Windows Analysis Report
phish_alert_sp2_2.0.0.0.eml

Overview

General Information

Sample name: phish_alert_sp2_2.0.0.0.eml
Analysis ID: 1531694
MD5: d9d874ff1eb3dbf809345d7d6f2509ec
SHA1: ad720ca6777233dc90ab6b09fc44667e5ef5b889
SHA256: 6d702762dbf87afbd3a560b77786eb584c8b05e26495152d92f2d591a7072727
Infos:

Detection

Score: 23
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

AI detected landing page (webpage, office document or email)
Detected non-DNS traffic on DNS port
HTML body contains password input but no form action
HTML page contains hidden javascript code
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores files to the Windows start menu directory

Classification

Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Base64 decoded: <?xml version="1.0" encoding="UTF-8"?><svg xmlns="http://www.w3.org/2000/svg" width="18" height="100%" viewBox="0 0 18 18" class="btn-google__svg"> <path d="M17.64 9.2a11 11 0 0 0-.16-1.84H9v3.49h4.84a4.12 4.12 0 0 1-1.79 2.71v2.26H15a8.78 8.78 0 0 0...
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Iframe src: https://12370631.fls.doubleclick.net/activityi;src=12370631;type=pd_app;cat=pd-ap0;ord=9120255653985;npa=0;auiddc=1225100163.1728655869;u1=;u7=undefined;u8=undefined;ps=1;pcor=554010169;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;frm=0;gtm=45fe4a90v9176682100z86615274za201zb6615274;gcs=G111;gcd=13t3t3l3l5l1;dma=0;tag_exp=101671035~101686685;epver=2;~oref=https%3A%2F%2Fapp.pandadoc.com%2Flogin%2F%3Fnext%3D%2Fa%2F?
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Iframe src: https://td.doubleclick.net/td/fls/rul/activityi;fledge=1;src=12370631;type=pd_app;cat=pd-ap0;ord=9120255653985;npa=0;auiddc=1225100163.1728655869;u1=;u7=undefined;u8=undefined;ps=1;pcor=554010169;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;frm=0;gtm=45fe4a90v9176682100z86615274za201zb6615274;gcs=G111;gcd=13t3t3l3l5l1;dma=0;tag_exp=101671035~101686685;epver=2;~oref=https%3A%2F%2Fapp.pandadoc.com%2Flogin%2F%3Fnext%3D%2Fa%2F?
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Iframe src: https://12370631.fls.doubleclick.net/activityi;src=12370631;type=pd_app;cat=pd-ap0;ord=9120255653985;npa=0;auiddc=1225100163.1728655869;u1=;u7=undefined;u8=undefined;ps=1;pcor=554010169;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;frm=0;gtm=45fe4a90v9176682100z86615274za201zb6615274;gcs=G111;gcd=13t3t3l3l5l1;dma=0;tag_exp=101671035~101686685;epver=2;~oref=https%3A%2F%2Fapp.pandadoc.com%2Flogin%2F%3Fnext%3D%2Fa%2F?
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Iframe src: https://td.doubleclick.net/td/fls/rul/activityi;fledge=1;src=12370631;type=pd_app;cat=pd-ap0;ord=9120255653985;npa=0;auiddc=1225100163.1728655869;u1=;u7=undefined;u8=undefined;ps=1;pcor=554010169;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;frm=0;gtm=45fe4a90v9176682100z86615274za201zb6615274;gcs=G111;gcd=13t3t3l3l5l1;dma=0;tag_exp=101671035~101686685;epver=2;~oref=https%3A%2F%2Fapp.pandadoc.com%2Flogin%2F%3Fnext%3D%2Fa%2F?
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Iframe src: https://12370631.fls.doubleclick.net/activityi;src=12370631;type=pd_app;cat=pd-ap0;ord=9120255653985;npa=0;auiddc=1225100163.1728655869;u1=;u7=undefined;u8=undefined;ps=1;pcor=554010169;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;frm=0;gtm=45fe4a90v9176682100z86615274za201zb6615274;gcs=G111;gcd=13t3t3l3l5l1;dma=0;tag_exp=101671035~101686685;epver=2;~oref=https%3A%2F%2Fapp.pandadoc.com%2Flogin%2F%3Fnext%3D%2Fa%2F?
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: Iframe src: https://td.doubleclick.net/td/fls/rul/activityi;fledge=1;src=12370631;type=pd_app;cat=pd-ap0;ord=9120255653985;npa=0;auiddc=1225100163.1728655869;u1=;u7=undefined;u8=undefined;ps=1;pcor=554010169;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;frm=0;gtm=45fe4a90v9176682100z86615274za201zb6615274;gcs=G111;gcd=13t3t3l3l5l1;dma=0;tag_exp=101671035~101686685;epver=2;~oref=https%3A%2F%2Fapp.pandadoc.com%2Flogin%2F%3Fnext%3D%2Fa%2F?
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: <input type="password" .../> found
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No favicon
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No <meta name="author".. found
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No <meta name="author".. found
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No <meta name="author".. found
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No <meta name="copyright".. found
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No <meta name="copyright".. found
Source: https://app.pandadoc.com/login/?next=/a/#/documents/C2edxovHUsjF2GgqzPKjZ7?requestAccessDisabled=true HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 40.126.32.136:443 -> 192.168.2.16:58079 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:58084 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:58199 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:58093 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.136
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: eur02.safelinks.protection.outlook.com
Source: global traffic DNS traffic detected: DNS query: app.pandadoc.com
Source: global traffic DNS traffic detected: DNS query: cdn.cookielaw.org
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: cdn.segment.com
Source: global traffic DNS traffic detected: DNS query: edge.fullstory.com
Source: global traffic DNS traffic detected: DNS query: static.prod.pandadoc-static.com
Source: global traffic DNS traffic detected: DNS query: tag.clearbitscripts.com
Source: global traffic DNS traffic detected: DNS query: x.clearbitjs.com
Source: global traffic DNS traffic detected: DNS query: sentry.infrastructure.pandadoc.com
Source: global traffic DNS traffic detected: DNS query: api.pandadoc.com
Source: global traffic DNS traffic detected: DNS query: ad.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: td.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: geolocation.onetrust.com
Source: global traffic DNS traffic detected: DNS query: api.segment.io
Source: global traffic DNS traffic detected: DNS query: app.clearbit.com
Source: global traffic DNS traffic detected: DNS query: d31uqz37bvu6i7.cloudfront.net
Source: global traffic DNS traffic detected: DNS query: js.hs-analytics.net
Source: global traffic DNS traffic detected: DNS query: dr79nymq4x8i9.cloudfront.net
Source: global traffic DNS traffic detected: DNS query: 12370631.fls.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: adservice.google.com
Source: global traffic DNS traffic detected: DNS query: js-na1.hs-scripts.com
Source: global traffic DNS traffic detected: DNS query: track.hubspot.com
Source: global traffic DNS traffic detected: DNS query: d3m3a7p0ze7hmq.cloudfront.net
Source: global traffic DNS traffic detected: DNS query: js.hs-banner.com
Source: unknown Network traffic detected: HTTP traffic on port 58186 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58140 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58111 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58128 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58102
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58101
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58104
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58103
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58100
Source: unknown Network traffic detected: HTTP traffic on port 58192 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58181 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58106
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58105
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58113
Source: unknown Network traffic detected: HTTP traffic on port 58174 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58112
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58115
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58114
Source: unknown Network traffic detected: HTTP traffic on port 58122 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58105 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58111
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58110
Source: unknown Network traffic detected: HTTP traffic on port 58157 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58180 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58116
Source: unknown Network traffic detected: HTTP traffic on port 58146 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58119
Source: unknown Network traffic detected: HTTP traffic on port 58169 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58118
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58124
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58123
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58126
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58125
Source: unknown Network traffic detected: HTTP traffic on port 58127 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58152 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58120
Source: unknown Network traffic detected: HTTP traffic on port 58089 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58122
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58121
Source: unknown Network traffic detected: HTTP traffic on port 58133 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58078 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58135 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58141 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58110 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58128
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58127
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58129
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58135
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58134
Source: unknown Network traffic detected: HTTP traffic on port 58090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58137
Source: unknown Network traffic detected: HTTP traffic on port 58197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58136
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58131
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58130
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58133
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58132
Source: unknown Network traffic detected: HTTP traffic on port 58084 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58138 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58144 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58096 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58167 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58150 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58118 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58196 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58173 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58112 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58129 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58185 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58101 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58178 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58184 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58091 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58201
Source: unknown Network traffic detected: HTTP traffic on port 58123 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58156 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58179 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58190 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58139 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58162 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58106 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58145 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58151 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58134 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58125 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58189
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58186
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58185
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58188
Source: unknown Network traffic detected: HTTP traffic on port 58102 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58187
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58182
Source: unknown Network traffic detected: HTTP traffic on port 58131 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58181
Source: unknown Network traffic detected: HTTP traffic on port 58154 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58184
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58183
Source: unknown Network traffic detected: HTTP traffic on port 58177 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58180
Source: unknown Network traffic detected: HTTP traffic on port 58137 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58160 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58097 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58143 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58189 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58079
Source: unknown Network traffic detected: HTTP traffic on port 58092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58197
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58196
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58078
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58199
Source: unknown Network traffic detected: HTTP traffic on port 58119 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58193
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58192
Source: unknown Network traffic detected: HTTP traffic on port 58086 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58194
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58190
Source: unknown Network traffic detected: HTTP traffic on port 58113 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58161 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58098 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58188 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58086
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58089
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58088
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58084
Source: unknown Network traffic detected: HTTP traffic on port 58081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58081
Source: unknown Network traffic detected: HTTP traffic on port 58194 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58149 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58124 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58098
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58097
Source: unknown Network traffic detected: HTTP traffic on port 58130 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58099
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58094
Source: unknown Network traffic detected: HTTP traffic on port 58155 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58096
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58090
Source: unknown Network traffic detected: HTTP traffic on port 58172 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58092
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58091
Source: unknown Network traffic detected: HTTP traffic on port 58115 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58201 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58139
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58138
Source: unknown Network traffic detected: HTTP traffic on port 58182 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58146
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58145
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58148
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58147
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58142
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58141
Source: unknown Network traffic detected: HTTP traffic on port 58121 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58144
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58143
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58140
Source: unknown Network traffic detected: HTTP traffic on port 58158 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58147 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58149
Source: unknown Network traffic detected: HTTP traffic on port 58164 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58157
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58156
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58159
Source: unknown Network traffic detected: HTTP traffic on port 58126 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58158
Source: unknown Network traffic detected: HTTP traffic on port 58199 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58153
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58152
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58155
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58154
Source: unknown Network traffic detected: HTTP traffic on port 58132 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58151
Source: unknown Network traffic detected: HTTP traffic on port 58170 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58150
Source: unknown Network traffic detected: HTTP traffic on port 58153 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58136 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58142 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58165 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58168
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58167
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58169
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58164
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58163
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58166
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58165
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58160
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58162
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58161
Source: unknown Network traffic detected: HTTP traffic on port 58171 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58114 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58187 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58099 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58120 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58179
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58178
Source: unknown Network traffic detected: HTTP traffic on port 58094 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58175
Source: unknown Network traffic detected: HTTP traffic on port 58088 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58174
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58177
Source: unknown Network traffic detected: HTTP traffic on port 58103 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58171
Source: unknown Network traffic detected: HTTP traffic on port 58193 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58170
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58173
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58172
Source: unknown Network traffic detected: HTTP traffic on port 58159 -> 443
Source: unknown HTTPS traffic detected: 40.126.32.136:443 -> 192.168.2.16:58079 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:58084 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:58199 version: TLS 1.2
Source: classification engine Classification label: sus23.winEML@19/58@92/502
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241011T1010520455-7100.etl
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\phish_alert_sp2_2.0.0.0.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "37DDDAEE-9F34-4813-B165-420FD6211B01" "7F385A7B-179E-4911-ACAD-354D4B1CB9DA" "7100" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fapp.pandadoc.com%2Fcollaborator%2Fq779Y8X3yd4DqtXnoDyU2Y%2Fdocument%2FC2edxovHUsjF2GgqzPKjZ7%2Fsignup%2F&data=05%7C02%7Cy.atamaniuk%40gms.net%7C2379b2dd68f64c818cab08dce94808b0%7Cb257b72ab83c4005915bce5ce92eaad2%7C1%7C0%7C638641742839616804%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=rNowDTcUQfioIu6tQR89ajyK0OiKQBTLi%2B%2BrVqSyBVo%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1948,i,13608333319017150822,94770162492369872,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "37DDDAEE-9F34-4813-B165-420FD6211B01" "7F385A7B-179E-4911-ACAD-354D4B1CB9DA" "7100" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fapp.pandadoc.com%2Fcollaborator%2Fq779Y8X3yd4DqtXnoDyU2Y%2Fdocument%2FC2edxovHUsjF2GgqzPKjZ7%2Fsignup%2F&data=05%7C02%7Cy.atamaniuk%40gms.net%7C2379b2dd68f64c818cab08dce94808b0%7Cb257b72ab83c4005915bce5ce92eaad2%7C1%7C0%7C638641742839616804%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=rNowDTcUQfioIu6tQR89ajyK0OiKQBTLi%2B%2BrVqSyBVo%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1948,i,13608333319017150822,94770162492369872,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Window found: window name: SysTabControl32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common

Persistence and Installation Behavior

barindex
Source: Email LLM: Page contains button: 'OPEN THE DOCUMENT' Source: 'Email'
Source: Email LLM: Email contains prominent button: 'open the document'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File Volume queried: C:\Windows\SysWOW64 FullSizeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Queries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs