Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
phish_alert_sp2_2.0.0.0 (13).eml

Overview

General Information

Sample name:phish_alert_sp2_2.0.0.0 (13).eml
Analysis ID:1531116
MD5:d7f52aeb8f88e6aae33568f0525ebe29
SHA1:34fe6187c24dcb85f8370f53d0f08626f1c72a6f
SHA256:5a7d3b8181f1e69ebf5c29327f089cbd87b67b1825b541ad92d3f01a7823abc5
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores large binary data to the registry

Classification

  • System is w10x64
  • OUTLOOK.EXE (PID: 4132 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\phish_alert_sp2_2.0.0.0 (13).eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 5648 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "275573E4-4E3A-44CF-9503-868017FC0EFD" "DC9DDA95-057A-40A5-91CF-1110D1B5CBAE" "4132" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • HxOutlook.exe (PID: 6232 cmdline: "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca MD5: 6F8EAC2C377C8F16D91CB5AC8B8DBF5F)
  • HxAccounts.exe (PID: 7416 cmdline: "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe" -ServerName:microsoft.windowslive.manageaccounts.AppXdbf3yp5apt3t7q877db3gnz5zqpf71zj.mca MD5: 6FEB00C9A2C3FF66230658B3012BAB6A)
  • cleanup
No configs have been found
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 4132, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: http://b.c2r.ts.cdn.office.net/pr
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: olk6C0A.tmp.0.drString found in binary or memory: http://pki-crl.symauth.com/ca_7a5c3a0c73117406add19312bc1bc23f/LatestCRL.crl07
Source: olk6C0A.tmp.0.drString found in binary or memory: http://pki-ocsp.symauth.com0
Source: HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/
Source: HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/c780dddc8-18a1-5781-895a-a690464fa89cp
Source: HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/http://test-exp-s2s.msedge.net/ab/http://test-exp-s2s.msedge.net/a
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.aadrm.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.aadrm.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.addins.omex.office.net/api/addins/search
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.cortana.ai
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.diagnostics.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.microsoftstream.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.office.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.officescripts.microsoftusercontent.com/api
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.onedrive.com
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/imports
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://api.scheduler.
Source: HxAccounts.exe, 0000000B.00000002.3585589019.000001B58982B000.00000004.00000020.00020000.00000000.sdmp, 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://apis.mobile.m365.svc.cloud.microsoft
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://app.powerbi.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://augloop.office.com
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://augloop.office.com/v2
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: HxAccounts.exe, 0000000B.00000002.3585481715.000001B589800000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://az804205.vo.msecnd.net/
Source: HxAccounts.exe, 0000000B.00000002.3585481715.000001B589800000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://az804205.vo.msecnd.net/f
Source: HxAccounts.exe, 0000000B.00000002.3585481715.000001B589800000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://az815563.vo.msecnd.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://canary.designerapp.
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.designerapp.osi.office.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designer-mobile
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/fonts
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-assets
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-dynamic-strings
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-home-screen
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.entity.
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.hubblecontent.osi.office.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cdn.int.designerapp.osi.office.net/fonts
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/DeltaAdvisory
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/InteractiveInstallation
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/https://config.edge.skype.com/config/v1/780dddc8-18a1-5781-8
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.net/config/v1/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://consent.config.office.com/consentcheckin/v1.0/consents
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://consent.config.office.com/consentweb/v1.0/consents
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cortana.ai
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cortana.ai/api
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://cr.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://d.docs.live.net
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://designerapp.azurewebsites.net
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://designerappservice.officeapps.live.com
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dev.cortana.ai
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://devnull.onenote.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://directory.services.
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ecs.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ecs.office.com/config/v1/Designer
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://edge.skype.com/registrar/prod
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://edge.skype.com/rps
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/v2.1601652342626
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://fpastorage.cdn.office.net/%s
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://fpastorage.cdn.office.net/firstpartyapp/addins.xml
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://graph.ppe.windows.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://graph.windows.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://graph.windows.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/pivots/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?secureurl=1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ic3.teams.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://inclient.store.office.com/gyro/client
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://invites.office.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://lifecycle.office.com
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.microsoftonline.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.microsoftonline.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.microsoftonline.com/organizations
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.windows.local
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local/
Source: OUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drString found in binary or memory: https://login.windows.localR
Source: OUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drString found in binary or memory: https://login.windows.localnullD
Source: OUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drString found in binary or memory: https://login.windows.localnullros
Source: OUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drString found in binary or memory: https://login.windows.localtloR
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, App1728588612068758900_867B4047-AB37-4B0B-A391-40CA9AEDCC2D.log.0.drString found in binary or memory: https://login.windows.net
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://make.powerautomate.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://management.azure.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://management.azure.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messagebroker.mobile.m365.svc.cloud.microsoft
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.action.office.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.action.office.com/setcampaignaction
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.action.office.com/setuseraction16
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.engagement.office.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.engagement.office.com/campaignmetadataaggregator
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.lifecycle.office.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.lifecycle.office.com/getcustommessage16
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://messaging.office.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://mss.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://my.microsoftpersonalcontent.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ncus.contentsync.
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ncus.pagecontentsync.
Source: HxAccounts.exe, 0000000B.00000002.3585525319.000001B589813000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nexus.officeapps.live.com0
Source: HxAccounts.exe, 0000000B.00000002.3585525319.000001B589813000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nexusrules.officeapps.live.com07
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ods-diagnostics-ppe.trafficmanager.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://officeapps.live.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://officepyservice.office.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://officepyservice.office.net/service.functionality
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://onedrive.live.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://otelrules.azureedge.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://otelrules.svc.static.microsoft
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office365.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office365.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://outlook.office365.com/connectors
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://powerlift.acompli.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://pushchannel.1drv.ms
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://res.cdn.office.net
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://res.cdn.office.net/polymer/models
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://safelinks.protection.outlook.com/api/GetPolicy
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://service.officepy.microsoftusercontent.com/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://service.powerapps.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://settings.outlook.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://staging.cortana.ai
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://substrate.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://substrate.office.com/Notes-Internal.ReadWrite
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://tasks.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://templatesmetadata.office.net/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://useraudit.o365auditrealtimeingestion.manage.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://webshell.suite.office.com
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://word-edit.officeapps.live.com/we/rrdiscovery.ashx
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://wus2.contentsync.
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://www.odwebp.svc.ms
Source: 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drString found in binary or memory: https://www.yammer.com
Source: HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com
Source: HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com/
Source: HxAccounts.exe, 0000000B.00000002.3589072504.000001B590CF4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com5
Source: classification engineClassification label: clean2.winEML@5/22@0/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmpJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etlJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\phish_alert_sp2_2.0.0.0 (13).eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "275573E4-4E3A-44CF-9503-868017FC0EFD" "DC9DDA95-057A-40A5-91CF-1110D1B5CBAE" "4132" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: unknownProcess created: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca
Source: unknownProcess created: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe" -ServerName:microsoft.windowslive.manageaccounts.AppXdbf3yp5apt3t7q877db3gnz5zqpf71zj.mca
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "275573E4-4E3A-44CF-9503-868017FC0EFD" "DC9DDA95-057A-40A5-91CF-1110D1B5CBAE" "4132" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: microsoft.applications.telemetry.windows.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msoimm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso40uiimm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso30imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.word.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso98imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso50imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso98imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.model.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxcomm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.networking.hostname.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.diagnostics.telemetry.platformtelemetryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.view.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.hxshared.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.viewmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: clipc.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.resources.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.hx.mail.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.hxcalendar.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.remotedesktop.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winsta.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.profile.systemid.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winrttracing.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: wininet.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: schannel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: photometadatahandler.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ploptin.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: webservices.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: userdataaccountapis.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: userdataplatformhelperutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.accountscontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: accountsrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: aphostclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: hxoutlook.model.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: microsoft.applications.telemetry.windows.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mso30imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: office.ui.xaml.hxaccounts.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: hxcomm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.networking.hostname.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.system.diagnostics.telemetry.platformtelemetryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.accountscontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vaultcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: winrttracing.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: hxoutlook.resources.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: wuceffects.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32Jump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: phish_alert_sp2_2.0.0.0 (13).emlStatic file information: File size 1865992 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData 1Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeWindow / User API: threadDelayed 2329Jump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeWindow / User API: threadDelayed 414Jump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe TID: 6316Thread sleep count: 2329 > 30Jump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe TID: 6316Thread sleep count: 414 > 30Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformationJump to behavior
Source: phish_alert_sp2_2.0.0.0 (13).emlBinary or memory string: CmcoAYn+RKIeSME8plZPly02FuFYBoHGFSw8OUpbqg1if5Spq1HCRKjIFNnJcH8kxI8lOX2M64kY
Source: phish_alert_sp2_2.0.0.0 (13).emlBinary or memory string: 53xJVExmQwHgfSjTKIo1ihoFqKGqDuOIkpAuT59rbvOZtpmYz0QT0F9qirPc5J1cTss7sGr3FuMU
Source: settings.dat.5.drBinary or memory string: VMware, Inc. VMware20,1
Source: phish_alert_sp2_2.0.0.0 (13).emlBinary or memory string: E7bsFP+OmE47SAKgjRl7RBbJ8JRBWs/qpS53WSKD5pkyPFaa4bEg2uQEmUipJ+bzcsc1ILxir/CH
Source: phish_alert_sp2_2.0.0.0 (13).emlBinary or memory string: qJ1qL1AJuyF84yvu+LUhYbbiOmxcAap7I2dxKzqPlCgtqEMupWyqIFPp9Sa+n2wqEozxDY2GwGjV
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Modify Registry
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Virtualization/Sandbox Evasion
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS1
Application Window Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets14
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1531116 Sample: phish_alert_sp2_2.0.0.0 (13).eml Startdate: 10/10/2024 Architecture: WINDOWS Score: 2 5 OUTLOOK.EXE 95 118 2->5         started        7 HxOutlook.exe 62 18 2->7         started        9 HxAccounts.exe 1 2->9         started        process3 11 ai.exe 5->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://api.diagnosticssdf.office.com0%URL Reputationsafe
https://login.microsoftonline.com/0%URL Reputationsafe
https://shell.suite.office.com:14430%URL Reputationsafe
https://designerapp.azurewebsites.net0%URL Reputationsafe
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize0%URL Reputationsafe
https://autodiscover-s.outlook.com/0%URL Reputationsafe
https://useraudit.o365auditrealtimeingestion.manage.office.com0%URL Reputationsafe
https://outlook.office365.com/connectors0%URL Reputationsafe
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://api.addins.omex.office.net/appinfo/query0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/tenantassociationkey0%URL Reputationsafe
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://lookup.onenote.com/lookup/geolocation/v10%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/imports0%URL Reputationsafe
https://cloudfiles.onenote.com/upload.aspx0%URL Reputationsafe
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://entitlement.diagnosticssdf.office.com0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%URL Reputationsafe
https://canary.designerapp.0%URL Reputationsafe
https://ic3.teams.office.com0%URL Reputationsafe
https://www.yammer.com0%URL Reputationsafe
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies0%URL Reputationsafe
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive0%URL Reputationsafe
https://cr.office.com0%URL Reputationsafe
https://messagebroker.mobile.m365.svc.cloud.microsoft0%URL Reputationsafe
https://portal.office.com/account/?ref=ClientMeControl0%URL Reputationsafe
https://clients.config.office.net/c2r/v1.0/DeltaAdvisory0%URL Reputationsafe
https://edge.skype.com/registrar/prod0%URL Reputationsafe
https://graph.ppe.windows.net0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://tasks.office.com0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%URL Reputationsafe
https://sr.outlook.office.net/ws/speech/recognize/assistant/work0%URL Reputationsafe
https://api.scheduler.0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://api.aadrm.com0%URL Reputationsafe
https://edge.skype.com/rps0%URL Reputationsafe
https://globaldisco.crm.dynamics.com0%URL Reputationsafe
https://messaging.engagement.office.com/0%URL Reputationsafe
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://api.diagnosticssdf.office.com/v2/feedback0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/groups0%URL Reputationsafe
https://web.microsoftstream.com/video/0%URL Reputationsafe
https://api.addins.store.officeppe.com/addinstemplate0%URL Reputationsafe
https://graph.windows.net0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://analysis.windows.net/powerbi/api0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://substrate.office.com0%URL Reputationsafe
https://outlook.office365.com/autodiscover/autodiscover.json0%URL Reputationsafe
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios0%URL Reputationsafe
https://consent.config.office.com/consentcheckin/v1.0/consents0%URL Reputationsafe
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices0%URL Reputationsafe
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json0%URL Reputationsafe
https://safelinks.protection.outlook.com/api/GetPolicy0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/0%URL Reputationsafe
http://weather.service.msn.com/data.aspx0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://officepyservice.office.net/service.functionality0%URL Reputationsafe
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks0%URL Reputationsafe
https://templatesmetadata.office.net/0%URL Reputationsafe
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios0%URL Reputationsafe
https://messaging.lifecycle.office.com/0%URL Reputationsafe
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml0%URL Reputationsafe
https://mss.office.com0%URL Reputationsafe
https://pushchannel.1drv.ms0%URL Reputationsafe
https://management.azure.com0%URL Reputationsafe
https://outlook.office365.com0%URL Reputationsafe
https://login.windows.net0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://incidents.diagnostics.office.com0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/ios0%URL Reputationsafe
https://make.powerautomate.com0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://login.microsoftonline.com/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://shell.suite.office.com:14430C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://designerapp.azurewebsites.net0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://autodiscover-s.outlook.com/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://useraudit.o365auditrealtimeingestion.manage.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://outlook.office365.com/connectors0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://cdn.entity.5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://api.addins.omex.office.net/appinfo/query0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://clients.config.office.net/user/v1.0/tenantassociationkey5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://powerlift.acompli.net0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://rpsticket.partnerservices.getmicrosoftkey.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://lookup.onenote.com/lookup/geolocation/v10C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://cortana.ai5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://api.powerbi.com/v1.0/myorg/imports0C854535-0377-48C9-AB5E-1A7356CF1588.0.drfalse
  • URL Reputation: safe
unknown
https://cloudfiles.onenote.com/upload.aspx0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://entitlement.diagnosticssdf.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://api.aadrm.com/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://ofcrecsvcapi-int.azurewebsites.net/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://canary.designerapp.0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://ic3.teams.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
  • URL Reputation: safe
unknown
https://config.edge.skype.net/config/v1/HxAccounts.exe, 0000000B.00000002.3585636692.000001B589851000.00000004.00000020.00020000.00000000.sdmpfalse
    unknown
    https://www.yammer.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
    • URL Reputation: safe
    unknown
    https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
    • URL Reputation: safe
    unknown
    https://api.microsoftstream.com/api/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
      unknown
      https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
      • URL Reputation: safe
      unknown
      https://cr.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
      • URL Reputation: safe
      unknown
      https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
        unknown
        https://messagebroker.mobile.m365.svc.cloud.microsoft0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
        • URL Reputation: safe
        unknown
        https://otelrules.svc.static.microsoft0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          unknown
          https://portal.office.com/account/?ref=ClientMeControl0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://clients.config.office.net/c2r/v1.0/DeltaAdvisory0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://edge.skype.com/registrar/prod0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://graph.ppe.windows.net0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://res.getmicrosoftkey.com/api/redemptionevents0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://powerlift-frontdesk.acompli.net0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://tasks.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
          • URL Reputation: safe
          unknown
          https://login.windows.localROUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drfalse
            unknown
            https://officeci.azurewebsites.net/api/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
            • URL Reputation: safe
            unknown
            http://pki-crl.symauth.com/ca_7a5c3a0c73117406add19312bc1bc23f/LatestCRL.crl07olk6C0A.tmp.0.drfalse
              unknown
              https://sr.outlook.office.net/ws/speech/recognize/assistant/work5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
              • URL Reputation: safe
              unknown
              https://xsts.auth.xboxlive.com5HxAccounts.exe, 0000000B.00000002.3589072504.000001B590CF4000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                https://login.windows.localtloROUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drfalse
                  unknown
                  https://api.scheduler.0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                  • URL Reputation: safe
                  unknown
                  https://my.microsoftpersonalcontent.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                    unknown
                    https://store.office.cn/addinstemplate0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                    • URL Reputation: safe
                    unknown
                    https://api.aadrm.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                    • URL Reputation: safe
                    unknown
                    https://edge.skype.com/rps0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                    • URL Reputation: safe
                    unknown
                    https://outlook.office.com/autosuggest/api/v1/init?cvid=0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      unknown
                      https://globaldisco.crm.dynamics.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://messaging.engagement.office.com/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://dev0-api.acompli.net/autodetect0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://www.odwebp.svc.ms0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://api.diagnosticssdf.office.com/v2/feedback5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://api.powerbi.com/v1.0/myorg/groups0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://web.microsoftstream.com/video/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://api.addins.store.officeppe.com/addinstemplate0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://graph.windows.net0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://dataservice.o365filtering.com/5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                      • URL Reputation: safe
                      unknown
                      https://login.windows.localnullDOUTLOOK_16_0_16827_20130-20241010T1530110586-4132.etl.0.drfalse
                        unknown
                        https://officesetup.getmicrosoftkey.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                        • URL Reputation: safe
                        unknown
                        https://analysis.windows.net/powerbi/api5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                        • URL Reputation: safe
                        unknown
                        https://prod-global-autodetect.acompli.net/autodetect0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                        • URL Reputation: safe
                        unknown
                        https://substrate.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                        • URL Reputation: safe
                        unknown
                        https://login.windows.net/HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                          unknown
                          https://outlook.office365.com/autodiscover/autodiscover.json0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                          • URL Reputation: safe
                          unknown
                          https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                          • URL Reputation: safe
                          unknown
                          https://consent.config.office.com/consentcheckin/v1.0/consents0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                          • URL Reputation: safe
                          unknown
                          https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                          • URL Reputation: safe
                          unknown
                          https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                          • URL Reputation: safe
                          unknown
                          https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                          • URL Reputation: safe
                          unknown
                          https://d.docs.live.net0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                            unknown
                            https://safelinks.protection.outlook.com/api/GetPolicy0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                            • URL Reputation: safe
                            unknown
                            https://ncus.contentsync.0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                            • URL Reputation: safe
                            unknown
                            https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              unknown
                              https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              http://weather.service.msn.com/data.aspx0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://apis.live.net/v5.0/HxAccounts.exe, 0000000B.00000002.3585589019.000001B58982B000.00000004.00000020.00020000.00000000.sdmp, 0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://officepyservice.office.net/service.functionality0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://templatesmetadata.office.net/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://messaging.lifecycle.office.com/0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://mss.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://pushchannel.1drv.ms0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                              • URL Reputation: safe
                              unknown
                              https://xsts.auth.xboxlive.com/HxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                                unknown
                                https://management.azure.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                                • URL Reputation: safe
                                unknown
                                https://outlook.office365.com5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                                • URL Reputation: safe
                                unknown
                                https://login.windows.netHxAccounts.exe, 0000000B.00000002.3589021555.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3217980483.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.3014714983.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000003.2626277091.000001B590CBC000.00000004.00000020.00020000.00000000.sdmp, App1728588612068758900_867B4047-AB37-4B0B-A391-40CA9AEDCC2D.log.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://wus2.contentsync.0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                                • URL Reputation: safe
                                unknown
                                https://incidents.diagnostics.office.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                                • URL Reputation: safe
                                unknown
                                https://clients.config.office.net/user/v1.0/ios5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                                • URL Reputation: safe
                                unknown
                                https://make.powerautomate.com0C854535-0377-48C9-AB5E-1A7356CF1588.0.dr, 5F09DA67-81DC-49E0-8AB9-284A0013D796.5.drfalse
                                • URL Reputation: safe
                                unknown
                                No contacted IP infos
                                Joe Sandbox version:41.0.0 Charoite
                                Analysis ID:1531116
                                Start date and time:2024-10-10 21:29:08 +02:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:0h 5m 7s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:default.jbs
                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                Number of analysed new started processes analysed:12
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • EGA enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Sample name:phish_alert_sp2_2.0.0.0 (13).eml
                                Detection:CLEAN
                                Classification:clean2.winEML@5/22@0/0
                                Cookbook Comments:
                                • Found application associated with file extension: .eml
                                • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, HxTsr.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                                • Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.113.194.132, 52.109.76.243, 2.19.126.160, 2.19.126.151, 40.74.98.195, 13.107.42.16
                                • Excluded domains from analysis (whitelisted): omex.cdn.office.net, config.edge.skype.com.trafficmanager.net, slscr.update.microsoft.com, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, config-edge-skype.l-0007.l-msedge.net, officeclient.microsoft.com, l-0007.l-msedge.net, config.edge.skype.com, a1864.dscd.akamai.net, ecs.office.com, self-events-data.trafficmanager.net, client.wns.windows.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, onedscolprdjpw03.japanwest.cloudapp.azure.com, outlookmobile-office365-tas.msedge.net, s-0005.s-msedge.net, l-0007.config.skype.com, config.officeapps.live.com, osiprod-neu-buff-azsc-000.northeurope.cloudapp.azure.com, settings.data.microsoft.com, ecs.office.trafficmanager.net, omex.cdn.office.net.akama
                                • Report size exceeded maximum capacity and may have missing behavior information.
                                • Report size getting too big, too many NtOpenKey calls found.
                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                • Report size getting too big, too many NtQueryAttributesFile calls found.
                                • Report size getting too big, too many NtQueryValueKey calls found.
                                • VT rate limit hit for: phish_alert_sp2_2.0.0.0 (13).eml
                                No simulations
                                InputOutput
                                URL: PDF document Model: jbxai
                                {
                                "brands":["Skillsoft"],
                                "text":"INVOICE Client No: 20-1169 For Professional and Consulting Services Rendered In Connection With the Following: DESCRIPTION QTY RATE AMOUNT Data entry,
                                 Data Analytics,
                                 Document Verifications,
                                 Financial reports management,
                                 Verification services. Consulting fees for additional services incurred due to IRS requirement to report partner capital accounts on tax basis. Time includes recalculation of partner capital accounts and proper basis tracking. Innovation,
                                 transformation,
                                 and leadership deliver strategy and implementation from a business and technology view to help you lead in the markets where you compete. Additional fees for time incurred to update From 1065 after new trial balance was received. SUBTOTAL TAX TOTAL BALANCE DUE $8,
                                600.95",
                                "contains_trigger_text":false,
                                "trigger_text":"",
                                "prominent_button_name":"unknown",
                                "text_input_field_labels":"unknown",
                                "pdf_icon_visible":false,
                                "has_visible_captcha":false,
                                "has_urgent_text":false,
                                "has_visible_qrcode":false}
                                No context
                                No context
                                No context
                                No context
                                No context
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):231348
                                Entropy (8bit):4.384060124951261
                                Encrypted:false
                                SSDEEP:1536:WPYL+qgsY6fQO20BngsSWNcAz79ysQqt2NKfLqoQA7rcm0FvcJJyLjBoNJpH+dFO:TLgf/Sg2miGu2cqoQsrt0FvN5ug8EYb
                                MD5:D959295194EAEDFA240A4D466BA00A2C
                                SHA1:60B0312DBD1A75F5236BE4B16629C181A1DCAF55
                                SHA-256:25DADCB263AC9BBA89C8C3716CE999E48D620D1A0214BD5DBEFF4C2B83E936A6
                                SHA-512:10918A5275438F4CAB801A75AFF9D33D91DECCD46549031B5642D21A97851DB50A7A78807FF3FD566EA60E2B416EBB7E0D8941CCF937BE1D16C202356CD8AA0A
                                Malicious:false
                                Reputation:low
                                Preview:TH02...... ....J.......SM01X...,.......J...........IPM.Activity...........h...............h............H..h..o......75....h............H..h\eng ...r\Ap...h.[..0.....o....ho12............h........_`.k...h.32.@...I.6w...h....H...8..k...0....T...............d.........2h...............kU.I...........!h.............. h.}......0.o...#h....8.........$h........8....."h.R.......M....'h..............1ho12.<.........0h....4.....k../h....h......kH..h0...p.....o...-h .......\.o...+h.12.......o................. ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000.GwwMicrosoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:ASCII text, with very long lines (65536), with no line terminators
                                Category:dropped
                                Size (bytes):322260
                                Entropy (8bit):4.000299760592446
                                Encrypted:false
                                SSDEEP:6144:dztCFLNyoAHq5Rv2SCtUTnRe4N2+A/3oKBL37GZbTSB+pMZIrh:HMLgvKz9CtgRemO3oUHi3SBSMZIl
                                MD5:CC90D669144261B198DEAD45AA266572
                                SHA1:EF164048A8BC8BD3A015CF63E78BDAC720071305
                                SHA-256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
                                SHA-512:16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC
                                Malicious:false
                                Reputation:high, very likely benign file
                                Preview:51253fe60063c31af0d295afb42228b0:v2:2:1:1590:2:8479:76bd602437550e98c9043d06a55186ab7d95dea5a0e935a599f73e62a8c9b158e0afcb19351f6c353940c06a38172b94d18c02cf92bb8a80184eccca0392b259ab3e71dae73e491c7941997cb36ad4a198661f622dad478d840f66d530a0dde78acea3367f91fff62fbb3dc18faff0c708ad30edef5bea8b22c5fd782b770d8993386eaa784fd19a3c3e1db3b537b1a94d3d4fbd46f8df8fddf6d16611969fe0a97c50e0f3ac24750c93257cf5c161184aa7385800c87d803b339632a3d8ec7fe17a0afd83ce9e9d0e3f7b8d579637928a811f1f7e6d1887df2ddc7d4f752c4d600235e426c92c7bf8a1362f95457998cc0e5d4261f0efa4fada0f866dbcefb407dacab7a2914e91c2f08200f38c2d9d621962145b1464b0f204b326118a53ecdcab22bff005fdd5257c99a6dc51ac0600a49f2ef782396987e78c08b846dad5db55e8ccefffc64863bc2c3e90b95a09d25d0814a848c98fe01a82d4e30e6682dd546e12c45ca0d280a45295ab4bd632dafb070edfdc3c9e38313d5aeb195972986f8011b66817028fd8c78b67a0ac7e780eecc3fb6a31f5a025b8a9a3db278a98c0696aeaac739b18688b0f9c7d751bba02cc5f4e41853fb119b3c0c915059aaa92971244a1989124f12881ca88e6410df70b793a2c3a736ff4
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:ASCII text, with no line terminators
                                Category:dropped
                                Size (bytes):10
                                Entropy (8bit):2.4464393446710155
                                Encrypted:false
                                SSDEEP:3:LNQfTL:hgTL
                                MD5:8C35E388C408F1905175C6F1D926EA21
                                SHA1:6F9AD88D658441C451623FE639108DB20F8C5209
                                SHA-256:9AAEF46F1BEE05D28D69147131121C6BA730EFDC4AE5F7EF4BF58BB81215FD6C
                                SHA-512:950BAAAEDA56ECAC67AA26BFBA91DBBA7D95031A7468B07F4752DDCFEB7E982C30DFB822102EA09E925FCE348DA139BD21972F8D6BD0700356E4A6FCB1073594
                                Malicious:false
                                Reputation:low
                                Preview:1728588617
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):177810
                                Entropy (8bit):5.2871985454092645
                                Encrypted:false
                                SSDEEP:1536:ai2XfRAqcbH41gwEwLe7HW8bM/o/NMdcAZl1p5ihs7EXXPEAD2Odavo:vCe7HW8bM/o/TXsk4o
                                MD5:CB08901D7E204DADE848B4213E4EE135
                                SHA1:29E1D2F94E3E6002D7EB21EF8CFA5254F5C5F58B
                                SHA-256:7C80F3D90A2C549CC816A1682302A2CAF2B1F1BF8AD8DAEA4C40033136C6626C
                                SHA-512:7A43DBE72665582F8399A2A967D2019E44C28360742757246B53678F5703BAADE903D1CACE3528E58B6C09C6678D5D737DF0F5E1CFF5DE508BF8E6664ED46740
                                Malicious:false
                                Reputation:low
                                Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-10-10T19:30:14">.. Build: 16.0.18124.40132-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:SQLite 3.x database, last written using SQLite version 3023002, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                                Category:dropped
                                Size (bytes):4096
                                Entropy (8bit):0.09216609452072291
                                Encrypted:false
                                SSDEEP:3:lSWFN3l/klslpF/4llfll:l9F8E0/
                                MD5:F138A66469C10D5761C6CBB36F2163C3
                                SHA1:EEA136206474280549586923B7A4A3C6D5DB1E25
                                SHA-256:C712D6C7A60F170A0C6C5EC768D962C58B1F59A2D417E98C7C528A037C427AB6
                                SHA-512:9D25F943B6137DD2981EE75D57BAF3A9E0EE27EEA2DF19591D580F02EC8520D837B8E419A8B1EB7197614A3C6D8793C56EBC848C38295ADA23C31273DAA302D9
                                Malicious:false
                                Reputation:high, very likely benign file
                                Preview:SQLite format 3......@ .......................................................................... .....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:SQLite Rollback Journal
                                Category:dropped
                                Size (bytes):4616
                                Entropy (8bit):0.13760166725504608
                                Encrypted:false
                                SSDEEP:3:7FEG2l+7p1l4/FllkpMRgSWbNFl/sl+ltlslVlllfllB7n:7+/l0Kg9bNFlEs1EP/9
                                MD5:6ECD27C4F2CE89B87C49355CA17C4375
                                SHA1:625D28767BCFD867361E2981FF6DFA1E191C3D9B
                                SHA-256:A0ED7E653587C210740856820FAF78A5AA5E6E69C1DAA27854DB47F98368099F
                                SHA-512:F2D9AE1CE440303475A0E2327B288A02189F470C5E4A61EA7FCA34F6B5C72A5C09262EE45680DCB9ACEEE552F335923B427D87C67B19455867DD2743E25254B6
                                Malicious:false
                                Preview:.... .c.......V.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ .......................................................................... .................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):32768
                                Entropy (8bit):0.04458434447999482
                                Encrypted:false
                                SSDEEP:6:G4l2ESHB2DVt4l2ESHB2D20L9XXPH4l942U:l27Hyto27H65A0
                                MD5:1C966BD66950193DD9584788D0254E53
                                SHA1:D41C395455D8D554F03B75A309D9B21385AFD9B9
                                SHA-256:CA41920EABA271B0428044D960249427AFC721CBBB41719492DC03792779EECE
                                SHA-512:E04E10AD93AA50D7B7B86173ED8D2FEB730D39D3386E798AD616741920260422D54B5364B43157171026F570488BBC88AF4703A26A4AB02151C79D0958E45A8E
                                Malicious:false
                                Preview:..-...........................>.V.{.a..Q.L.-...-...........................>.V.{.a..Q.L.-.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:SQLite Write-Ahead Log, version 3007000
                                Category:modified
                                Size (bytes):45352
                                Entropy (8bit):0.39484083729385305
                                Encrypted:false
                                SSDEEP:24:KAmZDECEQ3zRDNAsUll7DBtDi4kZERDssyzqt8VtbDBtDi4kZERD5f:NmZECEQ15AsUll7DYMozO8VFDYM
                                MD5:A631F978C3206D24EFDBEA3251DF0D28
                                SHA1:7E9434D8A11E29E9BACEBA1497A529161D1C9229
                                SHA-256:26A33FA99F8033532DAA4F33541957F9507058CB20AF4C1F0691CFC7CA0073A4
                                SHA-512:7F71182CF795CB7E1F592C98D9EF2C4E30C01D1A7D2E2D85BBAC96D64C2316B6A843565DCA7E19C1E16E720702F0A63E4D508010EE7C9ECC24D4F7FDEFEBADE3
                                Malicious:false
                                Preview:7....-...........V.{.a.P.Y..f.(.........V.{.a.wD.....&SQLite format 3......@ .......................................................................... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                                File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):174570
                                Entropy (8bit):5.290046308985573
                                Encrypted:false
                                SSDEEP:1536:ii2XPRAqIbz41gwErLe7HW8bM/hMdcAZl1p5ihs7gXXWEIJROdYvo:ZHe7HW8bM/FXTZWo
                                MD5:50137F203E9C9161EDC28B8E62767C7D
                                SHA1:BACD590DADE1FE3CF994C36113AAFC7638479295
                                SHA-256:1AAB3195125E981E785E19B8EB666B17E5CE2D80104896041450D36EC64B6EFC
                                SHA-512:92D1C56E7C1A44DF9BA745FB89D1E4DBD89B29206BDD1793AA8088B7F8A84C32D7E306C2AC2B9E24EE569FDA184485930F9681A7E0BD44F9E037067125EE32BD
                                Malicious:false
                                Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-10-10T19:30:43">.. Build: 16.0.18124.40132-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                                Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):65536
                                Entropy (8bit):0.12700381634716104
                                Encrypted:false
                                SSDEEP:12:BtWxeXXPqF69Fq5DCrUdK8C/Q1UMCl2M+aqc2EfK8ClXH:nWW1RodKfISMClCaoEfKfl
                                MD5:E4ABCB93D51C0543D219E1419E6095BB
                                SHA1:FA4167AB5E66FF32A90F41F1D19654D0E9DD6D9F
                                SHA-256:62D59F746891A389BCB4790D51B7755552B32A1ADBCCB15AF63B62BBD7DAB090
                                SHA-512:B8383AEC029EE72F08BEAAE29FC87FB1DD640F9E5B846201322A1421128ED1CC9DC3529A9C95E0FD15282E7F40B88E36CCB83E2150825D9F2F3A17297490B339
                                Malicious:false
                                Preview:............................................................................j..............%....................eJ..............Zb..............................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................0j..N............*.J...........H.x.A.c.c.o.u.n.t.s.A.l.w.a.y.s.O.n.L.o.g.g.e.r...C.:.\.U.s.e.r.s.\.e.n.g.i.n.e.e.r.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.a.c.k.a.g.e.s.\.m.i.c.r.o.s.o.f.t...w.i.n.d.o.w.s.c.o.m.m.u.n.i.c.a.t.i.o.n.s.a.p.p.s._.8.w.e.k.y.b.3.d.8.b.b.w.e.\.L.o.c.a.l.S.t.a.t.e.\.H.x.A.c.c.o.u.n.t.s.A.l.w.a.y.s.O.n.L.o.g...e.t.l.............P.P.........>C.%............................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):65536
                                Entropy (8bit):0.12095834830350193
                                Encrypted:false
                                SSDEEP:12:6HPqF69Fq5DCrI8CXQ1UMCl2M+aqc2EOCkf:o1RcfgSMClCaoEFk
                                MD5:ED4AB8985AE1FAFD9963067EBC672C22
                                SHA1:08AD2D0BFCB0F0140DCCC5E11F1671F3B4FF6093
                                SHA-256:E4CED9E01D006D50E70A89313B11016ACCD4D6EB395EE71DE1C4A78E4DABD90F
                                SHA-512:A959ACB9BE2A9E4A2A6AC2BBA9871404C800708834F121049D3B20F05E4BBAB74854B45F0A0F7F9CD32B0E5A417D60CDEB43C22D97FBE916E5C2003CE1328DE6
                                Malicious:false
                                Preview:............................................................................H.......X...]..#....................eJ..............Zb..............................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................0j..N...............J...........H.x.M.A.l.w.a.y.s.O.n.L.o.g...C.:.\.U.s.e.r.s.\.e.n.g.i.n.e.e.r.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.a.c.k.a.g.e.s.\.m.i.c.r.o.s.o.f.t...w.i.n.d.o.w.s.c.o.m.m.u.n.i.c.a.t.i.o.n.s.a.p.p.s._.8.w.e.k.y.b.3.d.8.b.b.w.e.\.L.o.c.a.l.S.t.a.t.e.\.H.x.m.A.l.w.a.y.s.O.n.L.o.g...e.t.l.......P.P.....X...f..#....................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                                File Type:MS Windows registry file, NT/2000 or above
                                Category:dropped
                                Size (bytes):524288
                                Entropy (8bit):2.5544884816223483
                                Encrypted:false
                                SSDEEP:3072:HuANVM/E7Tc6/tCg8vNsuLwgBEjFOBZ1UoLWwPA+n6x1QWAEFRbZqO/q7pEtbygv:gFsp6BX4R4
                                MD5:6A31E537E6196DC172EABD2CDB9C2835
                                SHA1:E68408233BA75461C6368246E38BAB1B26CE44EC
                                SHA-256:0DE1842D326C196D5BC78ABBE9E068915A103E0068FC63F0ACE6CE07D23B7770
                                SHA-512:F2C9F441DF999A3AE22F86D370DD5FE0CAADE74AFE2F1D20E090274B7F4D3125F0175ADF04EC9C66DC69A0D910D254468311DF0A30B537A7649D157056D1E0F1
                                Malicious:false
                                Preview:regf........b.Q.7.................. ....P......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtm.4..J...............................................................................................................................................................................................................................................................................................................................................O.Zu........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                                File Type:MS Windows registry file, NT/2000 or above
                                Category:dropped
                                Size (bytes):286720
                                Entropy (8bit):4.021738015921241
                                Encrypted:false
                                SSDEEP:3072:MuANVM/E7Tc6/tCg8vNsuLwgBEjFOBZ1UoLWwPA+n6x1QWAEFRbZqO/q7pEtbygv:VFsp6BX4R4
                                MD5:55C06FC50782DA0DADCB156456CC476D
                                SHA1:CC8166DE93B9CBADC3F5C6628D6A5F2B1D63393E
                                SHA-256:414E170337051870471BC88CCB39131582B0E4FF89C344DA82EAF922B7444614
                                SHA-512:0EFBBC80F1313F97366CC7796D5C6BFA6B2E484AFC0DB1980C1EAC87F672DD7B33662CCA32D5E8EF9FF577C0C09F91C276E74D039CC5C30D77253F00F97676A6
                                Malicious:false
                                Preview:regf........b.Q.7.................. ....P......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtm.4..J...............................................................................................................................................................................................................................................................................................................................................H.ZuHvLE.^...........P.......W....{S.T.x>@.....P..hbin................b.Q.7..........nk,.T...7...... ...........................x...............................Test....p...sk..h...h.......t.......H...X.............4.........?.......................?....................... ... ...............YQ..fr]%dc;.............nk .t.8.J................................5..h...............8...............ConfigSettings..p...sk..x...x...9...t.......H...X.............4.........?.......................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:ASCII text, with very long lines (1979), with CRLF line terminators
                                Category:dropped
                                Size (bytes):20971520
                                Entropy (8bit):0.008684462399406312
                                Encrypted:false
                                SSDEEP:768:BMP/bTIcZx4zJ9K+juapdJUiGbbaF7oZBRdc:BMPDTPX4zP/jfbK/QcZBj
                                MD5:2D36C44E6E5CD411A450272AF36BF98D
                                SHA1:A216BA7D28592B05B58D39C2122AD4E58ED6A454
                                SHA-256:20ED08516FEC9B3CE7714296857F6A85AB6D65359A736F7B34F67AFA4C851ECA
                                SHA-512:BC7EA45E1EABB403250CB9A7BFFAB683D45C37458F5E339AC206D1E37A2F1948DA69CD1F5145B73DC286C37C994FCA0D50355432A375B91B368D041F8489B7AF
                                Malicious:false
                                Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..10/10/2024 19:30:12.132.OUTLOOK (0x1024).0x1188.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.System.GracefulExit.GracefulAppExitDesktop","Flags":33777014402039809,"InternalSequenceNumber":17,"Time":"2024-10-10T19:30:12.132Z","Data.PreviousAppMajor":16,"Data.PreviousAppMinor":0,"Data.PreviousAppBuild":16827,"Data.PreviousAppRevision":20130,"Data.PreviousSessionId":"874161A5-CB1D-43FA-AA1C-AE056610619A","Data.PreviousSessionInitTime":"2024-10-10T19:29:48.531Z","Data.PreviousSessionUninitTime":"2024-10-10T19:29:51.687Z","Data.SessionFlags":2147483652,"Data.InstallMethod":0,"Data.OfficeUILang":1033,"Data.PreviousBuild":"Unknown","Data.EcsETag":"\"\"","Data.ProcessorArchitecture":"x64"}...10/10/2024 19:30:12.211.OUTLOOK (0x1024).0xC50.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":22,
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):20971520
                                Entropy (8bit):0.0
                                Encrypted:false
                                SSDEEP:3::
                                MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                Malicious:false
                                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):135168
                                Entropy (8bit):4.668794695101362
                                Encrypted:false
                                SSDEEP:768:BvtsieW9b9S4lZ+egQ9UGt4IV/ck8TejQGB7ODKDiyJUR+ZX7MDzAiaYZMZ:A4rJL9UGN2GB7OB0UR+ZXY5w
                                MD5:721D9759B60C28278A2D81735F8E546D
                                SHA1:5D9EFA65AD34867860F815214D3E036F4E659F14
                                SHA-256:536001370C0E8535F7BD1230853237B2D62472B24D6081D42E9517964F0FF414
                                SHA-512:69891D3CE240094E2CCBE512FE64BF7A1D8AA22512E0C49610E943D46E4056DF04A061EF652917AE060DE55E1B92DAC98490989DDA1A430AD6024D2DAA70E1A8
                                Malicious:false
                                Preview:............................................................................h.......$.......J...................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................0j..N...............J...........v.2._.O.U.T.L.O.O.K.:.1.0.2.4.:.a.d.5.a.b.7.a.f.2.2.0.f.4.c.3.a.9.0.2.a.9.7.4.f.d.4.7.9.d.d.8.5...C.:.\.U.s.e.r.s.\.e.n.g.i.n.e.e.r.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.1.0.1.0.T.1.5.3.0.1.1.0.5.8.6.-.4.1.3.2...e.t.l.......P.P.....$.......J...................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):1002964
                                Entropy (8bit):7.963738375904716
                                Encrypted:false
                                SSDEEP:12288:No8Ed9Up6BwgjJYAQO6O5nAdkKJPu/gZhcEw81:No8U9UpuwgjKAQO6O5IkK2gZhcvW
                                MD5:2F5B72CDA832CBCB7735288F86DF2206
                                SHA1:C9240938BB67B4F229F13252692CBB3366D5C91D
                                SHA-256:AF95FB7558C2A727C06D43DFF64F4FDB3A880F9798E0AF9B3323995721056A58
                                SHA-512:4F9EB8F2794C25F517630E136CEC66120AB24909DF6584555C5D2D30D467CD7E4813C5B24DDF18D92DB71D9394FD40A71E3F0335E311AE95BC0D698DB4E1AD65
                                Malicious:false
                                Preview:R.vv.f..b.|.....d.5..:R.h._..fkq.?..?.|...........@X.HFPL.[....*G.xGtW.D=..-.C..."./.J.q..L\.!5......a..'. J.../JIy.A.x.;.8...\........F.... .....%...,t.@..W...F.(..G.....!.......?vZ....>_..b[..........no....C.9D.~G......3.z~..M...&.)1.+5.}....,Z.;.i}.R.E....e..M.m....7....Z....o......+~.^;..M...}.f....'..l...=...i[.n..?.y......7.N...d..~.}.<.w.<5.. 07..A....7...&...v.o.E.U..,.l/.'..03.....E......zP.3....(.c0..N........b..g..J..........&.]^...47....fh..;.......c..4.Kw|.Q..Q.74].)h.9.l\V.....p......5Y1)..j.....+....6Q..D.q9uZ..[._s..I...d.....{.W./....q..{..9Hc.*..s..V..K..y.8.8.}.J....58$.g.+.3...L..E&S.:.1.].Vk.5.jo.P/OQ....).e.2y....=.{#N.E.z-7M..\kY....+K-.'.K...Wv....&..../.C..W..#C..@.......2...-.,a$.R...!'.F..+i...-.Yl4.s0ufgj(...B..2....:.I..AC.4t..^...........K.....t...S.9....{...TK.i(.9...._.....o..]'z...m..m..-m.s.Y..A.....g`.[o...W.|....w....t..<G...T.PkT."...Px.%.^.V.>*}ExG.4.3<p..@..ZK..>...H].Y.....u.{...S.S.'
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):87932
                                Entropy (8bit):7.937546765484504
                                Encrypted:false
                                SSDEEP:1536:g8DAOu+UascrqQ1Ckz6h7hJU/SQoocwBCXHImbdfzW65V7Oqc+NP5qcc:g0hUascmQh2h7nU/SQqwCfhfzB5OqcSu
                                MD5:3365865014EB4401F729D363B7313EE5
                                SHA1:DF2B62D7FA430D08E72C0DA1F180311EDD809C67
                                SHA-256:CDF921BD4F22F1F424FA3E290A426311BA5AF84FBDDA99AC08131ED3DCB652C3
                                SHA-512:56BF8730050F9D1FE795F4DE2E361C8ECDC0FB68304DBD2B20CC8366C79BC139CFE9663FA83D32A597BFF74B133422CB8833FF937D9F2EB495D368753445AAA4
                                Malicious:false
                                Preview: 0 obj.<</BaseFont /Helvetica /Encoding /WinAnsiEncoding /Subtype /Type1 /Type /Font >>.endobj..1123 0 obj.<</ByteRange [0 127526 139796 1019] /Contents (0...*.H..\r.....0....1.0...+......0...*.H..\r.......0...0............5zF.\r....KE<..0\r..*.H..\r.....0u1.0...U....US1#0!..U.\n..Adobe Systems Incorporated1.0...U....Adobe Trust Services1"0 ..U....Adobe Product Services G30..\r220211000000Z.\r351231235959Z0~1+0\)..U..."ARE Production V8.1 G3 P24 10076851.0...U....Adobe Trust Services1#0!..U.\n..Adobe Systems Incorporated1.0...U....US0.."0\r..*.H..\r..........0..\n.......'.......\\">.H..;...+a..z!.ZC.\)..\\..6...R.2..........?..{..../......P.2@PDu...^.B...\r..S..s...\(mc....N....l.....D..$.9..O..0Js.*.F..?..4./.U.g..i..L]8.R......N.c.P..p.}. .Q........9.r0..5UV..H..\r..H......U...}\r.}!w....e.jv?..*.},tT....Z.V.h..........0...0...U.......0.0...U........0...U.%.\r0...*.H../...0....U. ...0..0....*.H../...0s0q..+.......0e.cYou are not permitted to use this License Certificate
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):30
                                Entropy (8bit):1.2389205950315936
                                Encrypted:false
                                SSDEEP:3:0XYllt:0XY
                                MD5:3CC27AD38002DB013DC33CC19365E505
                                SHA1:15DC2C3711FC00E680E52CE60C806ADB40123D60
                                SHA-256:8AE228CA4E9F2A786F236752BA30B634578E5D274DB40FCF6794424DF0382645
                                SHA-512:45F88C8D752635CACE46ADBE275DE49C86631EA6D6D5AB569BB39BA774C0BB55F742CCD7884DA24B6B05FFBC6848693D0259A10ACC3A980CAF4D91BEC9124654
                                Malicious:false
                                Preview:....Cr........................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:Composite Document File V2 Document, Cannot read section info
                                Category:dropped
                                Size (bytes):16384
                                Entropy (8bit):0.6705411275282485
                                Encrypted:false
                                SSDEEP:12:rl3baF3CqLKeTy2MyheC8T23BMyhe+S7wzQP9zNMyhe+S7xMyheCOY:raRmnq1Py961OY
                                MD5:9F14132A8B366EFD99E0C856E034B562
                                SHA1:444378F238FD782F12BFA11227BC5EA4B92B20C8
                                SHA-256:72723FF37CA5EA72A971DAA2CDB062E9C56618C890450233F975BCFE80D2701E
                                SHA-512:13049AC519C848B067EDF7D138ACF0A8B68B0D564B579C8B3BAD3AEEE889AA5EBCBD6E720768304EA44DB2C4BDC23C4FBC4293FBCE09D6AB3946A2298C918DB5
                                Malicious:false
                                Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:Microsoft Outlook email folder (>=2003)
                                Category:dropped
                                Size (bytes):2302976
                                Entropy (8bit):5.919778175351237
                                Encrypted:false
                                SSDEEP:49152:4KQ8w3Ehd5D+hsrC82EIz3zKu63u0rjXlzVUr/jijVAGz1p+zPlb/88HFpsVPQ0C:498w3ExD+yG854J0
                                MD5:5C98B0CFEC9C0967738DAC376FF32AF7
                                SHA1:1C9DF78DBAA944453E6EC16A0D8E6531DB030D40
                                SHA-256:9D7A3B643D7A2A630D956B3008E392D9FA46139A42AA77E10EE99558B1FEE604
                                SHA-512:53C4FBBF804349F58174DD7ED572EF2C6621D83DA5D389DF53C4D3E5E58C34C3402A37F0D2AAE8D7EC7913172E1B2ABE9F78A6D33B15C02AF97E4671EE149325
                                Malicious:false
                                Preview:!BDN5...SM......\...}k..........T.......d................@...........@...@...................................@...........................................................................$#......D......................R...............O...................................................................................................................................................................................................................................................................................................'u ........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                File Type:data
                                Category:dropped
                                Size (bytes):1441792
                                Entropy (8bit):7.893283859427446
                                Encrypted:false
                                SSDEEP:24576:Cv0OHoa3AyA+b3gtpkpdxhOFn29PX2v02E3qWGzJbvu73o01jX5z1Uq/jbjV1G1U:gIawB+uqdnO1gPX282E3qPtvu73o01jT
                                MD5:0D83E96C26F77B0F11EBFE7B2E39495E
                                SHA1:043B248CAD52A361A734A1BFA7F86323766297FA
                                SHA-256:9AE5F55B3FA4F556FF7A6FB1E618E392E39F6BEFD899B6443E629F650F2D8A7A
                                SHA-512:7A7FE407731405AE5C2D1EC977DFBBB3E4C9925A5E7A242D85F362CD1F8534ABAB0F0B7D7072D17A2B0DFE132B6433D883803F5B19E2A00E1EE8C5125AD94E1D
                                Malicious:false
                                Preview:...oC...%.......$...D...J.....................#.!BDN5...SM......\...}k..........T.......d................@...........@...@...................................@...........................................................................$#......D......................R...............O...................................................................................................................................................................................................................................................................................................'u ....D...J.....................#......................................................................................................................"...............................................................................H.......................".......................".......-.............................................................../...............................B.......(...............".......M.......
                                File type:RFC 822 mail, ASCII text, with very long lines (998), with CRLF line terminators
                                Entropy (8bit):6.04899921367325
                                TrID:
                                • E-Mail message (Var. 5) (54515/1) 100.00%
                                File name:phish_alert_sp2_2.0.0.0 (13).eml
                                File size:1'865'992 bytes
                                MD5:d7f52aeb8f88e6aae33568f0525ebe29
                                SHA1:34fe6187c24dcb85f8370f53d0f08626f1c72a6f
                                SHA256:5a7d3b8181f1e69ebf5c29327f089cbd87b67b1825b541ad92d3f01a7823abc5
                                SHA512:b5d4f96d8573a2dd47c4ad265be5cd8c56d732f6523ecc342a427c44400ff0715c7712f0cff36f13588d085d74c8f07807137c9cc2ccc48c66e0ea12ec61825b
                                SSDEEP:24576:XgXuQJxyluQWGzaeke/3VSyO2rX6dsJ+8fMqJOo3jEsqr46FDqvepWNzbg2tUh4X:Xq5yoGbk67prX148EiOvMM4X
                                TLSH:0285123ADD6521D63B74521FD71E2C4238AA3B4F0CC8A1E5735AC54A91ACB3B9121CBF
                                File Content Preview:Received: from CH2PR08MB10633.namprd08.prod.outlook.com (::1) by.. PH0PR08MB6488.namprd08.prod.outlook.com with HTTPS; Thu, 10 Oct 2024.. 18:24:32 +0000..Received: from PH7PR02CA0012.namprd02.prod.outlook.com.. (2603:10b6:510:33d::12) by CH2PR08MB10633.na
                                Subject:[EXTERNAL] Vendor Setup
                                From:Skillsoft Coaching Business & Financial Services LLC <k.sword.m5@kzh.biglobe.ne.jp>
                                To:Penny Shoffner <pshoffner@bellpartnersinc.com>
                                Cc:
                                BCC:
                                Date:Thu, 10 Oct 2024 18:20:13 +0000
                                Communications:
                                • CAUTION: EXTERNAL SENDER Do not click links or open attachments unless you trust the sender and know the content is safe. Hi Elizabeth, Thank you for your response. Per your instructions, I have added the Accounts Department to this email thread and forwarded the invoice for their attention. I would greatly appreciate a quick confirmation once the payment is processed. Thank you in advance for your cooperation. Regards, Mike Morris Billing Clerk Skillsoft Coaching Business & Financial Services LLC 7887 E Belleview Ave Ste 600, Greenwood Village, Colorado 80111 Email: billing@biz-skillsoft.com --- From: Elizabeth Bell <Elizabeth.Bell@bellpartnersinc.com> Date: October 4, 2024, 11:31 AM Subject: Re: Invoice 55701 To: Mike Morris <billing@biz-skillsoft.com> Cc: Lance Busch <payments@biz-skillsoft.com> Dear Mike, Thank you for reaching out. I appreciate your patience regarding the invoice. As I said, you will need to be set up as a new vendor on our side. Kindly forward the attached invoice to our Accounts Department for vendor setup and payment processing. You may include them directly in this conversation. If you havent reached out, please do. Let me know if you hear anything. Regards, Elizabeth Bell --- From: Mike Morris <billing@biz-skillsoft.com> Cc:Lance Busch <payments@biz-skillsoft.com> Date: October 3, 2024, 10:21 AM Subject: Invoice 55701 To: Elizabeth Bell <Elizabeth.Bell@bellpartnersinc.com> Hi Elizabeth Bell, Regarding our conversation about the outstanding invoice for the last sessions of services provided, kindly find attached the relevant invoice for immediate processing: Invoice 55701. The invoice was due on September 30, 2024. Please advise! Regards, Mike Morris Billing Clerk Skillsoft Coaching Business & Financial Services LLC 7887 E Belleview Ave Ste 600, Greenwood Village, Colorado 80111 Email: billing@biz-skillsoft.com
                                Attachments:
                                • bellpartnersinc.pdf
                                • W9.pdf
                                Key Value
                                Receivedfrom mail.biglobe.ne.jp by mta-snd-w04.biglobe.ne.jp with ESMTP id <20241010182015656.FAUG.83843.mail.biglobe.ne.jp@biglobe.ne.jp> for <pshoffner@bellpartnersinc.com>; Fri, 11 Oct 2024 03:20:15 +0900
                                Arc-Seali=1; s=201903; d=dkim.mimecast.com; t=1728584664; a=rsa-sha256; cv=none; b=j3OZ9qY0AdPtl2oiRJXWJh0TCpnC6Ltv4Lp/GR8iFiJdNcGaO/tm54/kOs9dqpGKq6rZmT GkXG4AMSyEvS0ROsYPbLgVbCQWAqnYqUwehUdCLhfoP9uSn4TesO6awUM53d3f1QbXZnwr p55b5LoGbD3F7gVpyveb+f55AfrDheste9JBWyEoOUO8M3ZDkIF/+hsNprKIjbswp6eiaq wc3KQ+sYK1d5ZBcsSxTpuuBcbF0CFPoXkjkV0Kmf5WCbu9VDerLSkh6I22793TpWXeLJvf H0OkiiErHPgcZFbIYDJoZmq7F8+O6pkN7R2DmWnzlhMch2QvJqc7pz1BLlMGCw==
                                Arc-Message-Signaturei=1; a=rsa-sha256; c=relaxed/relaxed; d=dkim.mimecast.com; s=201903; t=1728584664; h=from:from:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type:dkim-signature; bh=WQqFt/tI8b+XA5vH/Xfzp9SXYcwCsFzFwqzJbJfmHOo=; b=AIm7hEw8tlIhKxW4EPUxFIY7sZqhNCZYDV6nYM3rMzh+JyufOcfYrDj0DrhJg2EHRZ1/1T nChDWGJDtERRk6FUoctXVA7yhwDcZQWz/433KtJqn+f7h023cc9XpZrESQzWK5f39/Finh r9aOJ1jUFLDc2AqeAW43XfvYiBks2GDFA5n0EruoDJ5hNF3vtY7O0uIOXlR7eCywbjtehd 6Ze/Tzs1vjCW7qXxeeCeHjR8OHH2/QLFIdnIB8EQuMS+NrQSn+F9IU/YZZ+sgQ6YcvEbVI 9fonDjYDp3ASqkc0+B/hY4mX1VHI7w9vhQN9nLAMtIXDrOXSKBSP1J4E0kbaFw==
                                Arc-Authentication-Resultsi=1; relay.mimecast.com; dkim=pass header.d=kzh.biglobe.ne.jp header.s=default-1th84yt82rvi header.b="R/B+/95I"; dmarc=pass (policy=none) header.from=biglobe.ne.jp; spf=pass (relay.mimecast.com: domain of k.sword.m5@kzh.biglobe.ne.jp designates 27.86.113.49 as permitted sender) smtp.mailfrom=k.sword.m5@kzh.biglobe.ne.jp
                                Authentication-Resultsspf=pass (sender IP is 27.86.113.49) smtp.mailfrom=kzh.biglobe.ne.jp; dkim=fail (signature did not verify) header.d=kzh.biglobe.ne.jp;dmarc=pass action=none header.from=kzh.biglobe.ne.jp;compauth=pass reason=100
                                Received-SpfPass (protection.outlook.com: domain of kzh.biglobe.ne.jp designates 27.86.113.49 as permitted sender) receiver=protection.outlook.com; client-ip=27.86.113.49; helo=mta-sndfb-w01.biglobe.ne.jp; pr=C
                                Authentication-Results-Originalrelay.mimecast.com; dkim=pass header.d=kzh.biglobe.ne.jp header.s=default-1th84yt82rvi header.b="R/B+/95I"; dmarc=pass (policy=none) header.from=biglobe.ne.jp; spf=pass (relay.mimecast.com: domain of k.sword.m5@kzh.biglobe.ne.jp designates 27.86.113.49 as permitted sender) smtp.mailfrom=k.sword.m5@kzh.biglobe.ne.jp
                                X-Mc-UniqueDN28E3gwPJiLTGB3EAXWaA-1
                                FromSkillsoft Coaching Business & Financial Services LLC <k.sword.m5@kzh.biglobe.ne.jp>
                                ToPenny Shoffner <pshoffner@bellpartnersinc.com>
                                Reply-Tomyassistant@sales-selfservice.com
                                Subject[EXTERNAL] Vendor Setup
                                Message-Id<b4db8301-79be-11b2-601a-052c233e261c@kzh.biglobe.ne.jp>
                                DateThu, 10 Oct 2024 18:20:13 +0000
                                MIME-Version1.0
                                X-Biglobe-Senderk.sword.m5@kzh.biglobe.ne.jp
                                Dkim-Signaturev=1; a=rsa-sha256; c=relaxed/relaxed; d=kzh.biglobe.ne.jp; s=default-1th84yt82rvi; t=1728584421; bh=2YgX/cI2rf6tGF57D756Hac5bHpMYNzmS5qW5LJ0obQ=; h=From:To:Reply-To:Subject:Date; b=R/B+/95IayqhkHLIEoI+XffBcLAj3IBK2qPc//gc968NyLgHCNL1Kp0+NFn+UkaZZLYKNmtJ AKu4EfNxKKOfWOe7TmQZBPBdZIlJK5NTu45sOV7XKr31mpJctabT6ex8im83vRNb5bnoYevASl W1SgQ8tScJ1YSKAvWdd0qB7gOBiNKYbacY8f6G/lYkqPm7rmVCDgcbGLE53jqCq6hKi41kK2OA oUczWyS6jt/eaDl5i3lTk0DNO5tc1hV4PMPsB3VVCYI9xfMlQnKj2ULm8JBJXKS8tFk0j8iTJ6 XS0doP1p05Jm7faK0oqGSSYXw64ReiFanXov2bOQZCFquyqQ==
                                X-Mimecast-Spam-Score3
                                X-Mimecast-Impersonation-ProtectPolicy=Impersonation Protect;Similar Internal Domain=false;Similar Monitored External Domain=false;Custom External Domain=false;Mimecast External Domain=false;Newly Observed Domain=false;Internal User Name=false;Custom Display Name List=false;Reply-to Address Mismatch=false;Targeted Threat Dictionary=true;Mimecast Threat Dictionary=true;Custom Threat Dictionary=false
                                Return-Pathk.sword.m5@kzh.biglobe.ne.jp
                                X-Ms-Exchange-Organization-Expirationstarttime10 Oct 2024 18:24:25.1259 (UTC)
                                X-Ms-Exchange-Organization-ExpirationstarttimereasonOriginalSubmit
                                X-Ms-Exchange-Organization-Expirationinterval1:00:00:00.0000000
                                X-Ms-Exchange-Organization-ExpirationintervalreasonOriginalSubmit
                                X-Ms-Exchange-Organization-Network-Message-Id753eb0c7-a351-4b80-cbc3-08dce958c4ff
                                X-Eopattributedmessage0
                                X-Eoptenantattributedmessage7ba566b9-eb1e-462c-b923-57bac7bc136e:0
                                X-Ms-Exchange-Organization-MessagedirectionalityIncoming
                                X-Ms-Exchange-Skiplistedinternetsenderip=[27.86.113.49];domain=mta-sndfb-w01.biglobe.ne.jp
                                X-Ms-Exchange-Externaloriginalinternetsenderip=[27.86.113.49];domain=mta-sndfb-w01.biglobe.ne.jp
                                X-Ms-PublictraffictypeEmail
                                X-Ms-TraffictypediagnosticCY4PEPF0000EE33:EE_|CH2PR08MB10633:EE_|PH0PR08MB6488:EE_
                                X-Ms-Exchange-Organization-AuthsourceCY4PEPF0000EE33.namprd05.prod.outlook.com
                                X-Ms-Exchange-Organization-AuthasAnonymous
                                X-Ms-Office365-Filtering-Correlation-Id753eb0c7-a351-4b80-cbc3-08dce958c4ff
                                X-Ms-Exchange-AtpmessagepropertiesSA|SL
                                X-Ms-Exchange-Organization-Scl-1
                                X-Microsoft-AntispamBCL:0;ARA:13230040|7093399012|2092899012|3072899012|12012899012|82310400026|2722699018|43540500003
                                X-Forefront-Antispam-ReportCIP:205.139.110.120;CTRY:JP;LANG:en;SCL:-1;SRV:;IPV:NLI;SFV:NSPM;H:mta-sndfb-w01.biglobe.ne.jp;PTR:mta-sndfb-w01.biglobe.ne.jp;CAT:NONE;SFS:(13230040)(7093399012)(2092899012)(3072899012)(12012899012)(82310400026)(2722699018)(43540500003);DIR:INB
                                X-Ms-Exchange-Crosstenant-Originalarrivaltime10 Oct 2024 18:24:24.8916 (UTC)
                                X-Ms-Exchange-Crosstenant-Network-Message-Id753eb0c7-a351-4b80-cbc3-08dce958c4ff
                                X-Ms-Exchange-Crosstenant-Id7ba566b9-eb1e-462c-b923-57bac7bc136e
                                X-Ms-Exchange-Crosstenant-AuthsourceCY4PEPF0000EE33.namprd05.prod.outlook.com
                                X-Ms-Exchange-Crosstenant-AuthasAnonymous
                                X-Ms-Exchange-Crosstenant-FromentityheaderInternet
                                X-Ms-Exchange-Transport-CrosstenantheadersstampedCH2PR08MB10633
                                X-Ms-Exchange-Transport-Endtoendlatency00:00:07.9795943
                                X-Ms-Exchange-Processed-By-Bccfoldering15.20.8048.010
                                X-Microsoft-Antispam-Mailbox-Deliveryucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(930097)(140003)
                                X-Microsoft-Antispam-Message-InfosOMJ8lC3HQoYdHfo13uGMlNrmMTPVd8E7w1YS5zq1QorEM5bVK/Y8E2OVLGI4TLQ0gY7zT3d1Bivpw/zb+/q0nh5pqJkz90G/K7oMNQ4dX4In9OY4RkS6yVxzkcujuVvl2cQg8c72iRl9r7sSLGx78moY0HXEn7ZGEHWDqOH9C4VrCaCmN1mNwKfU3+TosXpU1bHeGi7DiqoRPQNiTOBT7Kjm6n0wovIx+dNYbJxs3BivnX3BaMZJFeNGcqh8Vsni1H03ABKUoQaekrp7PgaDkLMBpdGmG3Yfgjd7jZCdZNfT6zF0wf9iKfrt90q6L1+c/7sZFmzoPTgXrtRc7/tM0fp1wrQAA+EKkJLIcEwuuJx6uJ5qyt1xq8h55/UQSmeGayA2esGSOS5Q2rcsdsrTSLMjNiLA4bqmWZegJRO0ALOU+KxbvsWdRRB6cz6aZqJ+xsm2dc6OKVGlw2zWf9nSPhAkv97BWwmiEDgtQRXbbS8nM0gNnnLkEDX7476GDhLjQhnL3P69s/dmIMmQ1IhUlM7E4Hc3HS6EgTH63IyaUJeKDXjJ36Yuc1cd/pZpxS+jgsHg9UnjlhegtOEPh//Mh3WDrJXcZDkJCwxj2vYtE9jGcxQ5gzvcsBzbKQN6h/rvFbXYtlHbj8Zq0zAMlNYtszICakJAV0AAiL8LMrhD+LpY6um+zfQI0UgWVXg+XK1xPnyBUdrcLg/7UPXVOuCTprlMAoPlPLKHXliUxgyfMHOX0iM/jSGUKUBz5ar30LSVKyOPFxMTFQDcDK8Iuta/SrUM+DnA6tGcS44r/7wlXQXVAlDMbd6uaHK2l9fvMNF8c6a6g30rjEtAf4jsmryfuEQQJci4xdoJWCK+OM0lLuybOD7HtSkp3gpcX27A7k58sEaPjTzj+1ma6hUBAPPl21oOYnMR0oLeKgbKCOXtYtiMMWfGd0GLpPziO0JO1a3/92 RGfKkYp47MjPsjYUCb8GCgn/F0EjjhpQCJaa2pSCBEGyQK6lRn5mCtdSpOJk2S8kNv9Jm8HdmIrZk4vEhT1wqFGCBa6Ss/KCHJMv3B3119Li+bgVM6uqPJnM6rWYcPKJxIiAUuQfCUMVukpbinn/+1UfpQw7nvnE3am56wxSvP0yZm43unqJnY1G4fYgGZYmFQAiY0yXh+Vsp0H7LBZy72u1JYEsm/rMrM6hSqBtWLYB5/OGbnv/QL1GeYvQ2BbLSbQ+xEJ3TqfwxR/K3QsM+i8Wpq1uwV55iuLk+ui1EK3al7m9AxpzGF7b4xd1n/2uEhCPbOmTExyd9aRJHru2PqwV/I4gKfjqcfInaS8QFteL3PTyyzFtxzHWCsO6yal4jO8FLYo9l7iNnMI6XYQgihA38pADBZvUIa/TC/7AzBqBLcKpz4R0alJMp7G2F0nZOZpC0V5fkjSi2fGM2IC2kdEd5aFHuOYRG15s5kzCV0O92r8Tfysyh/iXNBYdO4IZKf/HzaOGmjUlk6DpaMOIM2+6WG5YMEo1kVv3iUUvt0LohXU6txR9hgmLd/EpWTWDWtgixip1aUMnkv5whGePwXPs+BOkkB0ikkB/SpjRdaaJaPTMMjkeiyK8bGk27YpBGw1w4qVzCunRGIdotBiG7WHf238032OtdAGlTV46HBqwHWH7f86s3AvXGs2CtGIkNMYuj8C3ZJWU9Qtjqztla7QL7jBYeNwUCUD6zTj29d7avJPvO5bXzit7dxdib4qWF9nTdrHqD+JTjpgcX/dgHtWbrhxeBPmWrNEtFlHmOVTNnlwI8zdmNUk/bkP29JdssPmdRedREWoSXPGSnKxM6xY9MrOlKFg4AP61ANoLHjdLQa3YsSux+nv4xn+zHJvui3I+PjS0fDp3WAyky3RMr06JWGHLF7d0lEnVtOxAWyFT2aVtcIouXZHUBRZ0F3H+ibXZ5GOkvrpsoSTyYOy0xtgkQnZyKgfuxq72M sFLTJmG1sSOiKR3GEjYcsTDArSGOJ2loCrhaD2MnFPia0vO4PyuXaP14gDtMfFHwJyQ9/xqPrcfFYD6gEdyAJHPBqQuo+Bhx0RVOqNrtNbxVEPIG7TwS2KHqN3xCZKUSp4z3+4UL9hayzqVAtKwJAKF6WMe9HJ4Enii791B0ErLsnm1yjPY4pZ+vpGpmdZAt5lHVrwtTuD2kNCyjvP6BUF4QLRO57nT9eMQowbE3O5h6ZRHWJyRLUrdhDBC+luPxETUF/krqMeiYH7rsXkxEumrl/j3n1Ec5ugqMR+Fz5qW9EqDPq+ofD+0C/x4mkKl3jBxnZyOy/WYzebaTH61evAru2iraicO0nQgfAaULovQ3mHOSa7rMqmctXRQTlZN6IFuO2SLP2MD7vaCaUmDSLRYq
                                Content-Typemultipart/mixed; boundary="----sinikael-?=_1-17285875823870.6693688166369929"

                                Icon Hash:46070c0a8e0c67d6
                                No network behavior found

                                Click to jump to process

                                Click to jump to process

                                Click to dive into process behavior distribution

                                Click to jump to process

                                Target ID:0
                                Start time:15:30:09
                                Start date:10/10/2024
                                Path:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                Wow64 process (32bit):true
                                Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\phish_alert_sp2_2.0.0.0 (13).eml"
                                Imagebase:0x720000
                                File size:34'446'744 bytes
                                MD5 hash:91A5292942864110ED734005B7E005C0
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:false

                                Target ID:2
                                Start time:15:30:14
                                Start date:10/10/2024
                                Path:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "275573E4-4E3A-44CF-9503-868017FC0EFD" "DC9DDA95-057A-40A5-91CF-1110D1B5CBAE" "4132" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
                                Imagebase:0x7ff7a0250000
                                File size:710'048 bytes
                                MD5 hash:EC652BEDD90E089D9406AFED89A8A8BD
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:false

                                Target ID:5
                                Start time:15:30:39
                                Start date:10/10/2024
                                Path:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca
                                Imagebase:0x7ff7f6fc0000
                                File size:2'486'784 bytes
                                MD5 hash:6F8EAC2C377C8F16D91CB5AC8B8DBF5F
                                Has elevated privileges:false
                                Has administrator privileges:false
                                Programmed in:C, C++ or other language
                                Reputation:moderate
                                Has exited:false

                                Target ID:11
                                Start time:15:30:43
                                Start date:10/10/2024
                                Path:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe" -ServerName:microsoft.windowslive.manageaccounts.AppXdbf3yp5apt3t7q877db3gnz5zqpf71zj.mca
                                Imagebase:0x7ff6fc210000
                                File size:274'432 bytes
                                MD5 hash:6FEB00C9A2C3FF66230658B3012BAB6A
                                Has elevated privileges:false
                                Has administrator privileges:false
                                Programmed in:C, C++ or other language
                                Reputation:moderate
                                Has exited:false

                                No disassembly