD7BF40E9A3236C6947356C184560738
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120653" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120651" />.. <SR T="2" R="([Ii][Nn][Nn][Oo][Tt][Ee][Kk])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):476
                        Entropy (8bit):4.2639253454828845
                        Encrypted:false
                        SSDEEP:
                        MD5:74D872EA16DF03506D214F0862DBBDE3
                        SHA1:B28FB5CA2D214A1BEA17E4E8CA33EC18B85A9D2A
                        SHA-256:D4B330CC22D526E5DF442E4BFB9FA4BA3FB78C9E472E26A97A20B79B3E997FFF
                        SHA-512:80173D696448A339E9FDE45813886F091D3224F4DD80244AA69F22C5C8FC70E7BA0104BA8EB963BB30635ED4509EEA0FC644C49E98D829D94CA670F7A36A2F0B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120654" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120653" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="innotek GmbH" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):4.719055574263021
                        Encrypted:false
                        SSDEEP:
                        MD5:4589ED351E39681CC16D932D3F00E043
                        SHA1:3F78108447DF75252CDE358C9A7B76F77567ABE3
                        SHA-256:3DD9187F700156092C092BC4F0CE9FD591EB3B148E472F2FD6E150A63679355A
                        SHA-512:79347B7D7558E94AFB3D505B61482902E2BC28F90CFB21F99865F298C3703B2FDE2B7AA22AD737AC3E2384307B2E4240753558DD5279207A4DC2E0668F8B38A1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120655" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120653" />.. <SR T="2" R="([Nn][Ii][Mm][Bb][Oo][Xx][Xx])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):476
                        Entropy (8bit):4.247714040651271
                        Encrypted:false
                        SSDEEP:
                        MD5:E9BE600B1629FB86977739F79E522855
                        SHA1:E8FE8DA9AF7554E24472781536AF73AB4AB5E848
                        SHA-256:D405F8DFA42BAF113F7D75FF2650DC97AA67D6C9101CDB28C34B564C79713BA7
                        SHA-512:1CD43ABD8160FBDED875F2601DD27899D4BE685D6CCC8271F880F2296B8660670E711345CAEC0A43C40EBF3C99F263BFE6B069EB724C6F6523364963F927B002
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120656" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120655" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Nimboxx Inc." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):4.717740715102454
                        Encrypted:false
                        SSDEEP:
                        MD5:F0AD1492A6C44F24EA5948EBE21A6EEC
                        SHA1:CE9B6CF27C5858386804C9AF8422D5EBCE7F8A09
                        SHA-256:AABBCFC63506C7DA9091B8CAC522A7E5410662D7B2ECADB28F291C7D71BFB4B4
                        SHA-512:D09B79738C85CABD4B0E13132774A1092709EE599DE5DDD522D9B4B8D44BFA4C66358CDDDD0AC002F60AA3E2CAF97CFB0D4A8D9874DB7554319C9023398D177C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120657" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120655" />.. <SR T="2" R="([Nn][Uu][Tt][Aa][Nn][Ii][Xx])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):471
                        Entropy (8bit):4.228778217940084
                        Encrypted:false
                        SSDEEP:
                        MD5:13A32A5095B4B723741BF367FDF2C6F1
                        SHA1:5824783B0D6852BAEB81B7C46CCFCB8B631AD9E1
                        SHA-256:E165302F8BC925034B7EC362326E1662B8B98A694A83B9DE7E6D8EB57873FB51
                        SHA-512:F14725F392E7FFA6C2716E8542F032CA04410421ECEC4BA2D85C451731F5E52966FE6C7DA24FC3C02EB2E3A8E55D449DDA2D65A92819A17C3BB34B8B6DAC9014
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120658" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120657" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Nutanix" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):467
                        Entropy (8bit):4.8714291926289155
                        Encrypted:false
                        SSDEEP:
                        MD5:E88110ADF90C4E766B2DF19C87D43A7C
                        SHA1:D2EC11B7076E6B36B77A0D9A23D3474DEB963B00
                        SHA-256:91112D57084BE41D76797D1684A4E8D175099465C8110B203403C3A9C47DB32E
                        SHA-512:ABA5DB1FE2D2BDECF8B1B20B3A1E06E0CF3430DEC7EA20F606318A17153307AF182A0AD07AE4DEB7DDDA472FE993D72056056A0128FC9A2AA953A79789DD3F3D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120659" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120657" />.. <SR T="2" R="([Oo][Pp][Ee][Nn][Ss][Tt][Aa][Cc][Kk] [Ff][Oo][Uu][Nn][Dd][Aa][Tt][Ii][Oo][Nn])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2524
                        Entropy (8bit):4.665113980597472
                        Encrypted:false
                        SSDEEP:
                        MD5:E459FF78211FA78FD5277C5F2641C28A
                        SHA1:859339B503504C29BEC1D55ED4FCD4DF216EA73F
                        SHA-256:44445E050DBE029E43FAEC4660DA8173D56D7762C85A1294BA2D33D1E9BAEC45
                        SHA-512:56FCEC2D665BFB2A372378DCC32C4F3A8DEBE626EC4F91BDB38E5D805F9971F5152BBBB9EBE1FFEF72AEC691603B6865E1466C26C3532F81B451FCFA9FD089B2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12065" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.TodoViewAndCalModulePeekMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="421" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="422" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="424" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="4" E="426" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="5" E="428" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="6">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="SessionType" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="SessionType" />.. </L>.. <R>.. <V V="4
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):484
                        Entropy (8bit):4.296339986640134
                        Encrypted:false
                        SSDEEP:
                        MD5:01C9D68421183B1C2627CD66E8ABF65F
                        SHA1:9DA726F692A04BB6D47344543D1854C9D2AE4573
                        SHA-256:30BBD2B7869B3F7AA3953118BB3B2DFE4C30B1979FE60A0A0C57917871F951BD
                        SHA-512:85E76A243F53D7B44074777CF28E43174ED3FEC1C36962167400C10BEF2CBE5E6ACC91BF749760DDE502F35275897E8EC6ABF7AC9B466344D0CBDF25BF602412
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120660" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120659" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="OpenStack Foundation" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):410
                        Entropy (8bit):4.646408713691851
                        Encrypted:false
                        SSDEEP:
                        MD5:2D65473C614D1268DF2EA60EFB643897
                        SHA1:772F3DAE5ADCAEB273ED3A7AD6F6593ADBDDD730
                        SHA-256:0779CA4DBF3100D51E9567AA7546F15D11A5C3B2FCE9715F63AD0453A70B214C
                        SHA-512:C11251F9FA6EF43957B7150D3940D502B523A3B3AADB529280059BCC7A673BBD4090C19AC7735FDC32F6189A2181D707F47EA424505B5FBE6F8861467FBADE32
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120661" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120659" />.. <SR T="2" R="([Oo][Vv][Ii][Rr][Tt])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):469
                        Entropy (8bit):4.194064506144483
                        Encrypted:false
                        SSDEEP:
                        MD5:2CC750D02C6EAF952125F6E6D7F7BB98
                        SHA1:A3EBB2B065B4E26C9AC8C37740F66D7843514579
                        SHA-256:FD74E64FF498ADFC38B6AE08AD9A798D324CC1C3DAC3A0BEE85224F11B6361DB
                        SHA-512:CF2B15C479825A10B7D6EF2B2A14F6A26BFF007632606C0C59BD918CA4737F2AB510110F10672FC908291C022A38FB12C17D93820E218098B7DDE9B07CB70D67
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120662" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120661" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="oVirt" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):426
                        Entropy (8bit):4.7392703636081
                        Encrypted:false
                        SSDEEP:
                        MD5:4390F647CB7FEC8C2CE2C78107BDFAE1
                        SHA1:EBF65EC154A9235FF2A322D37AC44B27A34231FA
                        SHA-256:FE0E93D944C17F4B45E9C6A87DC5830BE5E9B2FF3CA96F695582C500C2F72306
                        SHA-512:D4AF7868AF8FF8B76262281751FEBE750F239E4523F5DFB75A177682BCAE98BE9C3ADC42294B5309C8D01885E3FC6678828F494B6685A665553E1B00AD396482
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120663" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120661" />.. <SR T="2" R="([Pp][Aa][Rr][Aa][Ll][Ll][Ee][Ll][Ss])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):501
                        Entropy (8bit):4.344663057090138
                        Encrypted:false
                        SSDEEP:
                        MD5:6A8CA81E31901B83B19A8020B04C80E8
                        SHA1:2210F1C09691EA735817ED6F8E7A46BCBAB5B2F8
                        SHA-256:FDAE644926E54898717049D29AEBC3B0D5307D8465980A51494DE51566EF12D7
                        SHA-512:0F569BCF070AE1A19744685EEF47F4AA806AD219DD489B216D37B01390B37E40D37C470023BCA1C82CC54F3D69281F6B3297432ADDA6122A8C19288349319BE6
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120664" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120663" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Parallels Software International Inc." T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):406
                        Entropy (8bit):4.6411784830495595
                        Encrypted:false
                        SSDEEP:
                        MD5:883F186E839874979EBCB7B432E16F99
                        SHA1:F50665AF1F284A13F5308FCE336328A38A039D2C
                        SHA-256:4BF322ACC6BFBC1929028FA3AA7AB8BDE4F583E0E9BEB2E723B7F2E8A585D128
                        SHA-512:FB52ED2702F29793A6BC99487CDD1250D9810A6A63D3C5542740A950D9A6AC2F68C84A3143B8FC50C5D42DFB05B08776944A35BF94CDD930B90C890CC3C8E8CC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120665" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120663" />.. <SR T="2" R="([Pp][Ss][Ss][Cc])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):473
                        Entropy (8bit):4.217923487613823
                        Encrypted:false
                        SSDEEP:
                        MD5:CEA041A87401CD8CE4DF647954F8BE8C
                        SHA1:D3CDC4FFB37CA85381717575681F0CB263C3D5C6
                        SHA-256:80C0D9EC448144FDCE9CC43D7B3563F7E5CBCF2690A2828C39577E71DAC57E5E
                        SHA-512:1252F6087DECBF61BBA1A3102730AFCCAF0FB8A642E64E3128CA2D6D702B883C918AE7032FAA2E0D3B13FD86B48F866EFBBA80BD59CC33269D71027C4742D69A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120666" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120665" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="PSSC Labs" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):407
                        Entropy (8bit):4.675144216115545
                        Encrypted:false
                        SSDEEP:
                        MD5:B822BF741576F3FC8C6C85A001530C72
                        SHA1:D9D9DD2E994B4D595BE34257DB9CDE87A1154427
                        SHA-256:3CB288E64C3D4CCA4CB43DE69E548FB395F2B810D7AEC57651DD85AD0C1C367D
                        SHA-512:05050EAB7DE4ED2FD89AEA419F596A1F16D801994342CF198B3097F51DEF7B70AB725912C38996BC404615FB2C84E8A959A569F6B489AE652C60C50669CCF285
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120667" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120665" />.. <SR T="2" R="^([Qq][Ee][Mm][Uu])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):468
                        Entropy (8bit):4.2031880617577935
                        Encrypted:false
                        SSDEEP:
                        MD5:F9B53AA50528028C466350E3B1983441
                        SHA1:F1115BAF42CD66A04A53CF9BEF4D8BB77B2D64CE
                        SHA-256:83F20F7BB71C73715ED97A7B4F82C14149739B6FBB5FE4CDF22FDAB7E92E45C8
                        SHA-512:2B4490F7BBA567234EA6666DE60C008F34B593DFB066B8F0F122B572BC712242C5A1C7DC2E373C30B7CDE7956980E96DD4FE868DF135FA646427FEBDC8DEF1B1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120668" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120667" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="QEMU" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):415
                        Entropy (8bit):4.6857727650984105
                        Encrypted:false
                        SSDEEP:
                        MD5:ABB87A4B97F97F7392AD35C8ED191771
                        SHA1:B4FEEFC43EE59EA95784949E9D1CFC82A4659A21
                        SHA-256:F351A864EED582E9A7399AA2B04607BE46ACCB7FA7B7130D1AC06B51FA981053
                        SHA-512:4AACCC7764EF40F07FEA6C5F58A606F9F079D9102748A169B6EF5F8FE41671BE9CD997EE16BD62B4C2EB884A277A9B63BE7D29B7A264C084C9A276B2A014520A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120669" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120667" />.. <SR T="2" R="([Rr][Ee][Dd] [Hh][Aa][Tt])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1294
                        Entropy (8bit):5.100233374667119
                        Encrypted:false
                        SSDEEP:
                        MD5:F059FB615F950B2AF41E1DC39D434793
                        SHA1:5E67351A1177C53F385767ED3A3F86CC53CF14DE
                        SHA-256:65C9226F67D362C031306D8DC3C2CEAC0515DAB2B04FE7C2E567256CA9B2C5DF
                        SHA-512:038F085B88BC37D275D0A2E2A5A0017F41E4707815FEB1E9A226F9CE7408C0CA4B7ED2BFF37FA12FB0FB0E1303762EE5C6AAD87FBE58E41EEF42A899C100A0AD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12066" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.CalendarOptions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="421" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="B" I="0" O="false" N="ShowWeekNumbers">.. <S T="1" F="ShowWeekNumbers" />.. </C>.. <C T="B" I="1" O="false" N="ShowAlternateCalendars">.. <S T="1" F="ShowAlternateCalendars" />.. </C>.. <C T="B" I="2" O="false" N="WeatherEnabled">.. <S T="1" F="WeatherEnabled" />.. </C>.. <C T="U32" I="3" O="false" N="DowStart">.. <S T="1" F="DowStart" />.. </C>.. <C T="U32" I="4" O="false" N="AltCalType">.. <S T="1" F="AltCalType" />.. </C>.. <C T="U32" I="5" O="false" N="AltCalLang">.. <S T="1" F="AltCalLang" />.. </C>.. <C T="U32" I="6" O="false" N="CalViewDirection">.. <S T="1" F="CalViewDirection" />.. </C>.. <C T="U32" I="7" O="false" N="CalTextD
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):471
                        Entropy (8bit):4.207510286120392
                        Encrypted:false
                        SSDEEP:
                        MD5:C7D044602693FD113B2227BFDD7C38AB
                        SHA1:D91E75F2970B3FD2FA8BE17DA4C5CF66846012F7
                        SHA-256:229004FEAB8D2FADB5B0479EDB4B028771F0B2CB602F0D5338AD0A4B5B88BF74
                        SHA-512:77D2CF43F55F4F1CB078096C21972EE61AB5EA181F2DA4552E0A5B0F686CED0526FB37D8236086F05BDA5FC70309D63D324C65F9CEAC8C77F5207F1CFB835A9E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120670" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120669" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Red Hat" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):431
                        Entropy (8bit):4.753551727724934
                        Encrypted:false
                        SSDEEP:
                        MD5:8535BFB69FB3B7CFD9D8FBDAC87D554B
                        SHA1:C2302F7D1B7F997217AB9118E0AD3AA54C28E3E7
                        SHA-256:B9A1D397BC24E63060E8CBA125A36B8340A23798CBBD2C52A6A5AB156120F5CB
                        SHA-512:F96D22A00B452C61A78D9DA233BE16ADF9CBC7442674395DA39AC14294461D39F9ABC01457E9B67ACD5BC76A306C180D074565B301C880CD84938ADEEA2BF1C8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120671" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120669" />.. <SR T="2" R="^([Ss][Uu][Pp][Ee][Rr][Mm][Ii][Cc][Rr][Oo])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):474
                        Entropy (8bit):4.23626016395163
                        Encrypted:false
                        SSDEEP:
                        MD5:724C271FCB607628EEC70A186A603103
                        SHA1:BE7929E8D0541A3AEB1304F886F11C902FCED80B
                        SHA-256:493FC695D672D190AF88D5655B8D06422EB17B85503AADE03D6561870EF7FC78
                        SHA-512:1B25DD208C684D90E0EBADAC2B3C92298F786794D11BD0C8C6644E4F7192DBD0CC55526EAF6180F00D327F45EB627D1390C1CD85D3031C79F2EE9201D5ACFAB0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120672" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120671" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Supermicro" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):426
                        Entropy (8bit):4.745665849136667
                        Encrypted:false
                        SSDEEP:
                        MD5:D544D941DD5721A2120596DD34CD66BC
                        SHA1:C8EFD6A44553B5354499E1075076482E9DB4E5DE
                        SHA-256:D78A8AD83C8137D184D185C9B3284CCBB4AE51A7A865B17EC3258431E181E85D
                        SHA-512:A76AAE8D1ECD14D7A83614D2E176EFEF2069BB8BC6F8EFDF8E19AB5F82D77A5405B42C3165C3BE440D5E57183FF7BF30799A6286B6AE3B9BF89B5DC24EE78A24
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120673" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120671" />.. <SR T="2" R="([Tt][Hh][Ii][Nn][Pp][Uu][Tt][Ee][Rr])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):473
                        Entropy (8bit):4.248875269975603
                        Encrypted:false
                        SSDEEP:
                        MD5:EEF72D3AF72D6BB233E57D2ECA4C5E67
                        SHA1:9E18B80D63577BA258830285EC677FCBEE8A2DDE
                        SHA-256:53C4747902AB67B935C8C69F47211471864CB7778368ECA3A2153115B5987B1B
                        SHA-512:AD250D8A8066F34B14A09136DABC50F5D00713FCBC4CA5EF2B1175F006FA82984A90E289523CECFE1582642CB416AFD40D4E762071AF16D3343A23537B5FA03A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120674" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120673" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Thinputer" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):4.732537564749622
                        Encrypted:false
                        SSDEEP:
                        MD5:A5803FCA008EBB4215D6794478260470
                        SHA1:5E677E1996D94573FD855D4E8FC49C76D356A3D3
                        SHA-256:E59E9B6E8D289B006C02A4D14370B9ED243FBD404D40725E72313D72EF2EFD39
                        SHA-512:5998A4265BEA6FFA2DAF861ADFA70637FE789064DE5C347666227A4CD43DA5870F42D7D7A4C6D1F68D3C506B28E48A5759E726A869D423608C231C7625614C3F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120675" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120673" />.. <SR T="2" R="([Uu][Pp][Cc][Ll][Oo][Uu][Dd])">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):471
                        Entropy (8bit):4.227442357041803
                        Encrypted:false
                        SSDEEP:
                        MD5:CD1AA78C49B0AACEDC26FEC026752B16
                        SHA1:618104D0FEB37645B5F10137583656D4AB430A77
                        SHA-256:488A6F09DEA3BEA002C89A776BC512D7B50BD1576029453BFC5410F055149EA1
                        SHA-512:8C8D5AE73E100D8D7D9A7ECE0D3EDF77923908E5A8331225081A79C4148D75254B67270312ABFE896F507FBD6076FDEE7CDC4044F21C9EE57CA6FFFDB441552B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120676" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120675" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="UpCloud" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):404
                        Entropy (8bit):4.661785998382742
                        Encrypted:false
                        SSDEEP:
                        MD5:5A96DB174EACD20069A02B5407C0C808
                        SHA1:F63B6C071FE243A6462273299AFBCC26F3497DCA
                        SHA-256:71AB12643C94273B06500417B12EE7C071DB68BD0C9CCD6BF5EBCC02D8FD7B5B
                        SHA-512:013545F0949122842C701443655EFCEDB605A872E4B7DBC389F2DE2AFA848908FC6AD78FFDC5C1BFD541B7FAA66FF28500F80799E8C056DAC8A7087A27E29732
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120677" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120675" />.. <SR T="2" R="(^[Xx][Ee][Nn]$)">.. <S T="1" F="1" M="Ignore" />.. </SR>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="Matched" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="1" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):467
                        Entropy (8bit):4.197534104082195
                        Encrypted:false
                        SSDEEP:
                        MD5:073ABBFA23AC972DC68EB643BBE1835E
                        SHA1:EBE02BAA9F41ABD4AC59B1F26F931B309F051EBF
                        SHA-256:26F32E8DE1BEE15D714DFDF574584D100A1BAEAA57AEBB834829138AC10B441B
                        SHA-512:14C2CDCFDFAA5851D9C4E0DE174F11E90A6B1A262ABDDE31ACF753E714DE13796F2E2D91736CA36995ACF5B3CC236126F417A2EC0D84806AE6A3D078757C154B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120678" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120677" />.. <TH T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </TH>.. </S>.. <C T="W" I="0" O="false">.. <V V="Xen" T="W" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):173
                        Entropy (8bit):4.672551969702864
                        Encrypted:false
                        SSDEEP:
                        MD5:B9512C3DF946D084BC86CCFE97B1693E
                        SHA1:0335928D066C9044DA7A74ADF1D86C7396BA457E
                        SHA-256:C1C8E4336998E5C12444902701408EB2C0CDFEBE1C0991C9F04D2F5FC44F0113
                        SHA-512:02E9E4A251D6DA0906599E4F31EFB020C0EB8FF4A306D8FD8848ECA37F92FA512FD83DB9770D5F0FBCF99CB78A1CEE63CB8A6749075FF04314E4967D7639129E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120679" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120677" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):812
                        Entropy (8bit):5.088127872577837
                        Encrypted:false
                        SSDEEP:
                        MD5:BB63794E636D3F60D3B31166EC88933B
                        SHA1:C63C06243ABA48595B38E813FCC50C3D1A888CC4
                        SHA-256:9F0F8618AD3737E5F21821CAD685DD1711BE5AFDA74394DC63000DBA3061398C
                        SHA-512:7A9297218A09EFB48C46157102FE7F9A6DB7F24392D9390C03C258CE6EB573D66A252A38A6D15553ACE9B87664AD14B3CA62773926C5805D5DDFF9B5CBDE553E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12067" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslatorSettingsManagerGetAccountErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9lmvm" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. <F N="LoadState" />.. </S>.. </G>.. <C T="I64" I="0" O="false" N="GetCurrentAccountErrorHResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="GetCurrentAccountLoadState">.. <S T="1" F="LoadState" />.. </C>.. <C T="U32" I="2" O="false" N="GetCurrentAccountErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1951
                        Entropy (8bit):3.4239352185415433
                        Encrypted:false
                        SSDEEP:
                        MD5:0E2FF33E08A681C369342EB32360F033
                        SHA1:827699C57C66DF9179D5C6EBDDEA36C4B66E1079
                        SHA-256:01533738732C643B5034DF2146B9686CE4F59A17DD8A8CC50A214F4E4D915E82
                        SHA-512:CC376375DB510C2E461D0DD801ABD8E64302E2D2A763898E958B11E3CDB5C8C3E11ED1078830FC50E2F7A00BF7218181A08BF1FE0B36734216348DB854FFD3E9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120680" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <SS T="1" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" />.. <R T="2" R="120682" />.. <F T="3">.. <O T="LT">.. <L>.. <S T="1" F="SysVolSize" M="Ignore" />.. </L>.. <R>.. <V V="500000" T="U64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="SysVolSize" M="Ignore" />.. </L>.. <R>.. <V V="500000" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <O T="MUL">.. <L>.. <V V="1000" T="U16" />.. </L>.. <R>.. <O T="DIV">.. <L>.. <S T="3" F="SysVolSize" />.. </L>.. <R>.. <V V="1000"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):957
                        Entropy (8bit):3.7910096944673426
                        Encrypted:false
                        SSDEEP:
                        MD5:7CB423666403BEA7A8D658FDDF5341C4
                        SHA1:43B1A2F4370E48C17945E88CBF7A21CA813343E6
                        SHA-256:CB168457A3B5FDC287A8930C717726C65BBC4F246F8EF3DDD35B3185CD30F34D
                        SHA-512:0FA51B0C7E4D06C7F700758F99E461D71F2B03F9BB2B5E1539D2B447479EB4D73AB72ED03A9A2D2CB3EFEDAF3DCB14BD67A462276E9EED35410F11B99BE4E34E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120681" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="120608" />.. <R T="2" R="120680" />.. <TH T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="2" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" M="Ignore" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </TH>.. </S>.. <C T="U32" I="0" O="false">.. <S T="2" F="0" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="0" M="Ignore" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):500
                        Entropy (8bit):4.749671363510405
                        Encrypted:false
                        SSDEEP:
                        MD5:EEA245B12A09AC27DD15649C4E555836
                        SHA1:CC08485C36F44D94F727C6819780F19FA378ECCF
                        SHA-256:A8D3913C3EE127C05D6835F2BCFDC5C8CB570C0930A320FEEDF5133A33DBBEBC
                        SHA-512:770EC2D85F6F5A3B3B757D5C1D80B55870F34773C7350A0C7F14F296D0559B4C379CD04ADAC10B5ED30D9A9ED4591820CAB5E1381F389E138600DCEB58FDCBC7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120682" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryStartup" />.. <R T="2" R="120100" />.. <SS T="3" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" />.. </S>.. <C T="W" I="0" O="false">.. <O T="COALESCE">.. <L>.. <S T="3" F="DeviceManufacturer" M="Ignore" />.. </L>.. <R>.. <V V="Other" T="W" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):712
                        Entropy (8bit):5.068884957842964
                        Encrypted:false
                        SSDEEP:
                        MD5:62A11B8133F37331683E5B8897154EAF
                        SHA1:47A9DC01D15D259F5C445736B0492FC1AAB62A34
                        SHA-256:EA2A4A3916E96F7EE58D5C7F41AC1953F3AE2EBC02BCE35E5000CD9D0C0F4D22
                        SHA-512:905BA078C5DEC2509E34C57AAC4F4247994AADCA3E7333959FDC2C3F51952C6550FBAC4634D80DB538405292339938A33397DD4B9CCB1C27646EA224830FB851
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12068" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslatorSettingsManagerGetAccountFallbackCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9lmvq" />.. <UTS T="2" Id="9lmvr" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="FallbackDefaultAccountCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SignedInIdentityNullCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):666
                        Entropy (8bit):5.107260269014555
                        Encrypted:false
                        SSDEEP:
                        MD5:34BE6A4B481848B19747DD19036543EA
                        SHA1:DDB5869398D679691EE7E12EF195040873CB5408
                        SHA-256:24FEEDB3782E9DC6B6399D3E04C720D1CE91E60A9FD43B4A98FCE60218A04EED
                        SHA-512:0598058A70E4BF3EA88AAE95CFAD1830668D6CB038EF47F30F1B05CD2F495607BCC882274EB074917D889AF37EAA25C7EA894CECC96572921F59820DCF05FA64
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12069" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslatorInlineSettingsMessageError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9lmu7" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I64" I="0" O="false" N="MessageErrorHResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="MessageErrorHResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):645
                        Entropy (8bit):5.319772979451407
                        Encrypted:false
                        SSDEEP:
                        MD5:36BD8507402C0A4BB397CA9B4F5856C7
                        SHA1:752C0F305FFC9851B1503EAEBB1B3E637E4A7553
                        SHA-256:11B3399693167CF6082DD1C6A98781B63048BD456BB76D6811E49ABE7805E509
                        SHA-512:6A5540421F0D8E4A64BB2D21DE2FA83ADB412B3779BA22A15E9F04B9BA963D175C0A8CA58ACABF1D34F2363EECC87A7FEC9CF63EF7A73D706373C7B6DF130244
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12070" V="0" DC="SM" EN="Office.Outlook.Desktop.MobileUpsellAccountIdETW" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3899" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3751" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="true" N="AccountUIDFromAccountSetup">.. <S T="1" F="AccountUID" />.. </C>.. <C T="G" I="1" O="true" N="AccountUID">.. <S T="2" F="AccountUID" />.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2110
                        Entropy (8bit):4.672934814782323
                        Encrypted:false
                        SSDEEP:
                        MD5:64E32A71D44F6B2AC4E10F391E426296
                        SHA1:C066C3D399E29810BAB145DE0EA6F1C15CECFCCD
                        SHA-256:BCB8CE17E1EA8A7FD72182B4C0F9AADF7BE216207279DD3FE7FA87254FF9F8F3
                        SHA-512:F431C2E34B297BB87893224B83A3A1F828D06F69418A515D35C9B4D73EA5EFDC952D8D52157E316E83277A6F4548C75B13F3692BCF8CDC16C67EA14B3A23B38E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12073" V="0" DC="SM" EN="Office.Outlook.Desktop.Options.AdvIntlSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3749" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="3750" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="640" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="641" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsEnabled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="IsEnabled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="3" F="IsDisabled" />..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2553
                        Entropy (8bit):4.177134573279338
                        Encrypted:false
                        SSDEEP:
                        MD5:4C8147E27F5F8F0AB17FD573C4C18002
                        SHA1:BEF7D01CA403D5813E65CBB928914F1E8802C8BB
                        SHA-256:12AE3E31D4D6844123A07B8B2E03EBDFAD062C61042B81D68D29F16851C17F3C
                        SHA-512:9282D3E1345B55378EA110148A678E21D12AED12C65709C742C5FB327EC5516432539BC06DBA4F7348C7090B09CC6DEED656ED0D02C06D8216A6FF482274AB67
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12074" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.NativeFileUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="911" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <S T="1" F="FileTypeWXP" />.. </L>.. <R>.. <S T="1" F="OpenInApp" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <S T="1" F="FileTypeWXP" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="OpenInApp" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T=
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):575
                        Entropy (8bit):4.76510523034736
                        Encrypted:false
                        SSDEEP:
                        MD5:B9545D3B9F407EA26A343798FB2BFE3D
                        SHA1:B45E2BA0AB14084113A78228F038A99997BA6C8C
                        SHA-256:CFCF2A36215A0554CD81D717BA72233851177501415EDBFB02101A1B8D2490E3
                        SHA-512:9E5844701DC8205657F88256E7E5869839BDFBF518DEC22669A46C7D0AC1BA38791DCAD9E91836F4D30DB2A46914D4506517147642FB41560B982657AB7C89EF
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12076" V="0" DC="ESM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="675" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="676" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <G>.. <S T="1">.. <F N="ConnID" />.. </S>.. <S T="2">.. <F N="ConnID" />.. </S>.. </G>.. <C T="W" I="0" O="false">.. <S T="1" F="PUID" />.. </C>.. <C T="W" I="1" O="false">.. <S T="2" F="OMSTenantId" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):721
                        Entropy (8bit):4.939646716571213
                        Encrypted:false
                        SSDEEP:
                        MD5:A373AE3A4E8C8B6F58E78A555D5E8D9C
                        SHA1:D7561652E926D1AC777F05DD7A5C5419CF0B0EC9
                        SHA-256:879FA98DD402E755615BDBEB97BB7367D8DBF1BB74794D0C04E211418047BE5F
                        SHA-512:6FFE5527662034856CC329F92F8EB67DC96FB15420C805C5068B6578A041B47C55F7302631777669621B445C1375822DC2018E9E502AC214C06634167E74B11A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12079" V="1" DC="SM" EN="Office.Outlook.Desktop.Pcx.CreatePersona" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="89mtl" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Result" />.. <F N="Step" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountOfCreatePersona">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="I64" I="1" O="false" N="Result">.. <S T="1" F="Result" />.. </C>.. <C T="W" I="2" O="false" N="Step">.. <S T="1" F="Step" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):467
                        Entropy (8bit):5.36133231635639
                        Encrypted:false
                        SSDEEP:
                        MD5:68E9D8069205624EFD3A3335B447534B
                        SHA1:1E883DA314B132A266AF3E01A3DC8CFCEEE5A5FF
                        SHA-256:1C9674AC64B462B47C1267B29A6DD8BEEEC03BDF9ECD8087FC86F54DFC1D1108
                        SHA-512:8F953795D88B6BE8C47F2D4F11674B4B8D624261B0C9C61E8D5162062F5E978C6530608FD97B0AF1E14B68981974C0C44DD12BA4AE10B719DF6505905B3F5EE8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12083" V="1" DC="SM" EN="Office.Outlook.Desktop.ExchangeProvider.CachedMode" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="758" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="B" I="0" O="false" N="IsCachedMode">.. <S T="1" F="IsCached" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):782
                        Entropy (8bit):4.928631086096819
                        Encrypted:false
                        SSDEEP:
                        MD5:EED747633A3EAAFD393444E5C4521337
                        SHA1:B01D5755A51188F580D505E45828ADBF89513E37
                        SHA-256:C1183C7A3F14A26817D8C6B89F5BCF93A78A5E6B074C08646FC219ECA78F0988
                        SHA-512:61A55CA8DF4B25033CF378D87EF3D065E091BBB0D574ABF79F3766618ED32F400DCE4D7252F91BEA690A42F5D8E03F7BFDC736C3332A3EBD89EEA15A8E33B7B8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12086" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CMLViewForGroups" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9ucgi" />.. <UTS T="2" Id="9ucgh" />.. </S>.. <C T="B" I="0" O="false" N="IsCMLViewLoaded">.. <O T="COALESCE">.. <L>.. <S T="2" F="UsingCMLInGroups" />.. </L>.. <R>.. <S T="1" F="UsingCMLInGroups" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false" N="OverrideCMLSet">.. <O T="COALESCE">.. <L>.. <S T="2" F="OverrideCMLSet" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):746
                        Entropy (8bit):5.220332285838108
                        Encrypted:false
                        SSDEEP:
                        MD5:048FAA720DA6BB69A9676D5AA753CF2B
                        SHA1:D93CFB48EBF6FD2452AB9A4D77CCE2EC460E2C4C
                        SHA-256:20C6288F469B4BE734A430A80928C342618A8A454C7E87C9036554789DC91DD0
                        SHA-512:D5B99D1B50FCC9C8C5EC3282FF11A24D533FE7A4D2CDE363891330BD965710C0A2FFD63E2B429DDBD0F3B28BEA240AD2293D4B23E6F53A51CF8DB8C31D04CBF9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12088" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtLaunchEventType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8251" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="LaunchEventType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="LaunchEventType">.. <S T="1" F="LaunchEventType" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfLaunchEvents">.. <A T="SUM">.. <S T="1" F="NumberOfLaunchEvents" />.. </A>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):535
                        Entropy (8bit):5.345710525366189
                        Encrypted:false
                        SSDEEP:
                        MD5:DDC4D05D165221F91DB96646A86A8087
                        SHA1:550BE3E53241C8614D2C6E46939E435EDB71510A
                        SHA-256:E387E41AE46159ED15EF460D61CAB84358231EC2B671DA0E3410C25A326DDD91
                        SHA-512:52352A80C0B3F0F0F1456F015B447FCD39D4F159714EA60ABDBE03F33F22F59148E4F6184F14CB96C482BA222A815BAB5D6FA7D6C4ED39E8F330E2A23159903C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12090" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtFailedCreatingLaunchEventControl" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8253" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="AppId">.. <S T="1" F="AppId" />.. </C>.. <C T="U32" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2011
                        Entropy (8bit):4.223129071751869
                        Encrypted:false
                        SSDEEP:
                        MD5:1706318DBA07AE638795DD73B9A0EA61
                        SHA1:843A46C16CC66E31377D42FA130BEFFE0E6770E8
                        SHA-256:FDED02687F0FDBDDE8C843B85F3B892AADECDDA4BA4DB8D2E17890E753DD94C9
                        SHA-512:D6EDEA34E7B9A47D95D664EB7DDBDEBAC41123E48F140C7E4399E897A31D1FDE30811483C661BFC3386D0558BCDD56A1632301CD06E5A5B8848FB0EB2E62B05D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12091" V="1" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtLaunchEventItemSession" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8254" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="NumberOfAddInInstancesCreated" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="NumberOfAddInInstancesCreated" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2529
                        Entropy (8bit):3.9692322038527506
                        Encrypted:false
                        SSDEEP:
                        MD5:A01AC438F1AE9545554B78DE214C6A17
                        SHA1:C73FF52F38398D15CF1DABFFA29A26A7506003C1
                        SHA-256:EEB63D7917099E4047022D072EC9012D235A1DAB03AFC74A542BA2F328642C4F
                        SHA-512:C9DA1EC101A1C7EC19736031BD408266FCE0B215822DBF18C9D15DB32342B7F40321AB3739653D8984044F4578C827E5ECBA419889715AE786A64B6B8F4FA46A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12092" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtLaunchEventFunctionDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8255" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="FunctionDuration" />.. </L>.. <R>.. <V V="0" T="D" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="FunctionDuration" />.. </L>.. <R>.. <V V="1" T="D" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="FunctionD
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):707
                        Entropy (8bit):5.15403076294197
                        Encrypted:false
                        SSDEEP:
                        MD5:712A277F1141F42968EF0936E727F0C7
                        SHA1:9E841ABFDAABC99AC965789B8E20BAB497EADD82
                        SHA-256:BD4DE37DF1EC8BAE8BCACEEBB9E465FBEC77FEB4C2A6F914C828A47DC1CD414B
                        SHA-512:A1A97ADA0B8DA4A4308DEBC622150CF90EF1E7080483B8723F26926776FF970DE95CAFA852103A01701E4844E94BAB0F21FE20B05A71362DC812F61BF2E8E27D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12093" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsAdded" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4308" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="accountUId" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <S T="1" F="accountUId" />.. </C>.. <C T="U32" I="1" O="false" N="Count_AttachmentsAdded">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):773
                        Entropy (8bit):5.014742580997559
                        Encrypted:false
                        SSDEEP:
                        MD5:346B099C53C3B576A0E97A66555E3A95
                        SHA1:2A04CE4EB63C5F114EBD54336A2AD81DFE4395D0
                        SHA-256:8E0A8C28677FE01FBB4EE2866AF447A035020B82C5FD71F6AABF6CA9947B020C
                        SHA-512:3D39077AC02633F8B68232C25D1886C1837F855215E81F593F78183356A59D276404ABF8B59FE814F1C1734F0FEB8733D2E51BAE6825D248F2A380A227A1CD0A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12095" V="1" DC="SM" EN="Office.Outlook.Desktop.MetaOS.HubBarModuleUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="74r3v" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="3">.. <F N="Action" />.. <F N="ModuleId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ModuleAction">.. <S T="3" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="ModuleId">.. <S T="3" F="ModuleId" />.. </C>.. <C T="U32" I="2" O="false" N="TotalModuleActions">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):463
                        Entropy (8bit):5.337134844095705
                        Encrypted:false
                        SSDEEP:
                        MD5:84F81CA3F68A4659886F5881FE10A92F
                        SHA1:FD641C4EC74CD451CC6ED3799D1AA92C96029732
                        SHA-256:6EC0D971422175A169B2F48EB807E068911B953B02D9029074138CABB01CCE06
                        SHA-512:B93DD56CA97F40036092127C36BFAA93DDA24D4FC91B26D55B59328CD67DC24782B5B41762273EC40F1F1F9421C6F446F63483C04F0CD8A41B40FBD4CE848010
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12096" V="0" DC="SM" EN="Office.Outlook.Desktop.NavPane.FinalWidth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="3213" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="NavPaneWidth">.. <S T="2" F="Width" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):646
                        Entropy (8bit):5.012131472761123
                        Encrypted:false
                        SSDEEP:
                        MD5:8DEFD5C67A2FB3289145501856899227
                        SHA1:FFD24D1413D85965AE0E6821A46D050797E870E5
                        SHA-256:386003B11F189E8A836036FC44C930E6C3D54EFC752FE11263DC4E9CF2FBA331
                        SHA-512:155152520F5AFE9FC92CDFFDC684E3E7F1D9DFC75A5D474BE6CF6CF6F44DC5FC0B2319CEDAB7529C55EAC2899FABA3C290A6CD8E2FCF706E754E2456C0924D71
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12097" V="0" DC="SM" EN="Office.Outlook.Desktop.NavPane.OutlookTodayVisited" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="3214" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="OutlookTodayVisited">.. <O T="GT">.. <L>.. <C>.. <S T="3" />.. </C>.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1730
                        Entropy (8bit):5.095780647559037
                        Encrypted:false
                        SSDEEP:
                        MD5:B3CD0A553B79AE4BF6B61FCD9086AC0A
                        SHA1:820CE08500C9CC52E9BECACAEC264F8F53F8F5CF
                        SHA-256:CCDD40214B0B8A229D04C8FDB6137B3063A23C905085DC0C8CB3631223BD308C
                        SHA-512:6A3775617A663B882A31AF2DB031D0B675B487B204C4A3054CCC44B86B42BD891224DD878516AFE30D89EF6AF0A1BD568915B4D19284E15C2DD4B4E9D99C2990
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12098" V="0" DC="SM" EN="Office.Outlook.Desktop.Attachments.PreviewAndOpenStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4151" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="accountUId" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <S T="1" F="accountUId" />.. </C>.. <C T="U32" I="1" O="false" N="Count_WebRefWXPPreviewed">.. <A T="SUM">.. <S T="1" F="WebRefWXPPreviewed" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="Count_WebRefNonWXPPreviewed">.. <A T="SUM">.. <S T="1" F="WebRefNonWXPPreviewed" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="Count_WebRefWXPOpened">.. <A T="SUM">.. <S T="1" F="WebRefWXPOpened" />.. </A>.. </C>.. <C T="U32" I="4" O="fals
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):686
                        Entropy (8bit):5.173806221121232
                        Encrypted:false
                        SSDEEP:
                        MD5:6F32A6B152B44E31E42B6D7B10CCA532
                        SHA1:9C96245F4B876E17B4E0A6409ABD19955A03A5CA
                        SHA-256:677BE0C553FA8C9466C5547DDAFD8F2C6B4E689A5D608E2420212F8216ABD55B
                        SHA-512:A84548904080FD09DE18F1D1F84DE53B49978AC1CF0C253883C31F390641D95865BA630D7765CA4759BE1C2D98C5E58FFCF03642631DFA4547B9C7A4E134C899
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12099" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CopyEmailAddressUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18049" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CopyEmailAddrClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3212
                        Entropy (8bit):3.9612094117927494
                        Encrypted:false
                        SSDEEP:
                        MD5:05B29ED63F39416EF0C2B8C0017E7C0B
                        SHA1:D1502805A93914935A640122A35B57073C296FE3
                        SHA-256:92B65AF5B765C30E87236821FD7EDD4ABBD8437F6CEB0FD81D978131024148F7
                        SHA-512:2BD348D94E78A67DFD19C6FBB5E897ABAF5A0BD0EED237146ED750292A0119427442897CC162A2DDCAECB7A543EC6FDF824E3734935BF5A0B9EC58C245B739F0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12100" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtLaunchEventSdxSandboxLaunchTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8252" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="SdxSandboxLaunchTime" />.. </L>.. <R>.. <V V="0" T="D" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="SdxSandboxLaunchTime" />.. </L>.. <R>.. <V V="1" T="D" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):4474
                        Entropy (8bit):3.8836796697482163
                        Encrypted:false
                        SSDEEP:
                        MD5:C91E285472E676A9360C6BBD0ADD31B5
                        SHA1:3F867CF2DA3D47D5A741206F73FBF5E88E9A0DFE
                        SHA-256:F5A4AEF7AF3A3075BABB7D0A2FFCB0F01B52A4492D3276864C3BE38B225B91D5
                        SHA-512:40C02EAA534C8E37C3B572C2B36984BFE674225E68C500DCAB9516E440BC33E782C260FAE9477AD7D02AE992794E64CAEE65DE0050DB2E66D4E09BB9C74A2142
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12101" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtLaunchEventAddInInstanceDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8252" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="AddInInstanceDuration" />.. </L>.. <R>.. <V V="0" T="D" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="AddInInstanceDuration" />.. </L>.. <R>.. <V V="180" T="D" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3282
                        Entropy (8bit):4.509322215022879
                        Encrypted:false
                        SSDEEP:
                        MD5:DC556473D3032FBF184301545F929DD8
                        SHA1:4F208F54E00984A01E2040D7B1EC19DB2A159F4C
                        SHA-256:0C5CD23D2ECA1FFB28FF2921DDB63030685B481BCCFE0FD61C2792691F11B755
                        SHA-512:8908EB81FAD1B37414F1252F6EB71A8455C368FE5B68372A8129F67C5567652F43BE933E76F9596CD2C8833D6C37B1330FED447E9375B00BB8E3502461B06C82
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="390004" V="3" DC="SM" EN="Office.Wildfire.CanvasDeprovisionedDialog" ATT="350d24c16a934c2d9734791ed7301d8e-73bafc90-ca43-424c-815a-63b076120b49-6725" SP="CriticalExperimentation" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="ckyjo" />.. <UTS T="2" Id="ckyjp" />.. <UTS T="3" Id="ckyjq" />.. <UTS T="4" Id="ckyjg" />.. <UTS T="5" Id="cu6t1" />.. <UTS T="6" Id="ckyjf" />.. <UTS T="7" Id="ckyjh" />.. <UTS T="8" Id="ckyje" />.. <UTS T="9" Id="ckyji" />.. <UTS T="10" Id="ckyjk" />.. <UTS T="11" Id="ckyjj" />.. <UTS T="12" Id="ckyjl" />.. <UTS T="13" Id="ckyjn" />.. <UTS T="14" Id="ckyjm" />.. <F T="15">.. <O T="EQ">.. <L>.. <S T="4" F="IsGateEnabled" />.. </L>.. <R>.. <V V="True" T="B" />.. </R>.. </O>.. </F>.. <F T="16">.. <O T="EQ">.. <L>.. <S T="4" F="IsGateEnabled" />.. </L>.. <R>.. <V V="Fal
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):449
                        Entropy (8bit):5.297798715342976
                        Encrypted:false
                        SSDEEP:
                        MD5:21F035AAAA21E9B919920690017E1043
                        SHA1:65BC7C9EC7481F390F84BB89D187E58C8C63119C
                        SHA-256:06D994B675B0DB4AEE7D8FD325993ACEB1546217A59D8FF86B962A90AA096109
                        SHA-512:C869874DFEA611D2C55FF752581F70B4A677DD731188585B9123FFB579772FDC955FB83E475BCB2D43DB39F6E8BF1F926C1AB86685B1CB3A7684D750D28FA322
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="390005" V="1" DC="SM" EN="Office.Wildfire.CanvasDialogResiliency" ATT="350d24c16a934c2d9734791ed7301d8e-73bafc90-ca43-424c-815a-63b076120b49-6725" SP="CriticalExperimentation" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b36lp" />.. </S>.. <C T="W" I="0" O="falseNoError" N="ResiliencyExperience">.. <S T="1" F="ExperienceLoaded" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1997
                        Entropy (8bit):4.962466047797236
                        Encrypted:false
                        SSDEEP:
                        MD5:D7DF0C81AF59C7EFFE06CEB8CD133843
                        SHA1:4BFDD306EB8FE0638E6437F44DC841B32CB55E7F
                        SHA-256:F0AD740F5DCB2AEA86AAD20083E7434AC09369DD6BBBCBC58DBC6547A4B70E7B
                        SHA-512:5B6DB178A4DFB132E55794FFBD47B9E40BDC192419DF916CA1A5910DD248C6644E598F2AE60A62E31EBCB9955EEA00ED62C29B3CA5416661B531C9B6F2828544
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="440000" V="3" DC="SM" EN="Office.Charting.ActivityUnaggregatedCharting" ATT="8984684171524f0c86ea1d654968b2c4-7399462d-cac4-4abd-abdd-d14d00d89e06-7783" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ActivityInstance" />.. </RIS>.. <S>.. <UCSS T="1" C="Charting" S="Medium" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="WasSuccessful">.. <S T="1" F="Success" />.. </C>.. <C T="I32" I="2" O="true" N="ErrorCode">.. <S T="1" F="ErrorCode" M="Ignore" />.. </C>.. <C T="W" I="3" O="false" N="LogScopeName">.. <S T="1" F="ScopeName" />.. </C>.. <C T="TAG" I="4" O="false" N="ULS_Tag">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="5" O="true" N="ParentScenarioName">.. <S T="1" F="ParentScenarioName" M="Ignore" />.. </C>.. <C T="TAG" I="6" O="true" N="ParentScenarioTag">.. <S T="1" F="ParentScenarioTag" M="Ignore" />.. </C>.. <C T="U32"
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):451
                        Entropy (8bit):5.3318799789319815
                        Encrypted:false
                        SSDEEP:
                        MD5:A59982F2C8F965DDC0E418C5F63C85CA
                        SHA1:26E421CDE611E5668CBCD38F8721E424ABCCDC7B
                        SHA-256:E76D462BFDABED81BE2E5E519B7FA50866B567A06E5B72F1AAE9AE4A1445F03E
                        SHA-512:744AF64C8DF82D6151E60678DBE90CFD522D9970C633498451FD7836D1E6A27E9148F3C41AB9DB70CCE3F3E6EAE0D8F035A58DFD152749637156D8F39027DFD0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="460008" V="0" DC="SM" EN="Office.AppCompat.AppCompat.TelemetryDashboardResiliencyCrashLog" ATT="e35e38bb2f4e4141ba082f2262aa1b83-99b9fe95-327d-4155-8e27-1fdb3db29202-7299" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cc3sg" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):418
                        Entropy (8bit):5.258553972975612
                        Encrypted:false
                        SSDEEP:
                        MD5:505819EC80245284DCA3686F2939C99B
                        SHA1:72F1A3795039A68FBCA89FE7AAF15B131C8033C4
                        SHA-256:DFE5850D46A27E0F8FCEA22F8189967DFE56333997825BEE4E9ECF633EA158DD
                        SHA-512:AFA03C10FFAFD4E26159D0EFC5636C2A6B0CE8D746B467258C4E2C75DB709705A50A35E946B8F46ED24740231894A30FF292D9C5FC8BB81A58E83891B449F73A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="460009" V="0" DC="SM" EN="Office.AppCompat.AppCompat.AgentUpload" ATT="e35e38bb2f4e4141ba082f2262aa1b83-99b9fe95-327d-4155-8e27-1fdb3db29202-7299" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="db90i" />.. </S>.. <C T="FT" I="0" O="false" N="UploadTime">.. <S T="1" F="UploadTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1094
                        Entropy (8bit):4.957729381051681
                        Encrypted:false
                        SSDEEP:
                        MD5:D92F43729F9C8FA4B66450542AAA9134
                        SHA1:AD2777B81653B872ECD56569699EC9266A80247F
                        SHA-256:BF78477A441E833D1B29FB94ED0E598C92D399FBE99C797C98988FFF1404AEBB
                        SHA-512:FC79AC40E233E8A222FF378F34204CABA7AB273E8A9CE04AFA08EAC35674C3F1DADB71D9C8701243473975D18C102EAF8406C77D86860B62FEDE222A5564A29D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490002" V="13" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.UserSelected" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl583" A="b7zlb c2gwh c2gvz c2g5u dciwy dciw5" />.. <SR T="2" R="^......">.. <S T="1" F="SurveyId" />.. </SR>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="Matched" />.. </L>.. <R>.. <V V="Banner" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="3" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyFeatureName">.. <S T="3" F="SurveyFeatureName" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="SurveyId">.. <S T="3" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="ExpirationUTC">.. <S T="3" F="ExpirationUTC" M="Ignore" />.. </C>.. <C T="W" I="4" O="true" N="Uniqu
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):644
                        Entropy (8bit):5.218650687808662
                        Encrypted:false
                        SSDEEP:
                        MD5:9C97AAFE180DA2E59CFA4AD9574BADB8
                        SHA1:82443054CBAEEE052B9DB899B2827E40DF7B04DD
                        SHA-256:184F910F87F410FA119971CFDD758937ED4ECD016F082A43542EFED4F4CA707A
                        SHA-512:920000FA2DFB1882197CF2B27FCD8EF6E46AF997709BF36FB41FF2197B9FC3FE6418C114F2D4E9A605BD8C3F7913551916CA8C6A6A7CC6457C2944FF07C3DC3F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490003" V="7" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.TriggerMet" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" T="Upload-Medium" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl59l" A="c2gyk c2g8c dciyv" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="UniqueId">.. <S T="1" F="UniqueId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):758
                        Entropy (8bit):5.232302719741035
                        Encrypted:false
                        SSDEEP:
                        MD5:A923073D09A336D7E9B2BA6D6CFA3DA4
                        SHA1:C602E0E8C118C84BC9BA9DEF0C96EC06AD70161F
                        SHA-256:7790F9DD9EFFDDDF86D0A2B397E8CFC5CED9F99932FBFD6A0B74A67A953F8C15
                        SHA-512:3CEC63578F57773DFA4720A6A6E55FCFCD75471494C603B16597002F836F0D9CDA5CF3400BEA082E1D3CF5DEB72F638297490711E28116EA4FF81018A675FC5C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490004" V="7" DC="SM" EN="Office.Feedback.Survey.UI.Win32" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl9xx" A="bl9xo bl9xq bl9xp bl9xn bp405 b14tn b14td b14tf b14te b14tk b14ta b14tb clmf2 4ogdw 4ogc3 4ogc1 4ogcz 4ogcy 4ogcx 4ogcs 4ogcp 4n2e3 4n2e1 4n2e2 4n2e4 4n2ei 4n2ef" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyID">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="SurveyType">.. <S T="1" F="SurveyType" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):694
                        Entropy (8bit):5.132471131375387
                        Encrypted:false
                        SSDEEP:
                        MD5:57643FFB80D8EE40EBE2C5BE91E6B235
                        SHA1:09FDCDFB991946255CDE5AB3E46A92D10ABB4244
                        SHA-256:EE5E9A161271F4197C8041E7FA2B71A9B2415B44EC6183FCEBC2D87E8303EC59
                        SHA-512:14942C2BFAD7849E3B757ACDC620BF2DA481C3C2B373EC52E82889763CCB2A1BBD20741579AA6C70A114F17BC4C7BAF7A9A577B78A9FBEC169D91283AF4B9A2B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490005" V="3" DC="SM" EN="Office.Feedback.Survey.UI.Win32.Toast" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bn5lz" A="bn5l3 bn5l4" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyID">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="UniqueId">.. <S T="1" F="UniqueId" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="Reason">.. <S T="1" F="Reason" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1119
                        Entropy (8bit):4.858429693642566
                        Encrypted:false
                        SSDEEP:
                        MD5:2491ED1BF43648BE1AC8590E853F2563
                        SHA1:83A35326F23D9B9B2A87E05AFC4DE517FDF9F28E
                        SHA-256:24F90B5868CBF64BC183E1415AC1AB87C3415FC032E48CCD0C68D1BC2B8F726D
                        SHA-512:09796320C85043DA1BEB4BB0B73D7C92984E2FD2D18761A3826F1D6C17B0AC589FDA224184B59091E569D64D806961583DAF0B4D2237D1F8050418ED2666DA10
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490009" V="5" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.Errors" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl595" A="bl6ab c2g3y c2g37 c2hdl c2hdu" />.. <UTS T="2" Id="b55pw" A="c2gwy c2g6s" />.. <UTS T="3" Id="b7zln" A="c2gwo c2g6i" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="4" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="JsonException">.. <S T="4" F="Json_exception" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="JsonString">.. <O T="COALESCE">.. <L>.. <S T="1" F="JsonString" M="Ignore" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="2" F="channelStateAsJson" M="Ignore" />.. </L>.. <R>.. <S T="3" F="campaignStatesAs
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1054
                        Entropy (8bit):4.999452903396452
                        Encrypted:false
                        SSDEEP:
                        MD5:7BE3F9AE585F48137DDB83D194599484
                        SHA1:571EBE7102CF4EBBA055F3D435F1C3C076BBAA53
                        SHA-256:5160189915677719B6116DE6E71D175075601A02CE46DF1693331BF326AFD257
                        SHA-512:70D30C2E5B2436470BBE14CC28CDEC416DAFA58C5C0AC3F66AF8B1645084BF2E1230462E7CE6A9BC3D67190CDA8AA57AC6E4AE64099503695F4F77506668B0EA
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490010" V="7" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.SurveyTracked" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" T="Upload-Medium" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b9q72" A="c2gya c2g72 dciyl" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="GovernedChannelType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="2" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="2" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="UniqueId">.. <S T="2" F="UniqueId" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="GovernedChannelType">.. <S T="2" F="GovernedChannelType" M="Ignore" />.. </C>.. <C T="U32" I="4" O="true" N="PrimaryPriority">.. <S T="2" F="PrimaryPriority" M="Igno
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):522
                        Entropy (8bit):5.396572860245193
                        Encrypted:false
                        SSDEEP:
                        MD5:A90F6A229417292BE4FB76D0DBAB8926
                        SHA1:F7A0C85AA1631E53C5416F050707F4A16515DD69
                        SHA-256:0AE8F35547FF32F491B050F47D82E9BC13E51DF790BD033E5517D2F485A48D3E
                        SHA-512:0AB23048DFA72450068FBAA20D1A9D570968B4F903363DE07944287372A24245E794DA13FD4283884258DC3E4EF53702244980EBEE705A8FD971345F20BF19EE
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490011" V="4" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.ForcedCooldown" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ck0tl" A="ck0to ck0tq csffj c2gv0 c2gxw c2g5v c2g7o c2gyn c2g8f dcizh dciw6 dcixz" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):750
                        Entropy (8bit):5.1660163564825154
                        Encrypted:false
                        SSDEEP:
                        MD5:3BF5A212D8030694B90DD243467D6FE7
                        SHA1:1EECDCD53F5A9CC455F633B29F9CEF7492FA39BA
                        SHA-256:9982FA668AE03EA082322A5DCF882E28DD9A61B010CAD2D7DB20F172740C75D6
                        SHA-512:2D461FCBC004D7A73FE27A62434FC915013BEE5694B6E51A1A07CD2F99E296F45733FD538F32DEBD0003B142C52625CAF0F031DD2162E13B80A70A2F1A421B1B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490014" V="2" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.FeatureFlags" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ctrxf" A="ctrxh ctrxe ctrxg 6ulqq" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="AppName">.. <S T="1" F="AppName" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="FloodgateClientLibletEnabled">.. <S T="1" F="FloodgateClientLibletEnabled" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="FloodgateEnabled">.. <S T="1" F="FloodgateEnabled" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):776
                        Entropy (8bit):5.269995983314768
                        Encrypted:false
                        SSDEEP:
                        MD5:8CEED689BB687358926991903E7789E8
                        SHA1:32EAC2BFCCE452A3A52DEBE56398B6C1960B50B2
                        SHA-256:8209248CA79CDD94C96D191810EA21D4589C5D84AB9F04DA3FC1677BEDD4084C
                        SHA-512:C562B9BE958DDC7E9ECB8BB5D39BEF05251F4E0909B901B361A96B4F48697CFD6DA31CC2EBAE3DCEEED46C9A7E6F686C44E36EDA7A32B94F6B6AF628D5CACB29
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490016" V="3" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.RoamingSuccessfulReadWrite" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cvw3m" A="cvw38 cvw3t cvw3g cvw32 cvw3w cvw3q cvw4d cvw3v c2g0w c2g1w c2g1b c2g02 c2g13 c2g1h c2g01 c2g12 c2g1g c2hal c2hbl c2ha0 c2har c2hbs c2ha6 c2haq c2hbr c2ha5" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="U64" I="1" O="true" N="Count">.. <S T="1" F="count" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="AnonymousUser">.. <S T="1" F="anonymousUser" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):600
                        Entropy (8bit):5.313452430415608
                        Encrypted:false
                        SSDEEP:
                        MD5:CDC3A978642C30851A5A42D8D0285881
                        SHA1:0657EE05D352465B6DF55A54333868BEDDE6DFBD
                        SHA-256:3E9A27CF7744D2D19D38AA6DC4AE2DF4C7221D5DDF8E6550D39B48736F46238A
                        SHA-512:F1A392A347FD03104714766A103A9E683FA9A05307A256E23B05A81A5329F2769368017EBA7A7AAF9C8A4F7E57E669FA470516EE1233C1F136625120157BDF37
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490018" V="3" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.RegisterGovernanceProvider" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="csffr" A="csffs c2g0e c2g0f c2g96 c2g97 dcizx dcizy" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="U32" I="1" O="true" N="GovernedChannelType">.. <S T="1" F="GovernedChannelType" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):792
                        Entropy (8bit):5.1585853149422425
                        Encrypted:false
                        SSDEEP:
                        MD5:2096D6903035F26A0E39296573AFF472
                        SHA1:81A8ABE47BCF91B0065C532DE2969DE8A2D95656
                        SHA-256:D63051D59777806876F9DF5A04E9803400E5BD1CFD59FDC62F63F5D7E29ACB3C
                        SHA-512:BCE6E5B8035FB697D78D28C672DD464FD94716719C5AF80A64BC8950720F48254A3E637C68D5A61829C5D29B154C5519B34C59E9E5D966CC05385B47C1AA4FB1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490020" V="3" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.GetDecisionForAction" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c4cim" A="c4ciq c4cir c4ci1 c4ci2 c4cik c4cil dcizv dcizw dciyf dciy5 dciy6 dciyd dciye dedlj dedlk dedll dek9z" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="1" F="ActionId" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="Decision">.. <S T="1" F="Decision" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="ChannelType">.. <S T="1" F="ChannelType" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):909
                        Entropy (8bit):5.0162899219761075
                        Encrypted:false
                        SSDEEP:
                        MD5:898083A0B7D94221F1F80627996A95E1
                        SHA1:BCE486A49A5C7F5FD3E0C65E8A3F3B653653A344
                        SHA-256:470A3C0DAB926791E80C33E960F51768A6E89D9EDEDD704563C5B4256C29817D
                        SHA-512:4C0B9190490001583BD131761F40770C4BE77F09175668E66D23CF30B49CD5B9976A99E8342DDC7AA157A19E17060500F72E3738E1C81EDD88AA3600A4E2F9F8
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490023" V="0" DC="SM" EN="Office.Feedback.Survey.TeachingCallout" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dbtq1" A="dbtq2 dbs37 dbs38" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="UniqueId">.. <S T="1" F="UniqueId" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="CalloutShown">.. <S T="1" F="CalloutShown" M="Ignore" />.. </C>.. <C T="U8" I="4" O="true" N="DismissalType">.. <O T="COALESCE">.. <L>.. <S T="1" F="DismissType" M="Ignore" />.. </L>.. <R>.. <S T="1" F="DismissalType" M="Ignore" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):537
                        Entropy (8bit):5.227600293961609
                        Encrypted:false
                        SSDEEP:
                        MD5:7F136FB538B26F39FA65DC1EBCE20417
                        SHA1:0B47E74F0705AF4247F2E77A5CEA7DF7C5F6B926
                        SHA-256:45DDF603194824AC9CA2BE42A5A99A494137235636DB1C99754491870A72F116
                        SHA-512:53747C15E166D2908028C3A06819635F67DDA5C55E8E42DA994F95477B9EC2E5BE1BFAC0FACAB1519F6008C1C307052EA7C9D59ABCEE2804B5FA35961AF25FA9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490024" V="0" DC="SM" EN="Office.Feedback.Survey.Floodgate.EngineStarted" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c9kah" A="dcix0" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="U64" I="1" O="true" N="FloodgateStartTimeMs">.. <S T="1" F="FloodgateStartTimeMs" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):532
                        Entropy (8bit):5.250327563895679
                        Encrypted:false
                        SSDEEP:
                        MD5:B110F12E3CEFF00FA7291475911706D2
                        SHA1:DC5B77C871FE160C16876423C5CD6BB58F59E685
                        SHA-256:F3CC44E948AB4DE371618A9A80678A261FD78495C87FC2767B6055CD722697A3
                        SHA-512:7FC0FFA107716AC88281D91ACD97E7663970BC9BFC66C19D2425D2750F4E7114EA6DF9B14E863B48A364D3582B1D01206950DC508F51DEA7F8E399C8764A694C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490025" V="0" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.GetDecisionForActionPreStart" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="947yn" A="947ym" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="1" F="ActionId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):526
                        Entropy (8bit):5.2368508517516075
                        Encrypted:false
                        SSDEEP:
                        MD5:50319BBE2DEAAD25B7BFAC6FD119700B
                        SHA1:F0DCBA9F8725416D9BE50E1D24CB13B6EB9D4E5D
                        SHA-256:29243310207196CE758FE9F849028418AE25D2C90FF879D2CF1BD0F5C8F1091D
                        SHA-512:D42741DF6AB836A5132AEE9D0E5745400F286D500CC75315573E1859982A23AAAADDB7A4B5B49E35B0300D19D38A6C7A4701187A8CDCA377E8D75CFAB211D79A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490027" V="1" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.CampaignScope" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="93uqm" A="93uql de88r de88q" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="CampaignId">.. <S T="1" F="CampaignId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):723
                        Entropy (8bit):5.183641976679839
                        Encrypted:false
                        SSDEEP:
                        MD5:0094BCD57BF7071DF56EDA89F922D4AA
                        SHA1:E678BE3348BF636354365A083D611BD17FDA7B3C
                        SHA-256:93A182F5E1A54AFC5A9E8EAF30BC84BF199AB03CF9F0AA10B6D9975F27B3FF25
                        SHA-512:07BF673AE55162975DF3D1005C19601E62CE291119286F318969A312FA537FCDD405F5FE5F1FA943F285A73FA6A241280A549C830CD22358E82E06ECBC959208
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490028" V="0" DC="SM" EN="Office.Feedback.Survey.ShowBusinessBarResult" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dfjpi" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="B" I="1" O="true" N="BusinessBarShown">.. <S T="1" F="BusinessBarShown" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="SurveyId">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="UniqueId">.. <S T="1" F="UniqueId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):432
                        Entropy (8bit):5.2768580605666076
                        Encrypted:false
                        SSDEEP:
                        MD5:D7665B2A07F867142829D88CD77EC5EB
                        SHA1:2A99EB4A093FBAB26C50E9B42C91A89C37DFE7DE
                        SHA-256:84093C3E82784CA1E801489E7EDCA00679DD5FC8A77755BDE22ABF7345B1A20B
                        SHA-512:7426547CAA0A365F4467D94B4E3A39D531B06129A1D8B2416121F882B2D0B545CA8880BCE38CBB4E0C55DF143D786BE305BD7C476D9D6D2E84FEB6D907E7D01B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490029" V="0" DC="SM" EN="Office.Feedback.Survey.FloodgateClient.ScopeCompareLatency" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" T="Upload-Medium" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="de88s" A="de88t de88u" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):715
                        Entropy (8bit):5.162562112883083
                        Encrypted:false
                        SSDEEP:
                        MD5:27659BA5C87D859CB7D8AC1BED91799D
                        SHA1:0D54B87E8F42674C633CE27B684FE67D2A58F574
                        SHA-256:E168AFE8E6E81112011922E39D36EAF8B633224B34489A979830BEEE10B96E9E
                        SHA-512:172FFAB4E260F722DEC694361711C76EF28320F6E70608EE22254A0CC521A6E899613CF8430181FD4DFA557F61F30EC2051810B5ADF162456EA1CABA9DDD7678
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490030" V="2" DC="SM" EN="Office.Feedback.Survey.UI.Win32.FormClosed" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bwehn" A="63k36 4n2e0 4n2ex" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyID">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="UniqueId">.. <S T="1" F="UniqueId" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="SurveyType">.. <S T="1" F="SurveyType" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):586
                        Entropy (8bit):5.312769094340112
                        Encrypted:false
                        SSDEEP:
                        MD5:C215B41707B89D69F9352608A43B0CCF
                        SHA1:12246E1A6DD313D7FF6C4720781C031E668C12C6
                        SHA-256:4DB9C9F15FFC10B569A088CBAF4D5286B87214F1EA4099A4846D23B10E9B7FCB
                        SHA-512:06FCD211257FC218D3496EF835B1F1B2AB278DEC60E626C94D54DE5235E024F6C9DF881A5C539E482C8B8A343844618CAE16CAB4C686F2DB48E7EAEAE5EB744A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="490031" V="0" DC="SM" EN="Office.Feedback.Survey.Deserialization.Error" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9mjrl" A="9mjrk 8pgfl 9mjqt 9mjqs 8pgfe 9mjqq 9mjqp 8pgfd 7i427 9mjqo 9mjqn 8pgfc 9mjqm 9mjql 8pgfb 86t2j 86t2i 8pgfa" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="1" F="SurveyId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):813
                        Entropy (8bit):4.312139265456619
                        Encrypted:false
                        SSDEEP:
                        MD5:97480887C909657DE2E6C26767D44658
                        SHA1:4E235FDA43B2DF293E768EF12B97575650CF0E39
                        SHA-256:ED0DCF19493A7776AC2CB31C119E7C6FE5881A857FDE57FC7D6A256C4784A3D1
                        SHA-512:BC2706C806E0E02DA762F662BE61F77A7092B5DCEEC258FEDE055777B37CF4B015F8F8BF598CF9FCD90FA8E5450888FAA1508A18C7628E8ACB76980BC4F34B56
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500000" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.FromOutSpace" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmnm" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Tcid" />.. </L>.. <R>.. <V V="27265" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ParentTcid" />.. </L>.. <R>.. <V V="19951" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):807
                        Entropy (8bit):4.291095535715688
                        Encrypted:false
                        SSDEEP:
                        MD5:CAB89818EFC86AD02F0DFC239934F550
                        SHA1:1BD2A84159C5C1CA7C79FACACE3B32ACAE3C039B
                        SHA-256:42242208505A53696C66CE210D21AEDC387BE5E18498DFA44EF2145FD6CE8A3D
                        SHA-512:D0DD59CAA213F3ACA632467A4292788EEC434B1B2CD705325C4C5A3AAF85AB67A0F98999223245A30529555DD5F2AE3B1EAFE348DEC6BDC1363B78BF300C63E2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500001" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.FromRibbon" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmnm" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Tcid" />.. </L>.. <R>.. <V V="27302" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ParentTcid" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):4.304696165971124
                        Encrypted:false
                        SSDEEP:
                        MD5:B9FE84C8034F0390B6F40B5CC51392C2
                        SHA1:8074392B8D11F6EC88587888CB6CD307B9C2069D
                        SHA-256:3BB3612B624CC8BE710752821DAB8FB8BA86F8F464C6EE74FB3D51C3CA167E12
                        SHA-512:9EBAE6EB69B391DF1CBEEAD5FBB0A4C905E367B22C9F137411E616BA972BA0B2707D6E0B83B6CC01ADB26B3256A8C49D70E481EFBF3D3F3FA944E3CDF0AA6437
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500002" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.FromTellMe" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmnm" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Tcid" />.. </L>.. <R>.. <V V="27302" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ParentTcid" />.. </L>.. <R>.. <V V="25646" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):4.30035311191936
                        Encrypted:false
                        SSDEEP:
                        MD5:BA748D3B24E6AA62D2E5EA0548922F3C
                        SHA1:EB12C2030E90DF951FFBFDD87C69BE32DCD53420
                        SHA-256:8B03F24F3FFC841B220092E7B8E075F5AD1B2D6A011538E187E7031F444D86DE
                        SHA-512:05EE44878DCD91FC2A8A20BE7AE002DFFCAFAC66767B81E17F3E75F8AF40AC96EDC614EA4B272DD42136F7B242D2D155FC595FD39CB0CB7DC8BE90CD5242F114
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500003" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.ClickSmile" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmnm" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Tcid" />.. </L>.. <R>.. <V V="24269" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ParentTcid" />.. </L>.. <R>.. <V V="19951" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):811
                        Entropy (8bit):4.309548301743047
                        Encrypted:false
                        SSDEEP:
                        MD5:5B3ABF9CB31A50B750EC880004015F44
                        SHA1:9DA439D71D21C99F2DB6E12C40C751774908D01B
                        SHA-256:41FC176144E290AF26681D8BAA60E74877FBDE804082A60421BC5A859592D55A
                        SHA-512:1A20B437010A4E17D51C2D5BFC6996A370D2F71D70E8680F05919F7A02EC95FEF38E64C074A2C45376B6AE7ADB61D551ACD8291D27BCCAF8D6F51EE7778B7F6F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500004" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.ClickFrown" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmnm" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Tcid" />.. </L>.. <R>.. <V V="24270" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ParentTcid" />.. </L>.. <R>.. <V V="19951" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):810
                        Entropy (8bit):4.300576973226168
                        Encrypted:false
                        SSDEEP:
                        MD5:1539074CD194926C3AF7BA9423AF396D
                        SHA1:DE1DA008D48814ED947076EEBE009D8027E856D9
                        SHA-256:B774418C18E4440F09B2C66D5ED38F05C9C6DF24CE2BCA0BE7E373A6A930E4EC
                        SHA-512:505FCDE6A62EEA04B80FAAF63C069C2ADC4EF6848676A58D87376A88CE713EA5E5B9414A200EFC659C14C41EC92EE7D66A40062E21E83D180E0DD11787E54039
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500005" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.ClickIdea" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmnm" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Tcid" />.. </L>.. <R>.. <V V="27268" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ParentTcid" />.. </L>.. <R>.. <V V="19951" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):514
                        Entropy (8bit):4.9706193864986
                        Encrypted:false
                        SSDEEP:
                        MD5:2D4196F9CBB111960190988622AC5632
                        SHA1:D60CDDF713D096649CDCF7FDE93FFCC31C24037C
                        SHA-256:B18A3AC161D60E4DAF865CCD9309D906E3F327D0D5EF1660E5B6979B9BD2C8AF
                        SHA-512:47DE1FB0B3BE08FBC445DF572E2ADE4722F1FFCBD02CB51737790B231A8E4A3507F798D6F6A091552DA2F22445CD604B6922EAE17B18CA62A18C2A838AD39570
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500006" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.UserVoiceRedirect" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmhr6" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="UserVoice" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):433
                        Entropy (8bit):5.308582096223094
                        Encrypted:false
                        SSDEEP:
                        MD5:340296378E172B9C30902B76B0E553A3
                        SHA1:1E86D8CD1859B4DB2B04F1EF44AD314EAD69EFDA
                        SHA-256:519EF7F45337BC950B8612AB0D9062513D294E5C5C69F4FB0172B23AA74E563B
                        SHA-512:EC3ACB3BAC67E6F42EF77D755CC34BC3DB7CC5AADECA40BB3DBAEB13F077ACAA28C435B3272A0F5BFF278355AA72F6443F31E6A9DBE3FECB9509B51DDA9D0B77
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500007" V="1" DC="SM" EN="Office.Feedback.InApp.UI.Win32.ExtendedExperience" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmc7n" A="blief blieg" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):511
                        Entropy (8bit):4.974150258924041
                        Encrypted:false
                        SSDEEP:
                        MD5:277892A14D891D1B454D249632FB58E0
                        SHA1:B11863AB56BD0E328A5DFA7192560D3576E4AB16
                        SHA-256:860876F97AF134800FE88D5F662CC9D0E3C21807D4643D7D2FB1A405AFA40878
                        SHA-512:12A540631630350A4040E65C0F57D975E6856C046C52212E244E863E6864C43B09ED91E34AEFAD7905296B3A02BD70D674694928D35E6A7B5BC1FD80BF0CA898
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500008" V="2" DC="SM" EN="Office.Feedback.InApp.UI.Win32.CancelDialog" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmc7o" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="NormalExit" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):899
                        Entropy (8bit):4.952479754079968
                        Encrypted:false
                        SSDEEP:
                        MD5:DAFF902266E22EA10C7F6414EEF82B4F
                        SHA1:F6519F5B68533490CF1BDAB813A830791BCE57BA
                        SHA-256:7DD08B3E0BD33EAE6DF6084B071FA864426C6625ACA21D8E1DA80A17D149B94C
                        SHA-512:3498A9D8A5598EA1E5538EE0921FEDB8AA4402102D0C7AABD91EBA60C5A7E919EFAD36788F944F5E17C23FDF974063841DB9DC3EC59980EDC593FD27B4586461
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500009" V="4" DC="SM" EN="Office.Feedback.InApp.FeedbackSaved" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bm22r" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="FeedbackOrSurvey" />.. </L>.. <R>.. <V V="Feedback" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="true" N="IsEmailIncluded">.. <S T="1" F="IncludeEmail" />.. </C>.. <C T="B" I="1" O="true" N="IsScreenshotIncluded">.. <S T="1" F="IncludeScreenshot" />.. </C>.. <C T="B" I="2" O="true" N="IsDiagnosticsIncluded">.. <S T="1" F="IncludeDiagnostics" />.. </C>.. <C T="W" I="3" O="true" N="ClientFeedbackId">.. <S T="1" F="ClientFeedbackId" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):600
                        Entropy (8bit):5.207482801991389
                        Encrypted:false
                        SSDEEP:
                        MD5:70A72B681FAA5A7D4CD4D2EF3589AD74
                        SHA1:809790B97BBFB93058DD157DBF2E93588121F75B
                        SHA-256:DE8BC0642B1701286F900E4A644E08B0BE3CF7DB5F7400C2CB065651A8FDABC2
                        SHA-512:07E6BDB522323AE28E8FF1BBAB1512C7F42A0729C4BA8A09BB9D967E45FF2C6965C990B5871B0907B1A92574B89B5AE803C6F8BDFAE4CDAD706BE96F883D1440
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500022" V="4" DC="SM" EN="Office.Feedback.InApp.ManifestV2" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6pmi" A="b6pmh" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="ClientFeedbackId">.. <S T="1" F="ClientFeedbackId" />.. </C>.. <C T="W" I="2" O="true" N="FeedbackOrSurvey">.. <S T="1" F="FeedbackOrSurvey" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):635
                        Entropy (8bit):5.215264669354499
                        Encrypted:false
                        SSDEEP:
                        MD5:388E2B682B728CB3A5B8B2DF100380AE
                        SHA1:3E0451649D177A601AFBCF45481153DB867A0734
                        SHA-256:C970B9FC371F3C07C1F9B9FAE88450A57E9007ADFDF3F530E5E00AA3BB2C8CA3
                        SHA-512:D0FD769CD57EC59EEF3B47358C46F83AFF2E94E8C347548BC20C56C076BD3878F674F76B2739487B3C31751DC52AAE9005C0333BA6B66AE0D3DFDA589102DC82
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500023" V="4" DC="SM" EN="Office.Feedback.InApp.PayloadSent" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bm22s" A="82pus 82puv 82puu 82put cl8f9 cl8ga cl8gb" />.. </S>.. <C T="I32" I="0" O="true" N="HttpStatusCode">.. <S T="1" F="HttpStatusCode" />.. </C>.. <C T="W" I="1" O="true" N="ClientFeedbackId">.. <S T="1" F="ClientFeedbackId" />.. </C>.. <C T="TAG" I="2" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1151
                        Entropy (8bit):5.172608606212303
                        Encrypted:false
                        SSDEEP:
                        MD5:371B0694728B35525464CCAB1D16479E
                        SHA1:BE18E7A77E1337C9B5F4F6BB0BD81FB56885F836
                        SHA-256:C3BAA4E8500C7ECA429BA97170965B54BB14DAE5B7965B51C1D621E3BB674535
                        SHA-512:F0D49CDBD4A5D8915BBDC8FCF8FC653005E3E23A2C8D6A70E43064810ACDD6801049A98AA48792A100FF1C3D13D2E108E875A03BB39ADC62FBEC728E193C0E42
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="500024" V="3" DC="SM" EN="Office.Feedback.InApp.UI.Win32.TaskPane.HostedExperience" ATT="d79e824386c4441cb8c1d4ae15690526-bd443309-5494-444a-aba9-0af9eef99f84-7360" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="clmfh" A="clmfi clmfj clmfk clmfn clmfo clmfp clmfq clmfv clmfy 4ogd9 4ogee 4ogep" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="HostedSurveyTaskPaneException">.. <S T="1" F="HostedSurveyTaskPaneException" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="FeedbackType">.. <S T="1" F="FeedbackType" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="IsEmailIncluded">.. <S T="1" F="IncludeEmail" M="Ignore" />.. </C>.. <C T="B" I="4" O="true" N="IsScreenshotIncluded">.. <S T="1" F="IncludeScreenshot" M="Ignore" />.. </C>.. <C T="B" I="5" O="true" N="IsDiagnosticsIncluded">.. <S T="1" F="IncludeDiagnostics" M="I
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):389
                        Entropy (8bit):5.27198561301701
                        Encrypted:false
                        SSDEEP:
                        MD5:76361BF2DC7CFAC34FC112F6D186D72F
                        SHA1:56C19AD2A1AE8AA34C3C894D86E0FE60C0347148
                        SHA-256:6525ABCFEF842DBFA343AE95A86C31E6F5CB26B2640E7D856C12A4FA37016253
                        SHA-512:658DC02E869C1330F30EE07330FAAD0C8DE6E59700E54FD6192F84DF81402C757A668659666EB585AC03D864DE12407F647D6136ACEE7C31082F8AB3ECB49585
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="580000" V="1" DC="SM" EN="Office.Canvas.GraphImport.HomePageCacheStatus" ATT="625e97e3f60f498b93f637a1326ca839-4fa1bdd2-bae5-44a3-8d8c-a510d37d8472-7128" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cq03l" />.. </S>.. <C T="B" I="0" O="false" N="CacheValid">.. <S T="1" F="CacheValid" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):532
                        Entropy (8bit):5.247175088835789
                        Encrypted:false
                        SSDEEP:
                        MD5:591364F1AD5C63F19977C0AFBCC495F1
                        SHA1:DC6C08E715628543C02313CCB759E1E0469B2ABD
                        SHA-256:4F59F50EB02105C0F8064691ACCE4E963BE890999ECD79A32F16332A8CE9A559
                        SHA-512:9EB191B159640F9028BD0328458831A56E4AFD2B32D3BF759BB7ED81A242EFF51B2A2286D659255008B9F01C4B4A8948CEC011373DF2BF03274A22316F063DE9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="580004" V="0" DC="SM" EN="Office.Canvas.GraphImport.TenantRootMismatch" ATT="625e97e3f60f498b93f637a1326ca839-4fa1bdd2-bae5-44a3-8d8c-a510d37d8472-7128" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cyvpr" />.. </S>.. <C T="U32" I="0" O="false" N="ServerTenantRootLength">.. <S T="1" F="ServerTenantRootLength" />.. </C>.. <C T="U32" I="1" O="false" N="EnterpriseTenantRootLength">.. <S T="1" F="EnterpriseTenantRootLength" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):941
                        Entropy (8bit):5.040773212848216
                        Encrypted:false
                        SSDEEP:
                        MD5:795E7BEC68A2C9363EAC61DC448330E6
                        SHA1:043666C2DBAB0C3B54AF0852CD6033592BD699D3
                        SHA-256:0CA2D84BF29194B1D8603D1E85391CD77A8062DB8AB4280F4D35404EE0538627
                        SHA-512:45E72A3526BDEA761FA492FE56C424E5467FDA8AFF40EB598131B67F6AF8D4216FBAEC7060D2938A67EA04EAFB01D597B4F2B444990F1B590DEC28108CDAD1D7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610003" V="1" DC="SM" EN="Office.ML.UAPEventSink.LogSIGSSignal_1" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" DL="N" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bzlg7" />.. </S>.. <C T="W" I="0" O="false" N="ActivityIdType">.. <S T="1" F="ActivityIdType" />.. </C>.. <C T="W" I="1" O="false" N="AppIdType">.. <S T="1" F="AppIdType" />.. </C>.. <C T="W" I="2" O="false" N="ClientVersion">.. <S T="1" F="ClientVersion" />.. </C>.. <C T="W" I="3" O="false" N="OfficeUserId">.. <S T="1" F="OfficeUserId" />.. </C>.. <C T="W" I="4" O="false" N="UserType">.. <S T="1" F="UserType" />.. </C>.. <C T="W" I="5" O="false" N="ClientSessionId">.. <S T="1" F="ClientSessionId" />.. </C>.. <C T="W" I="6" O="false" N="ActivityCorrelationId">.. <S T="1" F="ActivityCorrelationId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):518
                        Entropy (8bit):5.2841571096031466
                        Encrypted:false
                        SSDEEP:
                        MD5:4028984A6B5BE58EB3E75E263BCAD5BE
                        SHA1:F8D670330942FA4E8F5D3A09BA281AA553E69C53
                        SHA-256:C8C3AB6D6B8317745D6E7EE06A46B2DF4353EA07B94744B46A1226DF3B36BFA4
                        SHA-512:1CEA79E9B451F32F05135D9DF15CF0F7A36F2270E403B4A6C39F5923730CFCB1AEBE76EB9B8959C6388E61E49B073B7980E86DEDCBEDCF36E91ED3639C2B708B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610005" V="1" DC="SM" EN="Office.ML.UAPEventSink.LogHttpRequestError_1" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" SP="CriticalBusinessImpact" DL="N" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvy26" />.. </S>.. <C T="I32" I="0" O="false" N="ErrorCode">.. <S T="1" F="SH_ErrorCode" />.. </C>.. <C T="W" I="1" O="false" N="ErrorMessage">.. <S T="1" F="ErrorMessage" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):622
                        Entropy (8bit):5.2487342610014425
                        Encrypted:false
                        SSDEEP:
                        MD5:CA3E7F6A785BD68441A5E8F2E52DCE48
                        SHA1:587ABA30BA44B1A8275A7EF5179A6418C5076538
                        SHA-256:6794EBCC8526F6FBBFE8D7D693310C79B37ED695E792E383011746DE833C0D80
                        SHA-512:2CE7693D4D74D596CEC53F26402ED64D30D682CB6E80CA1A86C4C2F59AB0A8F3BDA03D01962ACEBE2661753AFE8AFAB3A4ECA87C60B7486790387CDA0290E92A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610006" V="0" DC="SM" EN="Office.ML.UAPEventSink.LogServerRequestId_0" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" SP="CriticalBusinessImpact" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b5wbt" />.. </S>.. <C T="W" I="0" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>.. <C T="W" I="1" O="false" N="ActivityCorrelationId">.. <S T="1" F="ActivityCorrelationId" />.. </C>.. <C T="W" I="2" O="false" N="EndpointRequestId">.. <S T="1" F="EndpointRequestId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):727
                        Entropy (8bit):5.229279422935573
                        Encrypted:false
                        SSDEEP:
                        MD5:0A1B69E4A7FF174B9458FAF70226CBD2
                        SHA1:CDFB2724199BC8E7B57C2E9C8B2FAD0E1ECB0094
                        SHA-256:D4E21EDC71E6F0652403604A6C6CF07C04CDE6E1997CC0944A1AEC6CFC855313
                        SHA-512:9DB8E4888E8D3B4AF077FD549B57A836FA4AB372016E64C4CFE48D52F85D7BFCDE7790CF7FAEA110663E03277D28964B7D12E12881DBCB46A5469EB726AD321F
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610007" V="0" DC="SM" EN="Office.ML.UAPEventSink.LogWebServiceAPIOnSuccess_0" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" SP="CriticalBusinessImpact" DL="N" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6e1o" />.. </S>.. <C T="W" I="0" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>.. <C T="W" I="1" O="false" N="ActivityCorrelationId">.. <S T="1" F="ActivityCorrelationId" />.. </C>.. <C T="W" I="2" O="false" N="EndpointRequestId">.. <S T="1" F="EndpointRequestId" />.. </C>.. <C T="I64" I="3" O="false" N="NetworkLatency">.. <S T="1" F="NetworkLatency" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1233
                        Entropy (8bit):5.029355756673044
                        Encrypted:false
                        SSDEEP:
                        MD5:31CEAC17226E587303E7E8BB54A5A5AD
                        SHA1:AB195A9C6B3EBBFC09A4C0F1EC20113AD75FEA9E
                        SHA-256:8C7CD04268412C207FFB9C810D725CB346B362F9079B4F69AC210C5E7082ABA1
                        SHA-512:828C9B176FADD2CF2A104700F2C7B4BF9267F000B8B5043350B7331EAAEE42CAE6524E00C9A4F7F3748912D6A4EE4A5ADB87861BA4C43182549935F7E3DF757A
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610008" V="1" DC="SM" EN="Office.ML.UAPEventSink.LogWebServiceAPIOnError_1" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" SP="CriticalBusinessImpact" DL="N" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6e1p" />.. </S>.. <C T="W" I="0" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>.. <C T="W" I="1" O="false" N="ActivityCorrelationId">.. <S T="1" F="ActivityCorrelationId" />.. </C>.. <C T="W" I="2" O="true" N="EndpointRequestId">.. <S T="1" F="EndpointRequestId" />.. </C>.. <C T="I64" I="3" O="true" N="NetworkLatency">.. <S T="1" F="NetworkLatency" />.. </C>.. <C T="I32" I="4" O="true" N="ServiceStatus">.. <S T="1" F="ServiceStatus" />.. </C>.. <C T="I32" I="5" O="true" N="ErrorInfo">.. <S T="1" F="ErrorInfo" />.. </C>.. <C T="W" I="6" O="true" N="DiagnosisHeader">.. <S T="1" F="DiagnosisHeader" />.. </C>.. <C T="W" I="7" O="true" N="Diagnostics">..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):625
                        Entropy (8bit):5.235323832389742
                        Encrypted:false
                        SSDEEP:
                        MD5:A417B35863929A09C3B0A1AB653A6C4D
                        SHA1:D4DCC2CE8C26E0842F4FE60687A63BF9EFEDF99C
                        SHA-256:DABDB93531B3FF8D42F1AAF50E67E7735C348DCC5EE8D8479984D4F0BC6B9CAF
                        SHA-512:D98ECB785554A1363865951DFA8BAC56031638A856D9EDC740C5D59B149DD10F7245389101816347EE90EDB016053F2CE61E2F8C121C6D878652B2ABD37920F1
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610009" V="0" DC="SM" EN="Office.ML.UAPEventSink.LogWebServiceAPIFailure_0" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" SP="CriticalBusinessImpact" DL="N" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6e1q" />.. </S>.. <C T="I32" I="0" O="false" N="ServiceStatus">.. <S T="1" F="ServiceStatus" />.. </C>.. <C T="W" I="1" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>.. <C T="W" I="2" O="false" N="ActivityCorrelationId">.. <S T="1" F="ActivityCorrelationId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):626
                        Entropy (8bit):5.227013986666996
                        Encrypted:false
                        SSDEEP:
                        MD5:9E5834347B1D65C3F8AD7881714E3011
                        SHA1:4AE705B3159DC29CE71057716D74127275062A21
                        SHA-256:757FF557F26AB9A42DC1863BB17B0F23019B8C933BBAF55FCE5D5371215306FD
                        SHA-512:25B8904BF92173A37077A5BCD762FAE6B2F074DE911B2FBFFFD32B328098B4A45B282E11A0E1B0E4EFE7A2B9663A88BF2AD52CA325B0BA92A936CAC60EC7D8FD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="610010" V="0" DC="SM" EN="Office.ML.UAPEventSink.LogWebServiceAPIMissingField_0" ATT="655fe2f4f8414e4db3f881ce2bb96fc8-7a0f06e8-b403-4b25-afd7-a54cc7fda27b-7855" SP="CriticalBusinessImpact" DL="N" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6e1r" />.. </S>.. <C T="W" I="0" O="false" N="MissingField">.. <S T="1" F="MissingField" />.. </C>.. <C T="W" I="1" O="false" N="Endpoint">.. <S T="1" F="Endpoint" />.. </C>.. <C T="W" I="2" O="false" N="ActivityCorrelationId">.. <S T="1" F="ActivityCorrelationId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1151
                        Entropy (8bit):4.714131828094441
                        Encrypted:false
                        SSDEEP:
                        MD5:3145D9D851BBFA4F7C0DCC0A4E5EA751
                        SHA1:42B25D1941C414EF57502F7E2CF128184B3DA9FB
                        SHA-256:7ED3AF3A4CF89B61C8890E72E6DB81C3217C1C49791CF167DADCA42A4AC80244
                        SHA-512:C8D9FDD401429AB1414FAAE1776520AEF8779668DBA08C131F3AD554DBB0B163C61DA8B62528B632AD6D09942E75F6E82687B724834F008DCE1A5C47373A88CC
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63028" V="4" DC="SM" EN="Office.Identity.IdentityWarningsAggregation" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" DCa="PSP PSU" xmlns="">.. <S>.. <R T="1" R="63052" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetrySuspend" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="EndTime">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="W" I="1" O="false" N="Category">.. <S T="1" F="1" />.. </C>.. <C T="W" I="2" O="false" N="Tag">.. <S T="1" F="2" />.. </C>.. <C T="U32" I="3" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="FT" I="4" O="false" N="FirstTimeStamp">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="I32" I="5" O="true" N="ErrorId">.. <S T="1" F="3" />.. </
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1006
                        Entropy (8bit):4.75723033832876
                        Encrypted:false
                        SSDEEP:
                        MD5:57990533B82D23EF9FB4D0EDC5CC3AD5
                        SHA1:4D46DBBDFA1439D1B2983BE4EA1C26330BEA5EA7
                        SHA-256:97B698AB9B9FD2E3155D25191843159ABE8F66093D9CE22BEBDABE5E2959816D
                        SHA-512:FD3FD0C82F1BC693AF10629A39EEB985E23FAC6D488F2AACF242957F1AA48D9164CF9D9276DB0255B2A9D52737E4085B48584F310323E4C7D0A6304D3AF4BFF4
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63030" V="2" DC="SM" EN="Office.Identity.Identity.Sign.In16.Prompt" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="ax0z1" />.. <UTS T="2" Id="aysqq" />.. <UTS T="3" Id="aysrq" />.. <UTS T="4" Id="azfp5" />.. <UTS T="5" Id="a4dam" />.. <UTS T="6" Id="a4dao" />.. <UTS T="7" Id="a4dan" />.. <UTS T="8" Id="a4dap" />.. <UTS T="9" Id="aysr0" />.. <US T="10">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. <S T="7" />.. <S T="8" />.. <S T="9" />.. </US>.. </S>.. <C T="FT" I="0" O="false" N="Timestamp">.. <S T="10" F="TimeStamp100ns" />.. </C>.. <C T="TAG" I="1" O="false" N="EventId">.. <S T="10" F="ULS_Tag" />.. </C>.. <C T="W" I="2" O="true" N="HrdAuthScheme">.. <S T="1" F="IdentityProvider" />.. </C>.. <T>.. <S T="10" />.. </T>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):927
                        Entropy (8bit):4.653908788373925
                        Encrypted:false
                        SSDEEP:
                        MD5:F5CBD2AAAB08F1A9983AE55EE25F0D75
                        SHA1:FD5E836B42D7C5E1F0A12E28A19394D248C682FF
                        SHA-256:FB5465ED4686D2C02E2C0EC7B11DFD53C8D0074CF474D7A45F84ABD696F1D640
                        SHA-512:0F54900FFACB566775B7F10AEC548E19DEA9187C65605806DF11C653C032F9B823BE0E0FFCEB2AB66B6132B75870B1DA0860A470E121B215D66B08540C04A4C7
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63038" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <UCSS T="1" C="Identity OAuth2" S="Unexpected Monitorable Medium" />.. <UCSS T="2" C="Identity Third Party" S="Unexpected Monitorable Medium" />.. <UTS T="3" Id="baud9" />.. <UTS T="4" Id="a8s0f" />.. <UTS T="5" Id="a9a34" />.. <UTS T="6" Id="a6o7p" />.. <UTS T="7" Id="bbgck" />.. <US T="8">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. <S T="7" />.. </US>.. </S>.. <C T="FT" I="0" O="false">.. <S T="8" F="TimeStamp100ns" />.. </C>.. <C T="TAG" I="1" O="false">.. <S T="8" F="ULS_Tag" />.. </C>.. <C T="U32" I="2" O="falseNoError">.. <S T="8" F="ErrorBucket" M="Ignore" />.. </C>.. <C T="I64" I="3" O="falseNoError">.. <S T="8" F="ErrorCode" M="Ignore" />.. </C>.. <T>.. <S T="8" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):934
                        Entropy (8bit):3.996991224242757
                        Encrypted:false
                        SSDEEP:
                        MD5:D065C6DBC87E17EFD2A62E28337632E0
                        SHA1:57D91DB0D19404B832FC2396B98A1B1D281F5D04
                        SHA-256:C432814E76B5EFE46278A15CD50DCEE75480A28B4E38D9046181A7314CE2D280
                        SHA-512:A0CC0B0ED74F6515C1299E26EB111956845BBECD3ED336F70762834638244A259ED8620A076DA66574473F164002D3FD042365555FF98C595553F7CB5AE1340E
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63040" V="2" DC="SM" T="Subrule" DCa="DC" xmlns="">.. <S>.. <R T="1" R="63042" />.. <R T="2" R="63040" />.. </S>.. <G>.. <S T="1">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="2">.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. </G>.. <C T="FT" I="0" O="false">.. <S T="1" F="0" />.. </C>.. <C T="TAG" I="1" O="false">.. <S T="1" F="1" />.. </C>.. <C T="W" I="2" O="true">.. <S T="1" F="2" />.. </C>.. <C T="U64" I="3" O="false">.. <O T="COALESCE">.. <L>.. <O T="ADD">.. <L>.. <S T="2" F="3" />.. </L>.. <R>.. <V V="1" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <V V="1" T="U64" />.. </R>.. </O>.. </C>.. <C T="W" I="4" O="true">.. <S T="1" F="3" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1481
                        Entropy (8bit):4.315384231229811
                        Encrypted:false
                        SSDEEP:
                        MD5:30D4408E96A15926287644B2E5CA8EBD
                        SHA1:E08BE25D468586F804354A9EF6E31DC4AB930948
                        SHA-256:9EDC3B6847D5CDA98635726EAAECBBDBD8D2297D6B1C3FBE97F8A94267AC12A9
                        SHA-512:9BFAF553146897A850ADC3C1576C0AD897329F3C141AD91F2A05B5F8469D24CBE5B9B5E3C97F89C524BD9C6F5D9D9DDFB076A6D3FE1F7D11A22E587EB33BA404
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63041" V="2" DC="SM" EN="Office.Identity.GetAuthenticatedServiceTicketCadence" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="63040" />.. <R T="2" R="63041" />.. <R T="3" R="120100" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="3" />.. </L>.. <R>.. <V V="1" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="2">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="Timestamp">.. <O T="COALESCE">.. <L>.. <S T="3" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="4" F="0" />.. </R>.. </O>.. </C>.. <C T="TAG" I="1" O="false" N="Tag">.. <O T="COALESCE">.. <L>.. <S T="4" F="1" />.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):670
                        Entropy (8bit):4.785986914937611
                        Encrypted:false
                        SSDEEP:
                        MD5:121B42603FA4FA67C0A0816AA83E7245
                        SHA1:5B3EC40B7FA93D1810E127BF3E3F93D8F7105827
                        SHA-256:D7D3317FABD46CE829ED191B4C92E8A7D8E89F21A68FAA0F5A7632D0D07C86D6
                        SHA-512:05C5A167BA7E02A679309B8619F3731F36A4D5BF6834B5487F36E8BD48BA0994EE4B616594655E014900FD6567B19C25A78FF6FB774427A17BD5678A6EB46B80
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63042" V="3" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="awutb" A="awuxw bbvox bb9d3 bb9ed bb9ee" />.. <UTS T="2" Id="bb9d5" A="bb9d4 bhgns awuv5" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. </S>.. <C T="FT" I="0" O="false">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="TAG" I="1" O="false">.. <S T="3" F="ULS_Tag" />.. </C>.. <C T="W" I="2" O="true">.. <S T="3" F="IdentityMetadata_IdentityProviderType" M="Ignore" />.. </C>.. <C T="W" I="3" O="true">.. <S T="3" F="IdentityMetadata_LibraryType" M="Ignore" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1616
                        Entropy (8bit):4.71516383376384
                        Encrypted:false
                        SSDEEP:
                        MD5:F596D1DC61FFB503CA5181CBF5B11555
                        SHA1:4908C8C9042BF64FB3E440D1645475706F9A3067
                        SHA-256:6D741F5EDADD38BB4D471A50B920CF11CDB89F6F4E61C93830FF9886E7C4CA01
                        SHA-512:BBF75E0D1BCD98B4ECEA98C6733ED8DCD6C4B6FF93A1AA615230617552A745FBE225101DD005D5219C95C229B298341C5E9958F193BA441C4FFF0107DC53E57D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63046" V="10" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="bb9ef" A="azusw a18zb ax73j awuxy awupo bex9n awuxx azusx bb9eg awupn bb0g8 a99q0 bqo4s bdvux bdvuy awutc bdvuz awutd bdvu0 bdvu1 bjljc bjljd bjlje bjljf" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="TAG" I="1" O="false">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="2" O="true">.. <S T="1" F="Target" M="Ignore" />.. </C>.. <C T="W" I="3" O="true">.. <S T="1" F="Policy" M="Ignore" />.. </C>.. <C T="W" I="4" O="true">.. <S T="1" F="IdentityMetadata_IdentityProviderType" M="Ignore" />.. </C>.. <C T="W" I="5" O="true">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="1" F="IdentityMetadata_IdentityErrorState" M="Ignore" />.. </L>.. <R>.. <S T="1" F="ErrorState" M="Ignore" />.. </R>.. </O>.. </L>.. <R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):3787
                        Entropy (8bit):4.4616521769015565
                        Encrypted:false
                        SSDEEP:
                        MD5:5D3F05C08B281744750899694A2B272D
                        SHA1:2332176BEBA4313BE04E99387E9079F08A251D00
                        SHA-256:D76F935F529603AD6948760BF052541CC36345D0FE1F8704ADC877ED325CFF60
                        SHA-512:A542C5C2448E13E5442FA96071C1289F938E93F402FD403B2F13716D85F40E3CED9456DF687A40A054C1F31696D4ECA3F38EC259335EB3DF65541CCD5006F33C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63048" V="6" DC="SM" EN="Office.Identity.MsaSso" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bch1w" />.. <UTS T="2" Id="a3qpl" />.. <UTS T="3" Id="a3qpk" />.. <UTS T="4" Id="a3qpj" />.. <UTS T="5" Id="a3qpu" A="a3qpn" />.. <UTS T="6" Id="a3qpv" A="a3qpo" />.. <UTS T="7" Id="bch10" A="bd692" />.. <UTS T="8" Id="bch1x" />.. <UTS T="9" Id="bch1t" A="befh4 befh7" />.. <UTS T="10" Id="bch1z" />.. <A T="11" E="TelemetryShutdown" />.. <TO T="12" I="10min">.. <S T="1" />.. </TO>.. </S>.. <C T="B" I="0" O="false" N="OfficeIdentity_EqualTo_OidaIdentity">.. <O T="NE">.. <L>.. <C>.. <S T="2" />.. </C>.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false" N="BadOfficeIdentity_EqualTo_OidaIdentity">.. <O T="NE">.. <L>.. <C>.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1251
                        Entropy (8bit):4.702490763905221
                        Encrypted:false
                        SSDEEP:
                        MD5:94786F217AF30A964E78EE13ADD15779
                        SHA1:7EAD20ABC144AACC5E780C7E2778625B7B172120
                        SHA-256:5B13815B6B374BB2046B0E1DF81D276B9D6DAB24A3C5EE015E3C23685F4F033D
                        SHA-512:FEAB41F4B72C5A41FC581A33D13F5FE7CED666579AFEC8410F531F0EEE6E3BFD5F5C286B0FC7655D5776AA4343C376D917F63433E83AA7A575D3C57E52E73865
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63049" V="2" DC="SM" EN="Office.Identity.IdentityExceptionAggregation" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" DCa="PSP PSU" xmlns="">.. <S>.. <R T="1" R="63053" />.. <TI T="2" I="30s" />.. <A T="3" E="TelemetrySuspend" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. <F N="5" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="StartTime">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="FT" I="1" O="false" N="EndTime">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="TAG" I="2" O="false" N="Tag">.. <S T="1" F="1" />.. </C>.. <C T="U32" I="3" O="false" N="LoggingCategory">.. <S T="1" F="2" />.. </C>.. <C T="TAG" I="4" O="true" N="ExceptionTag">.. <S T="1" F="3" />.. </C>.. <C T="U32" I="5" O="false" N="Type">.. <S T="1" F="4" /
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1605
                        Entropy (8bit):4.891709249185111
                        Encrypted:false
                        SSDEEP:
                        MD5:5E71C951E0742553F6CA814BD504DEC9
                        SHA1:1EA52D66B91F903FF4CD4CB9C663F0819F8D43C1
                        SHA-256:77FEBBA76653660D10D002F38BDC83B9E09C0DCEED07F71DA975AAF96E887E9B
                        SHA-512:88B29CCB5E1F89F86504E623FDD30002C3ABF4BDAD62193BF3C27E0361BA6240C5D8C91052695A83D36237144CBF61DA4A904F72D5C50F7E69A5846F42074BCD
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63051" V="5" DC="SM" EN="Office.Identity.IdentityAuthHistoryPassthrough" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="befh4" A="befh7" />.. <UTS T="2" Id="befh8" />.. <UTS T="3" Id="befhk" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. <US T="5">.. <S T="1" />.. <S T="2" />.. </US>.. </S>.. <C T="U64" I="0" O="false" N="LastLoginDelta">.. <S T="4" F="LastLoginDelta" />.. </C>.. <C T="W" I="1" O="false" N="ErrorState">.. <O T="COALESCE">.. <L>.. <S T="5" F="PreviousIdentityMetadata_IdentityErrorState" />.. </L>.. <R>.. <S T="3" F="ErrorState" />.. </R>.. </O>.. </C>.. <C T="W" I="2" O="true" N="ProviderType">.. <S T="5" F="PreviousIdentityMetadata_IdentityProviderType" />.. </C>.. <C T="B" I="3" O="true" N="IsPersisted">.. <S T="5" F="P
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):2757
                        Entropy (8bit):4.676950301726056
                        Encrypted:false
                        SSDEEP:
                        MD5:557F022390A055F50407978A892DAEEE
                        SHA1:9BC1F40138F32CF3FFAB4ACCECF72A68C9DA5516
                        SHA-256:8813A1F67BEBF5E7110DA35C31217E37D5DE71C94DC146F7E9F859B32AB286F5
                        SHA-512:678D77842112386808C4F0A7433DC056A00102FCB7D40589126BEED21995B360BF46FA68670DB0320357BF7D94FE0FC4EFE5DDE75976E84F7105ACC35A9EEF20
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63052" V="3" DC="SM" T="Subrule" xmlns="">.. <S>.. <UCSS T="1" C="ADAL Authentication" S="Monitorable" />.. <UCSS T="2" C="Identity Accounts Control" S="Monitorable" />.. <UCSS T="3" C="IdentityADALClient" S="Monitorable" />.. <UCSS T="4" C="IdentityADALClientCritical" S="Monitorable" />.. <UCSS T="5" C="Identity Authentication Client" S="Monitorable" />.. <UCSS T="6" C="Identity Authentication Client Critical" S="Monitorable" />.. <UCSS T="7" C="IdentityAuthenticationCredStore" S="Monitorable" />.. <UCSS T="8" C="Identity Authentication CredSync" S="Monitorable" />.. <UCSS T="9" C="Identity Authentication CredUtil" S="Monitorable" />.. <UCSS T="10" C="IdentityConnectedAccount" S="Monitorable" />.. <UCSS T="11" C="IdentityConnectedAccountCritical" S="Monitorable" />.. <UCSS T="12" C="Identity Credentials Client" S="Monitorable" />.. <UCSS T="13" C="Identity Critical Error" S="Monitorable" />.. <UC
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):646
                        Entropy (8bit):4.704780431425281
                        Encrypted:false
                        SSDEEP:
                        MD5:42C6398BD816D57918051FFC5E57801C
                        SHA1:9F181C67430453CDF26231C1A4CBD13C6FA25BAD
                        SHA-256:3353B2E43B1475100DBF61F5905932415845C075207AF45FE7679145322BB092
                        SHA-512:EF134DC1192613243EFA14753F06128B9AEB94827EEC4053A3DA2015B2DAE3821A7325CFB63BD6B56D95F7E80EDDFD448993A72F823B3D316E599C4FDB243057
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63053" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <UCSS T="1" C="Identity Exception" S="Monitorable Unexpected" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="TAG" I="1" O="false">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="U32" I="2" O="false">.. <S T="1" F="LoggingCategory" />.. </C>.. <C T="TAG" I="3" O="true">.. <S T="1" F="ExceptionTag" M="Ignore" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="1" F="Type" />.. </C>.. <C T="U64" I="5" O="false">.. <S T="1" F="Error" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):616
                        Entropy (8bit):5.204052822096694
                        Encrypted:false
                        SSDEEP:
                        MD5:F98A9C6727DB647FD7043A3FF1087B49
                        SHA1:F8252553C722F81B8796A28ADB94293AA3282E14
                        SHA-256:58399B5B967AFCDBA716DCC89838A7050B51571EEC84F71A35765B6E00B5B9D1
                        SHA-512:FD1B8F3AEF2767843AD8A6B0795F82CE8AB29DB80D599C07A69797A38F13BFC7C98C39124782D7A590360829BC770B254A4D1A89A72B350AA1D1E8E1163684C2
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="63059" V="0" DC="SM" EN="Office.Identity.IdentityCountOnShutdown" ATT="5c65bbc4edbf480d9637ace04d62bd98-12844893-8ab9-4dde-b850-5612cb12e0f2-7822" SP="CriticalBusinessImpact" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bj46m" A="bj46k" />.. </S>.. <C T="TAG" I="0" O="false" N="Tag">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="U64" I="1" O="false" N="ValidIdentityCount">.. <S T="1" F="ValidIdentityCount" />.. </C>.. <C T="U64" I="2" O="false" N="AllIdentityCount">.. <S T="1" F="AllIdentityCount" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):0.04616353740967531
                        Encrypted:false
                        SSDEEP:
                        MD5:839B9365C9A94F229F96B737CEDA3F2F
                        SHA1:F6C0E3DC8DEA9D5A08FB452474CB430A9593702E
                        SHA-256:881B548A1DE778E7022201F0D1E1CA4C2390AD69AECB7AF37EED4EA89D8EAC51
                        SHA-512:F729568AC83FE63286DE7AE0836D0C87F0F3FED5D33B8139A1B0494438D0B4A0FF39219E804EB827D01CFDE69D6D348B5345C395E6C616A636D2A592FCADC432
                        Malicious:false
                        Reputation:unknown
                        Preview:..-......................P.G3......L9.k.%..N.K...-......................P.G3......L9.k.%..N.K.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:SQLite Write-Ahead Log, version 3007000
                        Category:modified
                        Size (bytes):49472
                        Entropy (8bit):0.4846682009783279
                        Encrypted:false
                        SSDEEP:
                        MD5:6E6FF1ED9D9F38F5AEC9EDFCDD09BC16
                        SHA1:2F7A2C2FA6749A44177F389ADA164D0AB496B60B
                        SHA-256:82A50091927E831B536586C7400097198EC83070DF30FA58DDE7259A942D4AAF
                        SHA-512:1AA1242BE58180441E122751AE1E639BD21090FC16C017CAF8FC373CC4FA2BAA8C6AFEB95A987D39E168A1F36B9A7697E514A42F2EF1C319D655FF1190979E16
                        Malicious:false
                        Reputation:unknown
                        Preview:7....-..............L9.k..................L9.k....84KSQLite format 3......@ .......................................................................... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):422
                        Entropy (8bit):5.324913317979872
                        Encrypted:false
                        SSDEEP:
                        MD5:554108A20E410C7CD1C5F36036146887
                        SHA1:6C865CB3A2B51A3EF44235986B25DD541563BACE
                        SHA-256:22AA981F10E839FBF2C5C3A8F3DE7CAA2F9C3ADD7AF4750420FD2B1A05BE1709
                        SHA-512:1E9D8D6B3D184DAAAE2F9A23AEFE60F8D235DDC624034722E1E5CD982985B8F24B03A39BFA754E6E9504DEDB735E79FEEE1BB0771556287532FCC8AB98281F9C
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piAvailGCShowPopup" v="3-True"/>....<e k="18-piFBUserPublishRange" v="9-2"/>....<e k="18-piAvailMtgShowPopup" v="3-True"/>....<e k="18-piAvailGCTextInGrid" v="3-True"/>....<e k="18-piFBUpdateSecs" v="9-900"/>....<e k="18-piAvailMtgTextInGrid" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):588
                        Entropy (8bit):5.274088444013153
                        Encrypted:false
                        SSDEEP:
                        MD5:6C0F34E0E60EA920F15392125A677A44
                        SHA1:EBCC7F57183FBC215D1882946C7BE89B7B9C87D1
                        SHA-256:081F41506BFC3016709C83D6E388F16C5EE76BADEAA60B2E2B0600F39380E442
                        SHA-512:142CCA2E66A8E557953D1CD248264FF6F34F5A6838C33C910A24604F253C776DE3EB358056EB114E7A11CCFFD39AF90589AC61D632B349874634BF11174FFE99
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piAutoProcess" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>....<e k="18-piRemindDefault" v="9-15"/>....<e k="18-piGroupCalendarShowMyDepartment" v="3-True"/>....<e k="18-piAutoDeleteReceipts" v="3-False"/>....<e k="18-piGroupCalendarShowDirectReports" v="3-True"/>....<e k="18-piGroupCalendarShowCoworkers" v="3-True"/>....<e k="18-piReminderUpgradeTime" v="9-222883601"/>....<e k="18-piShowFreeItems" v="9-0"/>....<e k="18-piShowWorkHourOnly" v="9-1"/>...</Data>..</UserConfiguration>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):207
                        Entropy (8bit):5.155214717558196
                        Encrypted:false
                        SSDEEP:
                        MD5:8BD87194AD4E92165AD51FEB25271160
                        SHA1:587DF434E982C396712F805F46C8DA66CEACD0E3
                        SHA-256:6C1B1E6B7A1F5A9499A3F7C66939B933D89EFD7BFF818255F57CD182C7474650
                        SHA-512:37F5689974333F744FD94D243D5CA5DD680DF4CF44E0072B293ED42BFA602C01157DBE3668CFD8287950675AB05621710C06D5798C51CB2D68570CE40183F7C0
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piImportedContactNickNames" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):267
                        Entropy (8bit):5.160869873037959
                        Encrypted:false
                        SSDEEP:
                        MD5:F351722FC2FCF3A1585D2A4FCD3174F9
                        SHA1:7107F9791498794416A472633D25F760FF62921C
                        SHA-256:0A4D7E4860AFAC36C43F2E5272678B7E267B46618AB46A596DD28DBC4C5915E3
                        SHA-512:EEF511A0E8C17D8DC6DB00BFBB46AE55E5F9257D9EA4B9ED1FCA1E0C4BD2EC7F96D859C76D67E8B2DF72E9336693337BBCC269C929CFC3AD2D4AD04DA08B355B
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piConversationsOnInAllFoldersChangeNumber" v="9-1"/>....<e k="18-piUpgradeToConversations" v="9-2"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):196
                        Entropy (8bit):5.121404985534659
                        Encrypted:false
                        SSDEEP:
                        MD5:18DD6E6C7E001E6EB529C89CB34A0035
                        SHA1:936B54A457C3C556F9450B145FE8C2C37E39EDB2
                        SHA-256:DFBDE381FDE1A284C81A72D06A1A43FAF49CD1C085C87234E34E50B881567806
                        SHA-512:05B58C78D721E3D30815D964F997AF0B768D63F061AB1A4881E38C6FEBA89DF630828B5AE9AA54B8CF6C6124B773ADAE682BACD655B043C60F6C4F4A9058891D
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piRuleOnAllRss" v="3-False"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):204
                        Entropy (8bit):5.146779630782915
                        Encrypted:false
                        SSDEEP:
                        MD5:A4DA275C13ACAA46CEB0D2158220CA0B
                        SHA1:9933ED454356A170E1CB3DB18ED7CB2895FDE004
                        SHA-256:3F476C44779AE7EAE8BF64111B9D90E7A24D43B88A9E62507956A534C997C467
                        SHA-512:69083E5BFCB09043044807452C78D680D5440D6E80F9311284518E15FBA7D7D8A71FD6DF18DFD8C479C27C8C80A8E73822D3D41BA2E0DC4DBFEF7AF4090A3CF9
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piGroupExpandAnimations" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):715
                        Entropy (8bit):4.935923051709176
                        Encrypted:false
                        SSDEEP:
                        MD5:9CA1DA1D62A9FF574E63B8946B541C96
                        SHA1:E9821F6D0A8F829D23E3A95F45D488D6BCB391F7
                        SHA-256:B6B10A07FAA634027F3780E77FC3B165DCF7D37E800195BFF5E147CCC492B828
                        SHA-512:B01B74A08FB9D5056AEF3FD780FF1AE4F06784BC8094AB49F0583D1DA1B040CFE765F15C5E0A9DE0C6C1A1E149ECD3EA597CAEB9A221176DF491C02F7F361A85
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0"?>..<Root xmlns="WorkingHours.xsd">...<WorkHoursVersion1>....<TimeZone>.....<Bias>300</Bias>.....<Standard>......<Bias>0</Bias>......<ChangeDate>.......<Time>02:00:00</Time>.......<Date>0000/11/01</Date>.......<DayOfWeek>0</DayOfWeek>......</ChangeDate>.....</Standard>.....<DaylightSavings>......<Bias>-60</Bias>......<ChangeDate>.......<Time>02:00:00</Time>.......<Date>0000/03/02</Date>.......<DayOfWeek>0</DayOfWeek>......</ChangeDate>.....</DaylightSavings>.....<Name>Eastern Standard Time</Name>....</TimeZone>....<TimeSlot>.....<Start>08:00:00</Start>.....<End>17:00:00</End>....</TimeSlot>....<WorkDays>Monday Tuesday Wednesday Thursday Friday</WorkDays>...</WorkHoursVersion1>..</Root>..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:PNG image data, 607 x 1714, 8-bit/color RGBA, non-interlaced
                        Category:dropped
                        Size (bytes):779819
                        Entropy (8bit):7.9907322716274924
                        Encrypted:true
                        SSDEEP:
                        MD5:C8A0A19F9A55D082EE7EB9AA53EA6E4A
                        SHA1:BB1C461DEF6D9FC710181ED9E64CB2C2CD916EB1
                        SHA-256:4DAB7B43671080F73A8AC303E3126CB63AF63690768893EE777CF405F3D632A8
                        SHA-512:B8D5BB1656F959B0CE625551AC98645C7E05932A47BD1AB6F14306B032FAC2A1F8B7F28882ADEE03C56E0003DD7D7E1CB89AEBA542578AE82225C8353A1E1F2F
                        Malicious:false
                        Reputation:unknown
                        Preview:.PNG........IHDR..._..........*.R.. .IDATx^.].......AA@D..v.&.^b....k.Qc....b..1..b.4b.(`A...2.?....1Y.W.z.lfv.+.;..y.{.=70....x.x<..j...C..0...C..0.~%..X.p...._...n.....!`...... `...!`.....!`......v..Ne.....!`....../....!`.....!`..#.F...l;.!`.....!`...F.l....@.E ..J ..>.?.......^....0....F...m..0.z..?F.....)!S2.sQ.+7....D..WG.o.6..._......LF.....aI.R...P.E....._...l......#_..D;.!`.t..~...I....$_$^$]|MB....._vVC...!`..f.!`.tI...^......i.......'...X..h..!`.t...|u..h.a.t..~.l).....z.GI....(..!........@gC..Wg.#6.C..X$.Z.p...b$..D"..X....."Al......B.......k...mC......U\./5..x<^..`...*)k..l/C..0....F....v.C..X.....b....y*.....rUWW..../k........\.."_..f.!..C.....j3t..!`.,.....\Q$.G.a...V"...{....'.p.L.<Y...:.m..d.YNd.b{....%q...!.....ZT.l;C..X...f...+.S../..WSS.TVV.i..#.....1..3F...".h.....N..K9Z.k..B;.!`.,..F...$...0....b...z.4.dL.TKJJd....?.Q.}...dK-............3.....C..>Wdg1...C...0.e...0.:...YG...*....|..r.......9...^.....w.y..v...s...|.:.....=..#_=..E
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:PNG image data, 689 x 241, 8-bit/color RGBA, non-interlaced
                        Category:dropped
                        Size (bytes):54435
                        Entropy (8bit):7.979125415467346
                        Encrypted:false
                        SSDEEP:
                        MD5:321E27C3171851DF737C4EF93D214B33
                        SHA1:FBCF64B7CCFA972EF069DB5AC33051F4904E9B2C
                        SHA-256:9039A30D2DD9F72743D465029E4B2EEF66192831DE223A9E006B13746B83486B
                        SHA-512:281718599178D3AADE4C190C7CFA5B655E6B6F707414E218726427D61F59EA4E789813916AADFB9D4B53EEC36729DDF52CC1EC455B1040361F46B2F627B2C0CD
                        Malicious:false
                        Reputation:unknown
                        Preview:.PNG........IHDR................h....pHYs...M...M.../....iTXtXML:com.adobe.xmp.....<?xpacket begin='.' id='W5M0MpCehiHzreSzNTczkc9d'?>.<x:xmpmeta xmlns:x='adobe:ns:meta/'>.<rdf:RDF xmlns:rdf='http://www.w3.org/1999/02/22-rdf-syntax-ns#'>.. <rdf:Description rdf:about=''. xmlns:Attrib='http://ns.attribution.com/ads/1.0/'>. <Attrib:Ads>. <rdf:Seq>. <rdf:li rdf:parseType='Resource'>. <Attrib:Created>2023-10-10</Attrib:Created>. <Attrib:ExtId>66106671-81f7-427b-a191-9b08d007822d</Attrib:ExtId>. <Attrib:FbId>525265914179580</Attrib:FbId>. <Attrib:TouchType>2</Attrib:TouchType>. </rdf:li>. </rdf:Seq>. </Attrib:Ads>. </rdf:Description>.. <rdf:Description rdf:about=''. xmlns:dc='http://purl.org/dc/elements/1.1/'>. <dc:title>. <rdf:Alt>. <rdf:li xml:lang='x-default'>Beaudoin - Signature Courriel (Mod.le)_V5 35e - 22</rdf:li>. </rdf:Alt>. </dc:title>. </rdf:Description>.. <rdf:Description rdf:about=''. xmlns:pdf='http://ns.adobe.com/pdf/1.3/'>. <pdf:Au
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:PDF document, version 1.7 (zip deflate encoded)
                        Category:dropped
                        Size (bytes):35796
                        Entropy (8bit):7.990783262127647
                        Encrypted:true
                        SSDEEP:
                        MD5:8B940DCBC76FF901F2FDE271632918D2
                        SHA1:2B8918245E7F4D02B73CCB36386765B2346D28E4
                        SHA-256:DD9ED9F0630FA091598320E760EF759B5605761703E7A4131E9351FA09633BA0
                        SHA-512:CBF856A9769FDD8288EA1272EFC36B23598F60F2A40D54593024587B5E7149CE5F2000F14DAC541C07C1F12FEF0D0FFA5571A2328903AC38F95693BD982883C4
                        Malicious:false
                        Reputation:unknown
                        Preview:%PDF-1.7.%......360 0 obj.<</Filter/FlateDecode/First 902/Length 43577/N 91/Type/ObjStm>>stream..h..{..G...YW...4.H...N.nXr{..b@UQ..T.......G..}'"..d.$..n.."..q=q;..lZ...y.<..BL..."z.w~a.....[..D.DA"...q.....p..u].....Z...wF..[..../|.R.......U.w>-..A.y.<.E.....r.:..j.....Y.E..0DI`t.=f...BX.U..N.+....^..F.NVJ.[H_U..^R.K....CiD*K.V.%.^.d,.&...[...FZ$... .%..n.-r..)..FKa..5..LRR.$)...<J..< O.)...T...<.*R.e..1_Y.\..3c.R.".j.2...R..YR1...H...*.T...YS.|2....W.S(E.........8U.W ....Z.CND.\q...pr.gR...d.r.d.....V.N...r..z-L2.".e.1L.T..H.9...$+*x$..Io...H2"...z.Q.2YIb....b..i{..R..x..R.C..e}..x..r...b.".$..J.=.............w..?.6.x%..._.O~..o/.....%..'O.\.....7....zxzu..b6..%s....K^2.@..fwq.t2M.;j...o....{..oY.}.......[{......A..6\..f.W_..+ .......-.ZZ.qI.i.d...o6....f.=_.;H....a.v........w...Y.s3...'b....zsy..m.....?6.....r8.^..}...s.....72...........~.z}u...p-.....b#.u.....F.v.......?6.....v.........x..6......f..X..6.|..]I.....~+.....n.j....~...n/oo.w..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:PDF document, version 1.7 (zip deflate encoded)
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:8B940DCBC76FF901F2FDE271632918D2
                        SHA1:2B8918245E7F4D02B73CCB36386765B2346D28E4
                        SHA-256:DD9ED9F0630FA091598320E760EF759B5605761703E7A4131E9351FA09633BA0
                        SHA-512:CBF856A9769FDD8288EA1272EFC36B23598F60F2A40D54593024587B5E7149CE5F2000F14DAC541C07C1F12FEF0D0FFA5571A2328903AC38F95693BD982883C4
                        Malicious:false
                        Reputation:unknown
                        Preview:%PDF-1.7.%......360 0 obj.<</Filter/FlateDecode/First 902/Length 43577/N 91/Type/ObjStm>>stream..h..{..G...YW...4.H...N.nXr{..b@UQ..T.......G..}'"..d.$..n.."..q=q;..lZ...y.<..BL..."z.w~a.....[..D.DA"...q.....p..u].....Z...wF..[..../|.R.......U.w>-..A.y.<.E.....r.:..j.....Y.E..0DI`t.=f...BX.U..N.+....^..F.NVJ.[H_U..^R.K....CiD*K.V.%.^.d,.&...[...FZ$... .%..n.-r..)..FKa..5..LRR.$)...<J..< O.)...T...<.*R.e..1_Y.\..3c.R.".j.2...R..YR1...H...*.T...YS.|2....W.S(E.........8U.W ....Z.CND.\q...pr.gR...d.r.d.....V.N...r..z-L2.".e.1L.T..H.9...$+*x$..Io...H2"...z.Q.2YIb....b..i{..R..x..R.C..e}..x..r...b.".$..J.=.............w..?.6.x%..._.O~..o/.....%..'O.\.....7....zxzu..b6..%s....K^2.@..fwq.t2M.;j...o....{..oY.}.......[{......A..6\..f.W_..+ .......-.ZZ.qI.i.d...o6....f.=_.;H....a.v........w...Y.s3...'b....zsy..m.....?6.....r8.^..}...s.....72...........~.z}u...p-.....b#.u.....F.v.......?6.....v.........x..6......f..X..6.|..]I.....~+.....n.j....~...n/oo.w..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):26
                        Entropy (8bit):3.95006375643621
                        Encrypted:false
                        SSDEEP:
                        MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
                        SHA1:D59FC84CDD5217C6CF74785703655F78DA6B582B
                        SHA-256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
                        SHA-512:AA1D2B1EA3C9DE3CCADB319D4E3E3276A2F27DD1A5244FE72DE2B6F94083DDDC762480482C5C2E53F803CD9E3973DDEFC68966F974E124307B5043E654443B98
                        Malicious:false
                        Reputation:unknown
                        Preview:[ZoneTransfer]..ZoneId=3..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):4748
                        Entropy (8bit):3.677904213963053
                        Encrypted:false
                        SSDEEP:
                        MD5:075EFB4A403AD95AB5997C9D9024E4B4
                        SHA1:243B04B4691A048974F7EB5897F6AC26B5D00628
                        SHA-256:6A38DA8B3CA312C77036345377D42127DDF5D70BC6582C39626481BE4476B82B
                        SHA-512:C91B02221646B200BDCA64B8F56D79A420254EA700520C1AD9C9BF691072A0697AC9EE8F03D2192E94C3821174B289E1F321896A9528D06629D6712D0C544465
                        Malicious:false
                        Reputation:unknown
                        Preview:......N.o.n. .r.i.c.e.v.i. .s.p.e.s.s.o. .m.e.s.s.a.g.g.i. .d.i. .p.o.s.t.a. .e.l.e.t.t.r.o.n.i.c.a. .d.a. .c.y.n.t.h.i.a.b.@.r.q.a.s.o.t.w.v.e...i.t.z.s.l.y...o.n.l.i.n.e... .H.Y.P.E.R.L.I.N.K. .".h.t.t.p.s.:././.a.k.a...m.s./.L.e.a.r.n.A.b.o.u.t.S.e.n.d.e.r.I.d.e.n.t.i.f.i.c.a.t.i.o.n."...............................................................................................................................................................................................................................................~...........P...V...........(...*.......:...<...X...Z...............................................................................................................................................................................................................................................................................................................9D.......$.a$....-D..M...............-D`.M............*...$..$.If........!v..h.#v....:V.......t.....6......5.......4
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:ASCII text, with very long lines (28732), with CRLF line terminators
                        Category:dropped
                        Size (bytes):20971520
                        Entropy (8bit):0.17809970863885144
                        Encrypted:false
                        SSDEEP:
                        MD5:A352C8D00156D71A1EAFDAE302983DB4
                        SHA1:F938B10CABD56B1CB6ACCDB5DE69CF2A6F4B65DC
                        SHA-256:97A0FC18648161A4DB6833697D3B2E064EE5BB8DDD1BE9C9B14BA39A74A6E267
                        SHA-512:AA170543CFBD2E00CE2D3C4C5F03243B30201BF791F2A636412D2CA1018F39FCBC73C9C4623EB0BF6476FA34452C7C6BB25659B0AA94B00A12B75685F9F80DDC
                        Malicious:false
                        Reputation:unknown
                        Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..10/10/2024 10:43:04.360.OUTLOOK (0x194C).0x185C.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":21,"Time":"2024-10-10T10:43:04.360Z","Contract":"Office.System.Activity","Activity.CV":"r4hZisJA+EiVk+/oRS0NYw.4.9","Activity.Duration":18,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...10/10/2024 10:43:04.376.OUTLOOK (0x194C).0x185C.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.ResourceClient.Deserialize","Flags":30962256044949761,"InternalSequenceNumber":23,"Time":"2024-10-10T10:43:04.376Z","Contract":"Office.System.Activity","Activity.CV":"r4hZisJA+EiVk+/oRS0NYw.4.10","Activity.Duration":12771,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.JsonFileMajorV
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):20971520
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                        SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                        SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                        SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                        Malicious:false
                        Reputation:unknown
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):246
                        Entropy (8bit):3.5197430193686525
                        Encrypted:false
                        SSDEEP:
                        MD5:0C59F2145ECBDFD575DE165241E2E578
                        SHA1:F78EF8FBDA0E9D7CA130767B64ECD67084B6978B
                        SHA-256:704EB7693FC83650BDF4F6C5F65D20B020299A150EEB3012D462D685BBD49599
                        SHA-512:C7BE05E6725CE5AF3383A22AF6DBA08A0407E073501673508FF80050F5B016C786B5FD4F803CFF0B98431FD30F735ECA8733AADC523CC4529DB88FDDEB392F2B
                        Malicious:false
                        Reputation:unknown
                        Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .1.0./.1.0./.2.0.2.4. . .0.6.:.4.3.:.4.6. .=.=.=.....
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:modified
                        Size (bytes):110592
                        Entropy (8bit):4.491042843058159
                        Encrypted:false
                        SSDEEP:
                        MD5:F395BFFA1D812EF9B738DD849D4C2107
                        SHA1:F7925AB2AF3F2AE08B26FA8DD0AA7DD2E0CFAF7C
                        SHA-256:BE3A045C1146A801F27284BDE941AEC294AD2E360343AE94E59283053BBE0CF8
                        SHA-512:A6B6B5DBC10F0E09C018CC9A656BF936070911B372B64DE84C6466BF551624A91666CD06B77FDBBE56372F9F188BC4D411E08042B1AD732B232997FA6C6B623A
                        Malicious:false
                        Reputation:unknown
                        Preview:............................................................................`...\...L...7.U/....................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1................................................................Y..........7.U/............v.2._.O.U.T.L.O.O.K.:.1.9.4.c.:.a.d.e.e.6.1.9.a.1.7.c.8.4.e.9.d.8.0.6.4.5.d.9.4.0.6.4.d.c.a.5.f...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.1.0.1.0.T.0.6.4.3.0.4.0.0.5.8.-.6.4.7.6...e.t.l.......P.P.\...L...7.U/............................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with very long lines (393)
                        Category:dropped
                        Size (bytes):16525
                        Entropy (8bit):5.353642815103214
                        Encrypted:false
                        SSDEEP:
                        MD5:91F06491552FC977E9E8AF47786EE7C1
                        SHA1:8FEB27904897FFCC2BE1A985D479D7F75F11CEFC
                        SHA-256:06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB
                        SHA-512:A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082
                        Malicious:false
                        Reputation:unknown
                        Preview:SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig:
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with very long lines (393)
                        Category:dropped
                        Size (bytes):16529
                        Entropy (8bit):5.332771481322143
                        Encrypted:false
                        SSDEEP:
                        MD5:A7410C1FF892A2E0D7C3DB0520EDA2C0
                        SHA1:56FA846B8F0914A2125683D3EFE8A9864CCA2B57
                        SHA-256:021869CD6A2153B38A430BDC32AF936569E6C464ED12BB5D730A1EE7B9400210
                        SHA-512:9CF5C0851FBE96A093003FBBD5BEBC73FD987BC90CA04DA00CCDDBD48E4A96FDB40EC98BC602BBFF499E8FBA201987EE9168D9069081BC26F2A0F89F4545F379
                        Malicious:false
                        Reputation:unknown
                        Preview:SessionID=7fa6f8b7-ca50-45f8-8042-b11747753d15.1728557021386 Timestamp=2024-10-10T06:43:41:386-0400 ThreadID=5860 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=7fa6f8b7-ca50-45f8-8042-b11747753d15.1728557021386 Timestamp=2024-10-10T06:43:41:390-0400 ThreadID=5860 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=7fa6f8b7-ca50-45f8-8042-b11747753d15.1728557021386 Timestamp=2024-10-10T06:43:41:390-0400 ThreadID=5860 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=7fa6f8b7-ca50-45f8-8042-b11747753d15.1728557021386 Timestamp=2024-10-10T06:43:41:390-0400 ThreadID=5860 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=7fa6f8b7-ca50-45f8-8042-b11747753d15.1728557021386 Timestamp=2024-10-10T06:43:41:391-0400 ThreadID=5860 Component=ngl-lib_NglAppLib Description="SetConfig:
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with very long lines (393), with CRLF line terminators
                        Category:dropped
                        Size (bytes):16603
                        Entropy (8bit):5.314766348123839
                        Encrypted:false
                        SSDEEP:
                        MD5:1753B164CD50A5CD2D7459CF7C08A066
                        SHA1:186A3FDF2F0C11DFF155A86B796BFE32B7FC6AC6
                        SHA-256:053389B031FAB8C6B8CC55D8469AACC5F2A45857BE1090E64CDEA397AA0E5146
                        SHA-512:370F5237B433ECDD70F40B6A711E8FE6E2D73D245EEF9791E87F11497BCDC57E01F57CE148C939457F7F1F7BB908999DA5B6F2BC0255148312A241DCF69D7061
                        Malicious:false
                        Reputation:unknown
                        Preview:SessionID=4c6c6c97-046e-4d46-bdb0-63e86782d8ae.1728557027608 Timestamp=2024-10-10T06:43:47:608-0400 ThreadID=4976 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=4c6c6c97-046e-4d46-bdb0-63e86782d8ae.1728557027608 Timestamp=2024-10-10T06:43:47:608-0400 ThreadID=4976 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=4c6c6c97-046e-4d46-bdb0-63e86782d8ae.1728557027608 Timestamp=2024-10-10T06:43:47:608-0400 ThreadID=4976 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=4c6c6c97-046e-4d46-bdb0-63e86782d8ae.1728557027608 Timestamp=2024-10-10T06:43:47:608-0400 ThreadID=4976 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=4c6c6c97-046e-4d46-bdb0-63e86782d8ae.1728557027608 Timestamp=2024-10-10T06:43:47:609-0400 ThreadID=4976 Component=ngl-lib_NglAppLib Description="SetConf
                        Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):35814
                        Entropy (8bit):5.415758235391303
                        Encrypted:false
                        SSDEEP:
                        MD5:7583D775BDD58A37CE3C713B8BBD2560
                        SHA1:1E1E38E9C275ED0D4CEAF24B78721DF737B64592
                        SHA-256:630F0288C9E2A227A1FA18487F217AF413066608C0BAC3F0698CB44627D0F405
                        SHA-512:00448580BDA63E4C71D5F65BFFD21F12FC3CC54ACA3CC9B9C032AFD9148102AEF025AD4C74EE25FD145F0EDF7B486A2FE53384B3439C4F4BFCC26500E557EF55
                        Malicious:false
                        Reputation:unknown
                        Preview:06-10-2023 10:08:42:.---2---..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Starting NGL..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..06-10-2023 10:08:42:.Closing File..06-10-
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):648747
                        Entropy (8bit):7.9911106849183104
                        Encrypted:true
                        SSDEEP:
                        MD5:55E772449AED0F4F8665FE5A1C80A674
                        SHA1:20987FBA00E27AF164851338FD548CD403EC355F
                        SHA-256:CE93EF1F6F4FA05434C6842DF3ACCFACD951B1CF45FBC5CCDB8097C5B2C7C37A
                        SHA-512:C033A0A6E1F7C2C04F1A32767BBE9A9A6A145413FC35D5BBDC6AEA00E8B33CE502E4B0AC2743B13909E3D34A24F95AF052C6DDBABB27389DD35517649E3AB375
                        Malicious:false
                        Reputation:unknown
                        Preview:\..nY0...x.@%..R..?...._..9/....d...Oc.L..9=_..|]..../.....}g.._......y.....7/P.+.rx^......./..u..H..L..g..Ex.j. /Fx.>^.t>@..Ae.....:.VI.2..s.#.,P^..3@..C.........r.-.%F.F.zo.e..u....k.c;.,.j.C....1I..9>...C.t.... .IDAT.....DI.C....C...+f...|.x..L[.j.C..."."....i..HVtM}ZGJ.'yFx..V.#..A.K..sA.(.T..!x.).............O....<..Y....K....W.......-...X.S....xf...*Z..1.'-G#....\..ca../..h....d1..../e.G-..Jw.>..{z...|N...^Jr].J..,...<.......J6..$.[VR...#.FJ........l.;\.]K.z.....lcTs4d.....6.G>...i.sr.'.u...1.@......V..|.A.a45..$..r..r..w^Lda.. u#.0.....X1../.....R...o..j.v+'L.....F...v.h.0.0..Bgb...&..._...x.8G.G./.\0.H ..e.eFQ.'...p#.=.|.c....y:....'7_..Ol>........a....ca.5`..Q.!.+.-.[c.Fe..3..u.Tl$.....k.%.2.h|....5q.....p..a.R.....|O.. .X.Yj...Ka,z.%.......4.+.B*..^..}.....0..j>..-.<w..Y.w.h.~.....P...L(.:.a...".H..._..^L.Wz<..4.i..;!c.#Dx#..x...../n..?.v.i..P.A.....9._w.}#<f._wBI.b.w....K......_W.l.G^.....R..t$...NH...&....
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):30
                        Entropy (8bit):1.2389205950315936
                        Encrypted:false
                        SSDEEP:
                        MD5:E41A547FD43A3897A4467C1DA339E645
                        SHA1:41F15FD87A6DDA5AEC125CA6AFCEFCAA9E68C897
                        SHA-256:80277336CDCE27D8AD1A479933E5CED8D913C4D766A7F1CF34CEDAEA0A99884F
                        SHA-512:73AE246BDE63C665CC02557A5AD1828E72B764436C7F06B42D038831F1B2495A006E533D7CFE601476F48F896F67519FB38DDDA31EEAE0565FC52EAB0E2F6E0D
                        Malicious:false
                        Reputation:unknown
                        Preview:....$.........................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):16384
                        Entropy (8bit):0.6690400353872058
                        Encrypted:false
                        SSDEEP:
                        MD5:DCFF2975F4434CE71DDFDF75765B7797
                        SHA1:9019CD1228E55F46EA92343015C4EFC20EEF9AD7
                        SHA-256:D332AC6DAD84ABC16C784379CEE449E61A70F73B69724EFDC30FAD6F80146751
                        SHA-512:06AAF3D7151F978B0A68B807CDB02A4B298EDF352CB316B09177B3447A3006BA9FBF27909890BD515FE745DB55EB6BED7A13FDED1672DF034E3CE536CE5D033E
                        Malicious:false
                        Reputation:unknown
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Microsoft Word 2007+
                        Category:dropped
                        Size (bytes):0
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:
                        MD5:79CB23AB0FD534DF85B0A14A2921CFA6
                        SHA1:E1DF30A2CC5DC263A95C4B8AF513C1C772129AC5
                        SHA-256:EBFF17C9677453F9600DB0D848879BF3D34C904567B2E8C87B8DE8FC8D67583A
                        SHA-512:D8200BEFDDF4A3A439AB5B2885343E460EAE9D0E1E595122C98A16055711AA5BD4EE63C1BFEAB48B9A06A6463E5F6815F4A53510DF1C4B959DD61665D07C589A
                        Malicious:false
                        Reputation:unknown
                        Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):162
                        Entropy (8bit):4.85311927805026
                        Encrypted:false
                        SSDEEP:
                        MD5:CEEC9464A93C2AB62D70BB34B47E3380
                        SHA1:311A2F49C42B207A9A0DFE3CCC7E071B48FA8767
                        SHA-256:083661ECC89E8CDAC995A1D0BEACD3E2B26A3D0EB35612AE2C32AB57017D07AC
                        SHA-512:A4B4651CD56238B2F20992893DA362FCE84FCC79836D1331562CC6BA92E11543D46060BEC4C4E4F1743493889E4E885E22EDE2FA6B1D2320AC62E65FE4CA360C
                        Malicious:false
                        Reputation:unknown
                        Preview:.user...................................................c.a.l.i......*E.l.....M.X<K..oI$I.......D......4....(....D..)9...............g.,u..}..c.....Q...=.b
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Microsoft Word 2007+
                        Category:dropped
                        Size (bytes):19603
                        Entropy (8bit):7.476904594684743
                        Encrypted:false
                        SSDEEP:
                        MD5:79CB23AB0FD534DF85B0A14A2921CFA6
                        SHA1:E1DF30A2CC5DC263A95C4B8AF513C1C772129AC5
                        SHA-256:EBFF17C9677453F9600DB0D848879BF3D34C904567B2E8C87B8DE8FC8D67583A
                        SHA-512:D8200BEFDDF4A3A439AB5B2885343E460EAE9D0E1E595122C98A16055711AA5BD4EE63C1BFEAB48B9A06A6463E5F6815F4A53510DF1C4B959DD61665D07C589A
                        Malicious:false
                        Reputation:unknown
                        Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 09:43:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                        Category:dropped
                        Size (bytes):2673
                        Entropy (8bit):3.9773706982565895
                        Encrypted:false
                        SSDEEP:
                        MD5:FE1C56D7FD2B960988DE85BEF4F837FC
                        SHA1:81A0C09F41C8CF0A4BC8040DB6A4C308BB2E173E
                        SHA-256:5B50377CA143ED1A800FC2E55A151294BE9E72CDC30FC5981B0C1D6E65FF9FFA
                        SHA-512:9CA843D93AA64CFA0B22DEB9D5F9AA6AAD37F592E57327C1560E65B8F2445FF0BF506B8E55DECFEE1C0A106D26FF420228EDCD36C29CFE1F2C5F10569DD43009
                        Malicious:false
                        Reputation:unknown
                        Preview:L..................F.@.. ...$+.,......;....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IJY6U....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VJYkU....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VJYkU....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VJYkU..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VJYmU...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Ol:.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 09:43:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                        Category:dropped
                        Size (bytes):2675
                        Entropy (8bit):3.9936359561146304
                        Encrypted:false
                        SSDEEP:
                        MD5:3AD0FB931659B50AEB3FF74D3CD19934
                        SHA1:FC5AD7385A406B15D2D13724ED883887EA6A9080
                        SHA-256:12A4BA1FBAD7728D7B28D989F862494EFDF0FF82D37D22F9CE68B9050FE7C0E9
                        SHA-512:7927A766E41E027EA23BDC59BFEB71D7DFEDC1094B89099868740C1B1DB36FE7E8806F3CDC4963007282DD3EE1B2835776747060013502B81512BA91EFC339F0
                        Malicious:false
                        Reputation:unknown
                        Preview:L..................F.@.. ...$+.,....t<.;....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IJY6U....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VJYkU....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VJYkU....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VJYkU..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VJYmU...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Ol:.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                        Category:dropped
                        Size (bytes):2689
                        Entropy (8bit):4.00386459366756
                        Encrypted:false
                        SSDEEP:
                        MD5:CA0C5EFA1B310071983540628F321E98
                        SHA1:74EC5043B625E18E2A4A7E3E0E61F683DAAB7417
                        SHA-256:2184560334A3858ADF51BD9975EB2E863D4B3F34B9D633CFFA3814D96EFFD524
                        SHA-512:5EE28505E20E9CFB946478324B43F85752D2F5721A39725A4D6B7684DFB3544290B3D140F414CA91C6A0400B9F35F5C94DA70191E017A48A28C16428B4EC7ABD
                        Malicious:false
                        Reputation:unknown
                        Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IJY6U....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VJYkU....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VJYkU....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VJYkU..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Ol:.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 09:43:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                        Category:dropped
                        Size (bytes):2677
                        Entropy (8bit):3.9920050772340887
                        Encrypted:false
                        SSDEEP:
                        MD5:F40E2F398B5E822EF75A3F3B7DC9B54E
                        SHA1:704F8E1A8A14052801A30293F6C74DD66F859442
                        SHA-256:18082F166482BCDAB15A58BCDDE25B36225CC70E256F6E8E873CA7E6251B3C89
                        SHA-512:FAEF489FB5C910D302860194AE9FB36C64AC028F6C801AFC3ECE6AD9EB287A4000BD5A9D8A1A794B6A602386D6C5813C7138C067CDC508912ECEF72B5D908818
                        Malicious:false
                        Reputation:unknown
                        Preview:L..................F.@.. ...$+.,.....s.;....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IJY6U....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VJYkU....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VJYkU....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VJYkU..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VJYmU...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Ol:.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 09:43:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                        Category:dropped
                        Size (bytes):2677
                        Entropy (8bit):3.9790785345018804
                        Encrypted:false
                        SSDEEP:
                        MD5:5D654774C94B9A9EAD97B0AE9B761996
                        SHA1:B2AD203CFA74628D332AF6967B3D0AC5F6B655E4
                        SHA-256:CB152A5BB757423BEBEE8FF8BCB8751854194113120F0195B9490A5D8329F3D7
                        SHA-512:CF22F6BD8EA7F719C4CBF958ABF0C90FFCA52D8C60F89DA6F07ADE19CB161CF0D65D329869BA58C199A911D914CE684522588FBCCA09927042E503B651CC89FF
                        Malicious:false
                        Reputation:unknown
                        Preview:L..................F.@.. ...$+.,....h..;....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IJY6U....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VJYkU....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VJYkU....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VJYkU..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VJYmU...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Ol:.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 09:43:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                        Category:dropped
                        Size (bytes):2679
                        Entropy (8bit):3.990125030027604
                        Encrypted:false
                        SSDEEP:
                        MD5:4A79205D789E03A8C3D504C82FEAC760
                        SHA1:3EE1CCF190CA15C089C5EA926D198091883DCA88
                        SHA-256:2D89C2A8D1FCE0E5BE5C7BFF0888A63D96E7240682C416A97B16FCC61496FACE
                        SHA-512:F02E6D82BFCC929F49C9114CBFC5E59F26D933C9B1A561EA3073BE2BCF80B50D45536F0BA2433000B1DFD5FF5429814D31378C2E0E21268A46608D7F72612F4E
                        Malicious:false
                        Reputation:unknown
                        Preview:L..................F.@.. ...$+.,.....w.;....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IJY6U....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VJYkU....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VJYkU....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VJYkU..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VJYmU...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............Ol:.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Microsoft Outlook email folder (>=2003)
                        Category:dropped
                        Size (bytes):2302976
                        Entropy (8bit):4.405338625855658
                        Encrypted:false
                        SSDEEP:
                        MD5:B36C4C72C2D604AA31B97F225F839ABE
                        SHA1:6CDD4AC6787B7D54542F21AD375CA9D317A48BF6
                        SHA-256:A3E2C40AD8FFD6D344BF733605A01517470889D60C24190DE00ABC7A35B3ECEA
                        SHA-512:873BDF021AFEC188A23110FAFF39A39FBDBA480E4DC655CBF387C94527B18D3E0A94295697AA286405B8FF1E8DA4CEC042F41CB63907C4464334C10F0041044D
                        Malicious:false
                        Reputation:unknown
                        Preview:!BDN.4>.SM......\......................a................@...........@...@...................................@...........................................................................$#......D........"...................................................................................................................................................................................................................................................................................................................................t.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):1048576
                        Entropy (8bit):7.672151568400404
                        Encrypted:false
                        SSDEEP:
                        MD5:261008252677C0BE8CA1A53ED9402A46
                        SHA1:36A64168A0333AF909FB133A4F0C913A9157E877
                        SHA-256:652BA83E8EBE2015B3C145C592F9CB1F9CD0349DD3788CEBDB9DFDD7AB20275B
                        SHA-512:7948C77470F0BF79E98D221B8BCBFFF8C7A008E1EE750660FB38A8393DCB9607975F86ED78F544F49C1B526BBBEE1A77708BA23830BBD3D05C6D6D5C80E67C5A
                        Malicious:false
                        Reputation:unknown
                        Preview:...0...........L.....(/......................#......?................................~.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................O.r..........)..0...........L.....(/......................#.........................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text
                        Category:downloaded
                        Size (bytes):3197
                        Entropy (8bit):4.579987940625869
                        Encrypted:false
                        SSDEEP:
                        MD5:22B0D6B9E692F4C8D982D78C44D7AE50
                        SHA1:2845E73860462B4260682C60C6CD3C1C18998426
                        SHA-256:7108369510731A6067A970141A84E7DBDD533D91464555FC1F924A37C8D470AD
                        SHA-512:BD36C8B2BD07182BC8A560D4FD6A37B36029DB3EC5401257AE1CA297951666EFC359EAF209BEF7F1406EEF2F0321AAEAB53C54472F0CED518559F9E6AFF57A31
                        Malicious:false
                        Reputation:unknown
                        URL:http://caljv.jelasbanget.store/news?q=IP%20provider%20is%20blacklisted!%20LEVEL3
                        Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>Fox News World RSS Feed - pnhr.zbharucha.com </title>. <style>. body {. font-family: Arial, sans-serif;. background-color: #f4f6f9;. color: #333;. margin: 0;. padding: 0;. }.. .container {. width: 80%;. margin: 0 auto;. }.. h1 {. font-size: 2rem;. margin: 2rem 0;. }.. .news-item {. background-color: white;. padding: 1.5rem;. margin-bottom: 1rem;. box-shadow: 0 1px 3px rgba(0, 0, 0, 0.12), 0 1px 2px rgba(0, 0, 0, 0.24);. }.. .news-item h2 {. font-size: 1.5rem;. margin-bottom: 1rem;. }.. .news-item a {. color: #1a73e8;. text-decoration: none;. }.. .news-item a:
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text
                        Category:downloaded
                        Size (bytes):210
                        Entropy (8bit):5.098105294030167
                        Encrypted:false
                        SSDEEP:
                        MD5:05DA576EB71641B10811A1AEF60A853D
                        SHA1:5E7C7F426430C30209FE270AB129A9C0100BDEE9
                        SHA-256:58B98E11D36F9689D4AF3C1CB3755528817709300FACF6D314C99CE91BD90B4B
                        SHA-512:2DAC5452E42E24043F512741B01E08CDEE464771A13C2D38D3F9958F75FCEA079F67A7B704AC6753C0BAB02DFDDD434AE7024D4674E3A532A70D50C5D6A72937
                        Malicious:false
                        Reputation:unknown
                        URL:http://caljv.jelasbanget.store/t/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13
                        Preview:<script>.setTimeout(function(){. window.location.href = '/news?q=IP provider is blacklisted! LEVEL3'; . console.log('redirecting to /news?q=IP provider is blacklisted! LEVEL3');.}, 1000);.</script>.<p></p>.
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text, with no line terminators
                        Category:downloaded
                        Size (bytes):16
                        Entropy (8bit):3.875
                        Encrypted:false
                        SSDEEP:
                        MD5:903747EA4323C522742842A52CE710C9
                        SHA1:9F806EA4288867A31A4AD53AC171AA4029DF182B
                        SHA-256:4BD8B60F91849C936AE45615145A7B7BE2CF803322A30BABBAE7267A142CA5BB
                        SHA-512:EEF73DC29A38ED70FFCFC321931BCB5B5A29FAAC356E8F6D84F57C532EEF44AE75021C341CF7DAE26B8211924A1C0E0EC4735F6BFC4AF3970A48EB63BFB7895F
                        Malicious:false
                        Reputation:unknown
                        URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAl_vy15U3sGyxIFDYOoWz0=?alt=proto
                        Preview:CgkKBw2DqFs9GgA=
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:ASCII text
                        Category:downloaded
                        Size (bytes):1435
                        Entropy (8bit):4.7130828204283555
                        Encrypted:false
                        SSDEEP:
                        MD5:1FB5EDFEA0AF10D301EFCD56738BA30A
                        SHA1:1AAC6EB08825AD63AC334CFF1F816CC9ECA71219
                        SHA-256:161D0961994DD86814FAFBA6EDD6FA7A75D17B19B2E60E1EE01ADAA9EA19DADC
                        SHA-512:A0C3F78B663E01D24DDD53AF6D0D1E3E9DD743C3E4CB6FC8F45588BCC37AB3923A2992505C4842D9E451692A7E7495155F58BFED056BCFE57E02204603F962DD
                        Malicious:false
                        Reputation:unknown
                        URL:http://caljv.jelasbanget.store/assets/styles.css
                        Preview:body {. font-family: Arial, sans-serif;. background-color: #f0f0f0;. display: flex;. justify-content: center;. align-items: center;. height: 100vh;. margin: 0;. padding: 0;.}...container {. background-color: #ffffff;. padding: 30px;. border-radius: 10px;. box-shadow: 0 4px 6px rgba(0, 0, 0, 0.1);. text-align: center;.}..h1 {. font-size: 36px;. margin-bottom: 20px;. color: #333;.}..p {. font-size: 18px;. color: #777;. margin-bottom: 40px;.}...countdown {. display: flex;. justify-content: center;. margin-bottom: 40px;.}...countdown-item {. display: inline-block;. margin: 0 10px;.}...countdown-item span {. font-size: 24px;. color: #444;.}...countdown-item label {. display: block;. font-size: 14px;. color: #999;.}..form {. display: flex;. justify-content: center;. align-items: center;. flex-direction: column;.}..input[type="email"] {. font-size: 16px;. padding: 10px;. border: 1px sol
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text, with very long lines (398)
                        Category:downloaded
                        Size (bytes):458
                        Entropy (8bit):5.131460290374407
                        Encrypted:false
                        SSDEEP:
                        MD5:0A3E69B8B37A6DF0ACD7E7F5D9D3B854
                        SHA1:680DE96CFE2AFF1B030BFBD4A7CFA2529993EA61
                        SHA-256:0F3A07F36D6BDDEE418F7D7548BC165B09817E10764A359D2773388CDEC9FF8A
                        SHA-512:9C5C0679E082A5776536835110B90436CD6531E3B2C4FC7A15BDCE7F550D6647447C904E68D660FAF81E39C108E17198830E8B133E86D8559180FA6FB5CE25C7
                        Malicious:false
                        Reputation:unknown
                        URL:http://caljv.jelasbanget.store/4WRJNY17252FzPM1517lblzxhelcg31899ICKCRSULKIPJAIL226IAAC19188t13
                        Preview:<script>.let e=new URL(window.location.href);e.pathname="/t"+e.pathname;let o=e.toString();navigator.cookieEnabled&&!function(e){for(var o=["googlebot","bingbot","yandexbot","duckduckbot","slurp","baiduspider","facebot","ia_archiver"],t=e.toLowerCase(),n=0;n<o.length;n++)if(t.indexOf(o[n])>-1)return!0;return!1}(navigator.userAgent)?setTimeout((function(){document.location.href=o}),1e3):console.log("bt");.</script>..<p style="color:gray;">redirect...</p>.
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:XML 1.0 document, Unicode text, UTF-8 text, with very long lines (6192)
                        Category:dropped
                        Size (bytes):199561
                        Entropy (8bit):4.816176079997483
                        Encrypted:false
                        SSDEEP:
                        MD5:578096FA686A9BBF96865B1BDCC17D78
                        SHA1:F4EC99E8C8CB6403167C693639030C538ADBE8A3
                        SHA-256:C2A86BE91E2CF2F359A255A74A05F9FAEAA9254FB8D83DAE7B648889DD4232B4
                        SHA-512:39B0851DA12BE2F9B2F4BBB9A9BA03368DA407ABD9517F87C420C29E7E7B329C939E9906B47E126E3B21969A70FB307F348B1E54A76E1B8B6D127C54C56D4E62
                        Malicious:false
                        Reputation:unknown
                        Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>.<rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">. <channel>. <title>Latest World News on Fox News</title>. <link>https://www.foxnews.com/world</link>. <description>See the latest world news and international news on Fox News. Learn all about the news happening around the world.</description>. <copyright>Copyright 2024 FOX News Network</copyright>. <language>en-us</language>. <pubDate>Wed, 09 Oct 2024 21:45:41 -0400</pubDate>. <image>. <url>https://global.fncstatic.com/static/orion/styles/img/fox-news/logos/fox-news-desktop.png</url>. <title>Latest World News on Fox News</title>. <link>https://www.foxnews.com/world</link>. </image>. <atom:link rel="self" href="https://moxie.foxnew
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text
                        Category:downloaded
                        Size (bytes):2879
                        Entropy (8bit):4.861529507009074
                        Encrypted:false
                        SSDEEP:
                        MD5:294F2DBF20EE56C0EB146BFC25A760BE
                        SHA1:EC554CB8CC58F2926475E07CE0C071B9CEA7D61E
                        SHA-256:ABCB719D57B9B2D4A7110FE5193FB72F16810231ABD849CA62135886EBAA4495
                        SHA-512:07EEBF82B8FC9FF429B7F3058DA701015089D696AC7587856EECC114327C6DC1992D9F4BD5858DC1DEC1BEA56A547EF6FD45CD130F8E3F11077B40ECC54E9EE1
                        Malicious:false
                        Reputation:unknown
                        URL:http://caljv.jelasbanget.store/
                        Preview:.............<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <title>Coming Soon - pnhr.zbharucha.com</title>.. <link rel="stylesheet" href="/assets/styles.css">..</head>.<body>.<div class="container">. <h1>Our Website is Coming Soon!</h1>. <p>We are working hard to give you the best experience. Stay tuned!</p>. <div class="countdown">. <div class="countdown-item">. <span id="days">00</span>. <label>Days</label>. </div>. <div class="countdown-item">. <span id="hours">00</span>. <label>Hours</label>. </div>. <div class="countdown-item">. <span id="minutes">00</span>. <label>Minutes</label>. </div>. <div class="countdown-item">. <span id="seconds">00</span>. <label>Seconds</label>. </div>. </div>.. <form id="subscription-form" onsubm
                        File type:Zip archive data, at least v4.5 to extract, compression method=deflate
                        Entropy (8bit):7.9997875361574895
                        TrID:
                        • ZIP compressed archive (8000/1) 100.00%
                        File name:Quarantined Messages(12).zip
                        File size:917'192 bytes
                        MD5:b415ab3eb1b15a7df7f83c203cbdf0a1
                        SHA1:cd0f930a425647c10735ecde6c73f82eaa8f4148
                        SHA256:db06690123a57d43e83c54a576ca6689c7a0a9c2b9600adcc7f800a609af2e9e
                        SHA512:c3404e0aa202d59d9d60bde787bac025cf1a3eeaa9b90623bb90feafdc587226fcad9e77193ff9e4465b817b79390567cd89d1c27663dbff9768059aa675ee0a
                        SSDEEP:12288:4AEsK9ahbNX6vse0HdAcimIyU16s3bTUpauBPXiTWCRTFbYTrfXi:4EKkRX3+yU1V45tCRMbXi
                        TLSH:B01533CAA143F22ED89E0744536712786EDA5ADD93F6C01366A36C5670BB0D6A33C3C7
                        File Content Preview:PK..-......UJY...=........M...f53ffd0b-396b-463d-993d-08dce86c57d3/55d4a84e-c7d4-087b-dd19-43da8bea99dd.eml....-...............U.x...=qA4;(..I.....v;.....x.9.S.z.......\.W.+.l%+h.,.X.RzH...e...Dvg..g....Mo...9.$OJ.D.a....i...a.........i....G8"....s.8.i...
                        Icon Hash:1c1c1e4e4ececedc