Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
'Weekly Finances Report' has been shared with you-1.msg

Overview

General Information

Sample name:'Weekly Finances Report' has been shared with you-1.msg
Analysis ID:1545475
MD5:76a9e1e12ffbde07994fc959c17b2488
SHA1:2fb82d6301373b16e1300d5262475e676802d110
SHA256:6647c5d474e7cacdeaf2982d9226c00580de9bfcd6d4ca5d097b62bebbdea701
Infos:

Detection

Score:21
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

AI detected potential phishing Email
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification

Classification

  • System is w10x64
  • OUTLOOK.EXE (PID: 7280 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\'Weekly Finances Report' has been shared with you-1.msg" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 7672 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "143D4FE8-01BA-4276-95D5-3E05BC125111" "7244AA12-D62A-4B2F-A63D-2B351ACC5F92" "7280" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • cleanup
No configs have been found
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 7280, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: http://b.c2r.ts.cdn.office.net/pr
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD41570.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
Source: 'Weekly Finances Report' has been shared with you-1.msgString found in binary or memory: http://officeblogswest.blob.core.windows.net/wp-content/2014/01/OneDrive-forBiz_rgb_EN_Blue.png
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.aadrm.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.aadrm.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.addins.omex.office.net/api/addins/search
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.cortana.ai
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.microsoftstream.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.office.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.officescripts.microsoftusercontent.com/api
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.onedrive.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/imports
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://api.scheduler.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://apis.mobile.m365.svc.cloud.microsoft
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://app.powerbi.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://augloop.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://canary.designerapp.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designer-mobile
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/fonts
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-assets
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-dynamic-strings
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-home-screen
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-toolbar
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.entity.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.hubblecontent.osi.office.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cdn.int.designerapp.osi.office.net/fonts
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/DeltaAdvisory
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/InteractiveInstallation
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://consent.config.office.com/consentcheckin/v1.0/consents
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://consent.config.office.com/consentweb/v1.0/consents
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cortana.ai
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cortana.ai/api
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://cr.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://d.docs.live.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://designerapp.azurewebsites.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://designerappservice.officeapps.live.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dev.cortana.ai
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://devnull.onenote.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://directory.services.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ecs.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ecs.office.com/config/v1/Designer
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://edge.skype.com/registrar/prod
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://edge.skype.com/rps
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/v2.1601652342626
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://fpastorage.cdn.office.net/%s
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://fpastorage.cdn.office.net/firstpartyapp/addins.xml
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://graph.windows.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://graph.windows.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/pivots/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?secureurl=1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ic3.teams.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://inclient.store.office.com/gyro/client
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://invites.office.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://lifecycle.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.microsoftonline.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.microsoftonline.com/organizations
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.windows.local
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://make.powerautomate.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://management.azure.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://management.azure.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messagebroker.mobile.m365.svc.cloud.microsoft
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.action.office.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.action.office.com/setcampaignaction
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.action.office.com/setuseraction16
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.engagement.office.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.engagement.office.com/campaignmetadataaggregator
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.lifecycle.office.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.lifecycle.office.com/getcustommessage16
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://messaging.office.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://mss.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://my.microsoftpersonalcontent.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ncus.contentsync.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://notification.m365.svc.cloud.microsoft/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://notification.m365.svc.cloud.microsoft/PushNotifications.Register
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ods-diagnostics-ppe.trafficmanager.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://officeapps.live.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://officepyservice.office.net/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://officepyservice.office.net/service.functionality
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://onedrive.live.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://otelrules.azureedge.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://otelrules.svc.static.microsoft
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office365.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office365.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://outlook.office365.com/connectors
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://pushchannel.1drv.ms
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://res.cdn.office.net
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://res.cdn.office.net/polymer/models
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://safelinks.protection.outlook.com/api/GetPolicy
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://service.officepy.microsoftusercontent.com/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://service.powerapps.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://settings.outlook.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://staging.cortana.ai
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://statics.teams.cdn.office.net/evergreen-assets/illustrations/win32/m365-device-desktop-dark-1
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://statics.teams.cdn.office.net/evergreen-assets/illustrations/win32/m365-device-desktop-dark-2
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://statics.teams.cdn.office.net/evergreen-assets/illustrations/win32/m365-device-desktop-hc-100
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://statics.teams.cdn.office.net/evergreen-assets/illustrations/win32/m365-device-desktop-hc-150
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://statics.teams.cdn.office.net/evergreen-assets/illustrations/win32/m365-device-desktop-hc-200
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://statics.teams.cdn.office.net/evergreen-assets/illustrations/win32/m365-device-desktop-light-
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://substrate.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://substrate.office.com/Notes-Internal.ReadWrite
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://tasks.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://templatesmetadata.office.net/
Source: 'Weekly Finances Report' has been shared with you-1.msgString found in binary or memory: https://token.onelogin.com-token-auth.com/XUm5aUU5RRGNzMjBtRzZMcllzdmpxTHBMMVJTT1J2Z1BUOTJmZmdScTdxL
Source: 'Weekly Finances Report' has been shared with you-1.msg, ~WRS{F5E20112-51F8-450C-A90C-B87A52405B14}.tmp.0.drString found in binary or memory: https://token.onelogin.com-token-auth.com/Xa0Y1MmVibVhmY0E5dnlabzhVK2w2MVo4bXZUM3RzTFBZU1FSUEYxRHlzb
Source: 'Weekly Finances Report' has been shared with you-1.msg, ~WRS{F5E20112-51F8-450C-A90C-B87A52405B14}.tmp.0.drString found in binary or memory: https://token.onelogin.com-token-auth.com/XaFNXZmZxdFUzWDFPWVFxY2lia3BpYkY4UHdlcTNmZStWYjZidGFaMXFld
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://useraudit.o365auditrealtimeingestion.manage.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://word-edit.officeapps.live.com/we/rrdiscovery.ashx
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://wus2.contentsync.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: 180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drString found in binary or memory: https://www.yammer.com
Source: classification engineClassification label: sus21.winMSG@3/19@0/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmpJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241030T1052340892-7280.etlJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\'Weekly Finances Report' has been shared with you-1.msg"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "143D4FE8-01BA-4276-95D5-3E05BC125111" "7244AA12-D62A-4B2F-A63D-2B351ACC5F92" "7280" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "143D4FE8-01BA-4276-95D5-3E05BC125111" "7244AA12-D62A-4B2F-A63D-2B351ACC5F92" "7280" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior

Persistence and Installation Behavior

barindex
Source: EmailLLM: Detected potential phishing email: The sender domain 'notice-onedrive.com' is suspicious and not a legitimate Microsoft domain
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Process Injection
LSASS Memory13
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://api.diagnosticssdf.office.com0%URL Reputationsafe
https://login.microsoftonline.com/0%URL Reputationsafe
https://shell.suite.office.com:14430%URL Reputationsafe
https://designerapp.azurewebsites.net0%URL Reputationsafe
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize0%URL Reputationsafe
https://autodiscover-s.outlook.com/0%URL Reputationsafe
https://useraudit.o365auditrealtimeingestion.manage.office.com0%URL Reputationsafe
https://outlook.office365.com/connectors0%URL Reputationsafe
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://api.addins.omex.office.net/appinfo/query0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/tenantassociationkey0%URL Reputationsafe
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://lookup.onenote.com/lookup/geolocation/v10%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/imports0%URL Reputationsafe
https://cloudfiles.onenote.com/upload.aspx0%URL Reputationsafe
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://entitlement.diagnosticssdf.office.com0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%URL Reputationsafe
https://canary.designerapp.0%URL Reputationsafe
https://ic3.teams.office.com0%URL Reputationsafe
https://www.yammer.com0%URL Reputationsafe
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies0%URL Reputationsafe
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive0%URL Reputationsafe
https://cr.office.com0%URL Reputationsafe
https://messagebroker.mobile.m365.svc.cloud.microsoft0%URL Reputationsafe
https://portal.office.com/account/?ref=ClientMeControl0%URL Reputationsafe
https://clients.config.office.net/c2r/v1.0/DeltaAdvisory0%URL Reputationsafe
https://edge.skype.com/registrar/prod0%URL Reputationsafe
https://graph.ppe.windows.net0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://tasks.office.com0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%URL Reputationsafe
https://sr.outlook.office.net/ws/speech/recognize/assistant/work0%URL Reputationsafe
https://api.scheduler.0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://api.aadrm.com0%URL Reputationsafe
https://edge.skype.com/rps0%URL Reputationsafe
https://globaldisco.crm.dynamics.com0%URL Reputationsafe
https://messaging.engagement.office.com/0%URL Reputationsafe
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://api.diagnosticssdf.office.com/v2/feedback0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/groups0%URL Reputationsafe
https://web.microsoftstream.com/video/0%URL Reputationsafe
https://api.addins.store.officeppe.com/addinstemplate0%URL Reputationsafe
https://graph.windows.net0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://analysis.windows.net/powerbi/api0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://substrate.office.com0%URL Reputationsafe
https://outlook.office365.com/autodiscover/autodiscover.json0%URL Reputationsafe
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios0%URL Reputationsafe
https://consent.config.office.com/consentcheckin/v1.0/consents0%URL Reputationsafe
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices0%URL Reputationsafe
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json0%URL Reputationsafe
https://safelinks.protection.outlook.com/api/GetPolicy0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/0%URL Reputationsafe
http://weather.service.msn.com/data.aspx0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://officepyservice.office.net/service.functionality0%URL Reputationsafe
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks0%URL Reputationsafe
https://templatesmetadata.office.net/0%URL Reputationsafe
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios0%URL Reputationsafe
https://messaging.lifecycle.office.com/0%URL Reputationsafe
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml0%URL Reputationsafe
https://mss.office.com0%URL Reputationsafe
https://pushchannel.1drv.ms0%URL Reputationsafe
https://management.azure.com0%URL Reputationsafe
https://outlook.office365.com0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://incidents.diagnostics.office.com0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/ios0%URL Reputationsafe
https://make.powerautomate.com0%URL Reputationsafe
https://api.addins.omex.office.net/api/addins/search0%URL Reputationsafe
https://insertmedia.bing.office.net/odc/insertmedia0%URL Reputationsafe
https://outlook.office365.com/api/v1.0/me/Activities0%URL Reputationsafe
https://api.office.net0%URL Reputationsafe
https://incidents.diagnosticssdf.office.com0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://api.diagnosticssdf.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://login.microsoftonline.com/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://shell.suite.office.com:1443180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://designerapp.azurewebsites.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://autodiscover-s.outlook.com/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://useraudit.o365auditrealtimeingestion.manage.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://outlook.office365.com/connectors180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://cdn.entity.180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://api.addins.omex.office.net/appinfo/query180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://clients.config.office.net/user/v1.0/tenantassociationkey180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://powerlift.acompli.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://rpsticket.partnerservices.getmicrosoftkey.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://lookup.onenote.com/lookup/geolocation/v1180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://cortana.ai180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://api.powerbi.com/v1.0/myorg/imports180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
  • URL Reputation: safe
unknown
https://notification.m365.svc.cloud.microsoft/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
    unknown
    https://cloudfiles.onenote.com/upload.aspx180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
    • URL Reputation: safe
    unknown
    https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
    • URL Reputation: safe
    unknown
    https://token.onelogin.com-token-auth.com/XaFNXZmZxdFUzWDFPWVFxY2lia3BpYkY4UHdlcTNmZStWYjZidGFaMXFld'Weekly Finances Report' has been shared with you-1.msg, ~WRS{F5E20112-51F8-450C-A90C-B87A52405B14}.tmp.0.drfalse
      unknown
      https://entitlement.diagnosticssdf.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://api.aadrm.com/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://ofcrecsvcapi-int.azurewebsites.net/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://canary.designerapp.180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://ic3.teams.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://www.yammer.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
      • URL Reputation: safe
      unknown
      https://api.microsoftstream.com/api/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
        unknown
        https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
        • URL Reputation: safe
        unknown
        https://cr.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
        • URL Reputation: safe
        unknown
        https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
          unknown
          https://messagebroker.mobile.m365.svc.cloud.microsoft180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
          • URL Reputation: safe
          unknown
          https://otelrules.svc.static.microsoft180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            unknown
            https://portal.office.com/account/?ref=ClientMeControl180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://clients.config.office.net/c2r/v1.0/DeltaAdvisory180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://edge.skype.com/registrar/prod180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://graph.ppe.windows.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://res.getmicrosoftkey.com/api/redemptionevents180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://powerlift-frontdesk.acompli.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://tasks.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://officeci.azurewebsites.net/api/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://sr.outlook.office.net/ws/speech/recognize/assistant/work180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://api.scheduler.180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
            • URL Reputation: safe
            unknown
            https://my.microsoftpersonalcontent.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
              unknown
              https://store.office.cn/addinstemplate180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
              • URL Reputation: safe
              unknown
              https://api.aadrm.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
              • URL Reputation: safe
              unknown
              https://edge.skype.com/rps180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
              • URL Reputation: safe
              unknown
              https://outlook.office.com/autosuggest/api/v1/init?cvid=180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                unknown
                https://globaldisco.crm.dynamics.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://messaging.engagement.office.com/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://dev0-api.acompli.net/autodetect180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://www.odwebp.svc.ms180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://api.diagnosticssdf.office.com/v2/feedback180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://api.powerbi.com/v1.0/myorg/groups180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://web.microsoftstream.com/video/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://api.addins.store.officeppe.com/addinstemplate180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://graph.windows.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://dataservice.o365filtering.com/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://officesetup.getmicrosoftkey.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://analysis.windows.net/powerbi/api180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://prod-global-autodetect.acompli.net/autodetect180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://substrate.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://outlook.office365.com/autodiscover/autodiscover.json180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://consent.config.office.com/consentcheckin/v1.0/consents180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                • URL Reputation: safe
                unknown
                https://notification.m365.svc.cloud.microsoft/PushNotifications.Register180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                  unknown
                  https://d.docs.live.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                    unknown
                    https://safelinks.protection.outlook.com/api/GetPolicy180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://ncus.contentsync.180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      unknown
                      https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      http://weather.service.msn.com/data.aspx180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://apis.live.net/v5.0/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://officepyservice.office.net/service.functionality180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://templatesmetadata.office.net/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://messaging.lifecycle.office.com/180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://mss.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://pushchannel.1drv.ms180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://management.azure.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://outlook.office365.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://wus2.contentsync.180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://incidents.diagnostics.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://clients.config.office.net/user/v1.0/ios180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://make.powerautomate.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://token.onelogin.com-token-auth.com/XUm5aUU5RRGNzMjBtRzZMcllzdmpxTHBMMVJTT1J2Z1BUOTJmZmdScTdxL'Weekly Finances Report' has been shared with you-1.msgfalse
                        unknown
                        https://api.addins.omex.office.net/api/addins/search180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://insertmedia.bing.office.net/odc/insertmedia180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://outlook.office365.com/api/v1.0/me/Activities180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://api.office.net180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://incidents.diagnosticssdf.office.com180B2559-A2BE-43D3-928C-DBFF4A992EC5.0.drfalse
                        • URL Reputation: safe
                        unknown
                        No contacted IP infos
                        Joe Sandbox version:41.0.0 Charoite
                        Analysis ID:1545475
                        Start date and time:2024-10-30 15:51:13 +01:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 4m 52s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:9
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:'Weekly Finances Report' has been shared with you-1.msg
                        Detection:SUS
                        Classification:sus21.winMSG@3/19@0/0
                        EGA Information:Failed
                        HCA Information:
                        • Successful, ratio: 100%
                        • Number of executed functions: 0
                        • Number of non-executed functions: 0
                        Cookbook Comments:
                        • Found application associated with file extension: .msg
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.113.194.132, 52.109.76.243, 2.19.126.151, 2.19.126.160, 93.184.221.240, 40.79.150.120
                        • Excluded domains from analysis (whitelisted): omex.cdn.office.net, slscr.update.microsoft.com, eur.roaming1.live.com.akadns.net, wu.azureedge.net, dns.msftncsi.com, neu-azsc-000.roaming.officeapps.live.com, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, ocsp.digicert.com, 6.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.0.3.0.1.3.0.6.2.ip6.arpa, login.live.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, officeclient.microsoft.com, wu-b-net.trafficmanager.net, a1864.dscd.akamai.net, ecs.office.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, prod.configsvc1.live.com.akadns.net, wu.ec.azureedge.net, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, onedscolprdfrc02.francecentral.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com, s-0005.s-msedge.net, config.officeapps.live.com, osiprod-neu-buff-azsc-000.northeurope.cloudapp.azure.com, ecs.office.traf
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtQueryAttributesFile calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                        • VT rate limit hit for: 'Weekly Finances Report' has been shared with you-1.msg
                        No simulations
                        No context
                        No context
                        No context
                        No context
                        No context
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 4770 bytes, 1 file, at 0x2c +A "disallowedcert.stl", number 1, 1 datablock, 0x1 compression
                        Category:dropped
                        Size (bytes):4770
                        Entropy (8bit):7.946747821604857
                        Encrypted:false
                        SSDEEP:96:9/nBu64pydcvOHRUfu0xK1bQYMRSRNoYmxYvk56sHMZhh4m:9/nBuP2cGxUfu6K1bpWJ6vfh4m
                        MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
                        SHA1:719C37C320F518AC168C86723724891950911CEA
                        SHA-256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
                        SHA-512:02F88DA4B610678C31664609BCFA9D61DB8D0B0617649981AF948F670F41A6207B4EC19FECCE7385A24E0C609CBBF3F2B79A8ACAF09A03C2C432CC4DCE75E9DB
                        Malicious:false
                        Reputation:high, very likely benign file
                        Preview:MSCF............,...................O.................2Wqh .disallowedcert.stl....^K...CK.wTS...:.w.K'.C0T.....Bh.{....C.).*.....Y@...(..).R."E..D^6........u....|f~3...o.3. ..SPK.k.o#...."{-.U..P........:..aPr.@.d......Dy.h.....)..:...!./\A.....A<I_<$...q.h..........'.....7....H...@`T..K.S.%...Y4..R.....`.....-....D...(..b..-c."...G.=.dx..S+..2.a.E....d.L...77J...c.[..@..iT&..^78..g....NW6.Ek..FY.F........cNt.O.*..R....*......D...... k........J.y...z.d...;.9_t...].@....yw..}.x....d.t..`f\K..;|.*h.X...4/.;.xT......q>.0...<...3...X..L$.&.,b.....\V....\......G..O..@..H3.....t..J..).x.?.{[..G>.7...<...^Q..z..Gw9P..d....i].n%K}.*z..2.Py...A..s...z..@...4..........4.....*Y.d..._Z.5.s..fl.C..#.K{9^.E...k..z.Ma..G.(.....5g. ...}.t.#4....$;.,....S@fs....k......u .^2.#_...I........;.......w..P...UCY...$;.S._|.x..dK...[i..q..^.l..A.?.....'N.. .L.l......m.*.+f#]............A.;.....Z..rIt....RW....Kr1e=8.=.z:Oi.z.d..r..C_......o...]j.N;.s....3@3.dgrv.
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):338
                        Entropy (8bit):3.1560749728106776
                        Encrypted:false
                        SSDEEP:6:kK1GLN+SkQlPlEGYRMY9z+s3Ql2DUevat:tGkkPlE99SCQl2DUevat
                        MD5:B952B8F810AAD982E3994373504D7E6F
                        SHA1:F3471BC82514C7B255B627D992764BBD47555C0A
                        SHA-256:D9BA06D077DD3A3FFC96AA19160271953C032B8179818666DD246FCC382234DA
                        SHA-512:4ACBA05867127376710A231B742A6CA7FB45293FC4EF49A7FCA72C2B94BA19819C92B070B6F75354F86A7DB2C577E787E09DB3DE8747D7A9277E77D94661A64A
                        Malicious:false
                        Reputation:low
                        Preview:p...... .........I.a.*..(....................................................... .........p.........$...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".7.4.6.7.8.7.a.3.f.0.d.9.1.:.0."...
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):231348
                        Entropy (8bit):4.389253087179401
                        Encrypted:false
                        SSDEEP:1536:O/YLGkgsUHlMyTwfXgsSpaNcAz79ysQqt2fCkeqoQ6Ircm0Fvo/1yJ8pv8R+Z+Rx:XBgaKsgNamiGu2wqoQlrt0Fv/44N0LpM
                        MD5:6DCBE529AD091A59F41CD76774B9B758
                        SHA1:BB9669F6861EA5303358D39747D05747E545076C
                        SHA-256:12703A4209C9189B838CE0E2A08B2657EA9385A837376D21A9C38F85AE830EA3
                        SHA-512:AA86BE91AAC2015E83DEE44C5CAE6D03DB12A9CC8BB5147B9E67686C7E8936AE54F36AE3E74A802506A82C17CA0F8DF8448E00CE40DFBD54DE4DEA4F8BBE944B
                        Malicious:false
                        Reputation:low
                        Preview:TH02...... ..2.N.*......SM01X...,... ..N.*..........IPM.Activity...........h...............h............H..h.o......D.....h...........H..h\hub ...AppD...h81..0...0.o....h'_.............h........_`.k...hk\..@...I.Dw...h....H...8..k...0....T...............d.........2h...............k1.1...........!h.............. hR[......H.o...#h....8.........$h.......8....."h............'h..............1h'_..<.........0h....4.....k../h....h......kH..h....p....o...-h .......t.o...+h._.......o................. ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000....Microsoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:ASCII text, with very long lines (65536), with no line terminators
                        Category:dropped
                        Size (bytes):322260
                        Entropy (8bit):4.000299760592446
                        Encrypted:false
                        SSDEEP:6144:dztCFLNyoAHq5Rv2SCtUTnRe4N2+A/3oKBL37GZbTSB+pMZIrh:HMLgvKz9CtgRemO3oUHi3SBSMZIl
                        MD5:CC90D669144261B198DEAD45AA266572
                        SHA1:EF164048A8BC8BD3A015CF63E78BDAC720071305
                        SHA-256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
                        SHA-512:16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC
                        Malicious:false
                        Reputation:high, very likely benign file
                        Preview:51253fe60063c31af0d295afb42228b0:v2:2:1:1590:2:8479:76bd602437550e98c9043d06a55186ab7d95dea5a0e935a599f73e62a8c9b158e0afcb19351f6c353940c06a38172b94d18c02cf92bb8a80184eccca0392b259ab3e71dae73e491c7941997cb36ad4a198661f622dad478d840f66d530a0dde78acea3367f91fff62fbb3dc18faff0c708ad30edef5bea8b22c5fd782b770d8993386eaa784fd19a3c3e1db3b537b1a94d3d4fbd46f8df8fddf6d16611969fe0a97c50e0f3ac24750c93257cf5c161184aa7385800c87d803b339632a3d8ec7fe17a0afd83ce9e9d0e3f7b8d579637928a811f1f7e6d1887df2ddc7d4f752c4d600235e426c92c7bf8a1362f95457998cc0e5d4261f0efa4fada0f866dbcefb407dacab7a2914e91c2f08200f38c2d9d621962145b1464b0f204b326118a53ecdcab22bff005fdd5257c99a6dc51ac0600a49f2ef782396987e78c08b846dad5db55e8ccefffc64863bc2c3e90b95a09d25d0814a848c98fe01a82d4e30e6682dd546e12c45ca0d280a45295ab4bd632dafb070edfdc3c9e38313d5aeb195972986f8011b66817028fd8c78b67a0ac7e780eecc3fb6a31f5a025b8a9a3db278a98c0696aeaac739b18688b0f9c7d751bba02cc5f4e41853fb119b3c0c915059aaa92971244a1989124f12881ca88e6410df70b793a2c3a736ff4
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:ASCII text, with no line terminators
                        Category:modified
                        Size (bytes):10
                        Entropy (8bit):2.6464393446710157
                        Encrypted:false
                        SSDEEP:3:LDn:Hn
                        MD5:DEC1BFBB774031235CA5A903E7FDAD50
                        SHA1:18795E395A16F5DE27E0A78145A55B1D8D0D6799
                        SHA-256:1EFBB8B937F9D5EE23161F823FE4903187E39EA69E2AAD197A42FB317BD0B9D4
                        SHA-512:24E6D84E9F20AA2A07AD019C0EAFEEC25979FF369C5FFC9E3BED969B312BE01EAE58CA450A375F570497D523DFE40F1D75FD3B135028E1261C3805F5C77E37F1
                        Malicious:false
                        Reputation:low
                        Preview:1730299966
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):180288
                        Entropy (8bit):5.291005839302416
                        Encrypted:false
                        SSDEEP:1536:ki2XfRAqFbH41gLEwLe7HW8QM/o/NMOcAZl1p5ihs7EXXOEADpOoagYdGVF8S7CC:uPe7HW8QM/o/aXbbkx
                        MD5:A735D9FC80F5214F26B649E2D6B3E572
                        SHA1:BE8001637537B10DD130C860DC2C85C4272115B6
                        SHA-256:9FEEAF83C551A92AC42FFFB75AEA865E12148BA9268603678222D727CF96626F
                        SHA-512:8DF056C5745CF5A8275AFB6EE68C61F5D44A244AD16182623FBD9DAA99649038CC121FC567F1B689EEB179EEC7C689A44B5132CEECEC8C62EC39E2EF56DE4E2F
                        Malicious:false
                        Reputation:low
                        Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-10-30T14:52:38">.. Build: 16.0.18222.40125-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:SQLite 3.x database, last written using SQLite version 3034001, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                        Category:dropped
                        Size (bytes):4096
                        Entropy (8bit):0.09304735440217722
                        Encrypted:false
                        SSDEEP:3:lSWFN3l/klslpEl9Xll:l9F8E+9
                        MD5:D0DE7DB24F7B0C0FE636B34E253F1562
                        SHA1:6EF2957FDEDDC3EB84974F136C22E39553287B80
                        SHA-256:B6DC74E4A39FFA38ED8C93D58AADEB7E7A0674DAC1152AF413E9DA7313ADE6ED
                        SHA-512:42D00510CD9771CE63D44991EA10C10C8FBCF69DF08819D60B7F8E7B0F9B1D385AE26912C847A024D1D127EC098904784147218869AE8D2050BCE9B306DB2DDE
                        Malicious:false
                        Reputation:high, very likely benign file
                        Preview:SQLite format 3......@ ..........................................................................K.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:SQLite Rollback Journal
                        Category:dropped
                        Size (bytes):4616
                        Entropy (8bit):0.1384465837476566
                        Encrypted:false
                        SSDEEP:3:7FEG2l+f/k9/FllkpMRgSWbNFl/sl+ltlslN04l9XllF:7+/lMkvg9bNFlEs1E39t
                        MD5:9C0D10288FB152C0C81417668AF29079
                        SHA1:26F38C1C913970633BEF85702467203F94B236D0
                        SHA-256:BE8438887160665083F679A2099B96A33F4D9413B9C53263341AD32745A7BA50
                        SHA-512:92B0EEB9CEEE77E0FD509F2137CF22C68C4E71B04471B2D95F9AB11FCE8EE5F1258C2FCBF08DEDDB993BC2E00D287CAD53D66B51B4487F896C81BE259398E772
                        Malicious:false
                        Preview:.... .c.....#..`....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ ..........................................................................K.................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):32768
                        Entropy (8bit):0.04482848510499482
                        Encrypted:false
                        SSDEEP:3:G4l2lgqvbZx4l2lgqvbZA8lL9//Xlvlll1lllwlvlllglbXdbllAlldl+l:G4l26m4l26V0L9XXPH4l942U
                        MD5:C8CF9C70CCFF0D19C8FFEDE231AF1FB4
                        SHA1:1EBA5F1D5CECA2E4F80CE0CAABA99001D090A818
                        SHA-256:9F8C63C285B03A89337B1EFA89936D5A6E6090769A88CAE920459CABEE8E1284
                        SHA-512:500A2E99DE1BC46E944A3052A36F16F00D1C0F334125B1A840F6C4E8DD0312CCF32B9F375180D2033C737C6304D11D5A2CA7F8E4068710ABCDF1A652B11CB137
                        Malicious:false
                        Preview:..-.......................](.Y....Uyi...Q.>...{...-.......................](.Y....Uyi...Q.>...{.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:SQLite Write-Ahead Log, version 3007000
                        Category:dropped
                        Size (bytes):45352
                        Entropy (8bit):0.3941679129281351
                        Encrypted:false
                        SSDEEP:24:KvRwjNQMIzRDf7IjkBill7DBtDi4kZERDfQHjUxqt8VtbDBtDi4kZERDf8jq/:yRUNQj7YkBill7DYM76UxO8VFDYM7o
                        MD5:D6868B706E568718548B3217D82DFBBA
                        SHA1:67601F64C04F96E177C3B53ACADDD6B67026011C
                        SHA-256:4D67E285FE1FA26FD612818DD517FE0C2E6C75EEC7376154E789E209156B3B12
                        SHA-512:1B3F381D6283DEAC3AD7A3CC6237A6ADD8413EFD1566EA1F49539F07DA7FAA2379B8AEC527866FB9587BEC821CAFDE3007F714EAF7E34BBBE70D9C5AFBDC6788
                        Malicious:false
                        Preview:7....-............Uyi...N<...*............Uyi...~....@.SQLite format 3......@ ..........................................................................K.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):3260
                        Entropy (8bit):2.8577186720342564
                        Encrypted:false
                        SSDEEP:48:E0L8r/Lv6Lnl147D9wNChssdOLvFfaGdjv4d:E0L+GLlO7D92CaWkpm
                        MD5:4920AC28727A2511D3023F9F1744EBDE
                        SHA1:7AD5126D32C021648C42468D4363BA586F9D0D38
                        SHA-256:E6EC96ACFD930C18275076C9DAC0C1BFA75AF3785C1C9919ECE49923E461D648
                        SHA-512:B626425AB6E62CFDF179156AB1DE99D480F7605C73231F59939E7DF0CB629F002E21174544944D555CD3703AB9F78869F8A5634C7F542429B6B30C8CC63BA38B
                        Malicious:false
                        Preview:....B.o.b.,. .a...f.i.l.e. .h.a.s. .b.e.e.n. .s.h.a.r.e.d. .w.i.t.h. .y.o.u. .f.r.o.m. .y.o.u.r. .o.r.g.a.n.i.z.a.t.i.o.n.:...G.o. .t.o.....................................................................................................................................................................................................................................................................................................................................................................................................~...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:ASCII text, with very long lines (28737), with CRLF line terminators
                        Category:dropped
                        Size (bytes):20971520
                        Entropy (8bit):0.16142950385581745
                        Encrypted:false
                        SSDEEP:1536:IaEqwP6+qjTjD+wcAl/mKtf1eMXEvfavREUE3plj5Bk7QZDP67BN:wPd8L+wx3chZ
                        MD5:3F2AAF8A97C45934608B0AAC980D8C24
                        SHA1:181B3550005B208B3DD7FC62727310C455471C6F
                        SHA-256:319F562F645F65B66AF588BECD443AC8CBF30C5FF0CE9AE1085BAC72293B0547
                        SHA-512:7EB59DEEE1D8410D5830DF01A9AAEE96AABB708008228428C703E99FDDA888B57ED9473EC6EFA50C38710FEAEF3CB45DDE9F68093310F6FECFE9EA1F7D886C6B
                        Malicious:false
                        Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..10/30/2024 14:52:35.189.OUTLOOK (0x1C70).0x1C74.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":21,"Time":"2024-10-30T14:52:35.189Z","Contract":"Office.System.Activity","Activity.CV":"BFYVw0RMSkaflW7G4ZF54w.4.9","Activity.Duration":13,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...10/30/2024 14:52:35.235.OUTLOOK (0x1C70).0x1C74.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.ResourceClient.Deserialize","Flags":30962256044949761,"InternalSequenceNumber":23,"Time":"2024-10-30T14:52:35.235Z","Contract":"Office.System.Activity","Activity.CV":"BFYVw0RMSkaflW7G4ZF54w.4.10","Activity.Duration":10973,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.JsonFileMajorV
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):20971520
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3::
                        MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                        SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                        SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                        SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):94208
                        Entropy (8bit):4.457040971972012
                        Encrypted:false
                        SSDEEP:1536:KQ4uE95pQXtOxTZGR/nDHIlR1KA/AI/FJpdvjiys9z:b4uErpQX0xTZGR/nDHIlR1KA/AI/FJp2
                        MD5:6A9969D396BF790C7F9A5CFBB4895A52
                        SHA1:3D22CA1C760A0915E8AA4A44BB75AB188049D439
                        SHA-256:56CA8727AC37C11D056EFCDB53553F6C7DAA4E6FD20E15E2C57610493F66239C
                        SHA-512:9C449A6DF3C47C9CA7092BF27AEB632BF588CE6386A75540D7789E05B9C4B96DCD1D68AECA7F8AE2069000AD143F05BC45E9161AB04C7E1B9B7D4BCD54101E0E
                        Malicious:false
                        Preview:............................................................................d...t...p......Z.*..................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1............................................................}..[..............Z.*..........v.2._.O.U.T.L.O.O.K.:.1.c.7.0.:.4.0.1.1.e.a.f.0.e.c.6.a.4.a.5.7.a.d.2.6.f.7.7.1.8.3.8.8.9.2.d.3...C.:.\.U.s.e.r.s.\.h.u.b.e.r.t.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.1.0.3.0.T.1.0.5.2.3.4.0.8.9.2.-.7.2.8.0...e.t.l...........P.P.t...p...2k.Z.*..................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):163840
                        Entropy (8bit):0.3760740323536154
                        Encrypted:false
                        SSDEEP:192:d/Trxpf59w2r5iYqMBvK1Ai1v/Ngz0XHW5OAqAbAFAqHNh/:dJpr9qeikz0XHhAqMu
                        MD5:25AC992840771D23E85B95832F021A3D
                        SHA1:9FF98035FAF0B26C710534FEC732907ACD53F89A
                        SHA-256:99DE48F9BDC6402AB46831C301932DD148D6B94ADFFFECA03371637D898C1649
                        SHA-512:2E5963685BF05C39AE2E57DE9D5063DAC95E5E16BB18834C504A7EB61DB10061B630B16601E621E52F6E44B14E61A434DD1963FEF4652523C725839B5BB2AF7D
                        Malicious:false
                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):30
                        Entropy (8bit):1.2389205950315936
                        Encrypted:false
                        SSDEEP:3:j2t:
                        MD5:1BD4FCD057DD9BD25CEF018E34EA695E
                        SHA1:15404AE639E01EA7833B2361A151632740BDD33A
                        SHA-256:27ECF37009427E29B42361D1351F65A3A94DE2129F56A3127DE901D33D193809
                        SHA-512:2B8A22EFF02B57297DE5104716951BD557701D94D18E741CAAC4C228E4B442A5687EE0AE909E6CC45EF3DB53700A07EF600A9817D9F2CE7B3366A11F800DAD38
                        Malicious:false
                        Preview:..............................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Composite Document File V2 Document, Cannot read section info
                        Category:dropped
                        Size (bytes):16384
                        Entropy (8bit):0.6691811761010779
                        Encrypted:false
                        SSDEEP:12:rl3baF5VqLKeTy2MyheC8T23BMyhe+S7wzQP9zNMyhe+S7xMyheCom:rjmnq1Py9617
                        MD5:FB3BCFDA1115564B27A09F6D1BF12960
                        SHA1:B73DFEDBCAD1C472B1925E213DC4B76965243E01
                        SHA-256:B8E0FCD5E2B5E86BAC9D27D35DB629FEF80082D5168B0C5FC261345C6C7577BB
                        SHA-512:DE769FFE876995304F0A5737B39E23BC98416D23D762A209ADC2C712BF641089927AF0D379B2E52F357B9E5EA3D278C82B6565337BAF5A6E2471C9B7493969B8
                        Malicious:true
                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:Microsoft Outlook email folder (>=2003)
                        Category:dropped
                        Size (bytes):271360
                        Entropy (8bit):1.4154809057986373
                        Encrypted:false
                        SSDEEP:768:ZQc+SfWcaMdjQLTcPRZ8kwfp67sNflmOGbZhb8BUTIZ:LrHmkPv8XJq7beNZ
                        MD5:42FD9C361CB9B7D82397F8BADB433F67
                        SHA1:419AC7DE4F9F28D66D66A2ADE76B4F487A15BB98
                        SHA-256:9DDB822C13FC50A9A4B18C8B74C2ECD1EE5E4CD02E7EECC8385EFC13416451DD
                        SHA-512:1FE044B983DD4D3534824F0B7A72BA534089C82F7BECC13B69A646CA353812B4EB56693776FF73359E31D9E9D443267354114A0FF6A1F68C892E2CD0A2A866E3
                        Malicious:true
                        Preview:!BDN..zSM......\.......................\................@...........@...@...................................@...........................................................................$.......D......@:.......................|...............r..................................................................................................................................................................................................................................................................................H........p7.*j......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):131072
                        Entropy (8bit):1.6852923629600458
                        Encrypted:false
                        SSDEEP:384:5DPktKjxl1pS4MRf0q+tdTy/LGNkFd9QW+Wbl7umX1RzFE9G0yYjTIXJWhDeFqHR:1sezjmDG2vXe8BUTIZWh3gLXec
                        MD5:ED9057F93AA75118B060C74A9CEEF77D
                        SHA1:96446C037F8E1CC86B49185F278B2D0DC4014511
                        SHA-256:4FB9F1EDE39B0C476E1182A12873E4BA6B32914980FFED124186961AC12B20B8
                        SHA-512:78ACD3CCE7A681D34E56A9B0E5121948E885703645316239878274B5D55E16A2C562134CD17BB24ABD58ABE4E07F14C8A1050D07311183C32EA7E540D9D9B140
                        Malicious:true
                        Preview:.T.C...B.......p...x..X.*....................#.!BDN..zSM......\.......................\................@...........@...@...................................@...........................................................................$.......D......@:.......................|...............r..................................................................................................................................................................................................................................................................................H........p7.*j..x..X.*.......B............#.........................................................................................................................................................................................................................................................................................................................................................................................................
                        File type:CDFV2 Microsoft Outlook Message
                        Entropy (8bit):7.420184208256136
                        TrID:
                        • Outlook Message (71009/1) 58.92%
                        • Outlook Form Template (41509/1) 34.44%
                        • Generic OLE2 / Multistream Compound File (8008/1) 6.64%
                        File name:'Weekly Finances Report' has been shared with you-1.msg
                        File size:228'352 bytes
                        MD5:76a9e1e12ffbde07994fc959c17b2488
                        SHA1:2fb82d6301373b16e1300d5262475e676802d110
                        SHA256:6647c5d474e7cacdeaf2982d9226c00580de9bfcd6d4ca5d097b62bebbdea701
                        SHA512:ea5b8f9eae0f50b94d4ceba4836f13df167e73703be41d4e77be384a2e792eeba918e58b839655f4109c107c25228702c2d3d075c56cb5cc30e27fdff4defa68
                        SSDEEP:3072:BVUtwEiKCMiKw92pRgj0OuGSS3NuurKiw7rj3EWKp8r+z5BqoCiqFo7UuCsHP:DUqwgjp3SYuyReEWK2IBuiqFcURC
                        TLSH:EF24C0283AE94219F27ADF31DCE644D7D611FC46ED10EB8F3196730E1A71980B953A2E
                        File Content Preview:........................>.......................................................a...b...c......................................................................................................................................................................
                        Subject:'Weekly Finances Report' has been shared with you
                        From:OneDrive <no-reply@notice-onedrive.com>
                        To:bwallman@palliser.ca
                        Cc:
                        BCC:
                        Date:Wed, 30 Oct 2024 15:45:47 +0100
                        Communications:
                        • Bob, a file has been shared with you from your organization: Go to <https://token.onelogin.com-token-auth.com/Xa0Y1MmVibVhmY0E5dnlabzhVK2w2MVo4bXZUM3RzTFBZU1FSUEYxRHlzb29tODRTUDQ4alBDR3Y1cWUvN1JvVzhtWGVkaHFaSG0rOVpUTVV1VjY2a3MvZDB6TktwTHhsRk9xdzQwQjV6YjIvcnA5MjFsaFJEamtNdXI5UXQ1Qm9lK0ZsZFd0TXI0R2JWWlVYeFFXa2pBaXZOKzR2QXRkUTd3dlBLNzUrQ1RweERVMmQ5ZHQwdjlKZ2dlS2tEVUF5UEE9PS0tdFFWWndQdklZQXNodTY1US0tUXAyU1llVHhDaXRTRjU1OVNWMXFNdz09?cid=2262276963> Weekly Finances Report <https://token.onelogin.com-token-auth.com/XaFNXZmZxdFUzWDFPWVFxY2lia3BpYkY4UHdlcTNmZStWYjZidGFaMXFldkJJUk9VdmZTZVQxRk5QbVBlVFlJNGttbUlHcmViUysvaGcrWmRnbmwxLzZ6c0MrRWdVcEg1bHZtYnc4c2czNVlSUlhtdnRPc0gwWS9mZ3R4QTltZUZjdWZRZ1kvZmk0N2huS054TUFZUHJyNk4rNHcrNElWbjI0NWlrN2puRlNtYkx0ZzVhWExWcmpZbmt3PT0tLTFCMXhxTFNKS2ZOU3lIZTItLWtCRWhkMzBFQWZwNE0yN1QwM3BCT1E9PQ==?cid=2262276963> <http://officeblogswest.blob.core.windows.net/wp-content/2014/01/OneDrive-forBiz_rgb_EN_Blue.png> <https://token.onelogin.com-token-auth.com/XUm5aUU5RRGNzMjBtRzZMcllzdmpxTHBMMVJTT1J2Z1BUOTJmZmdScTdxL3M1SjZlQTk4RVg0YkpQN2ZtMWR4YmNhQXpEM0tQRTQvMVovd0I2em0wT25ENmZPZWcxWVJ3NkVhalVQc1VjRllWL29JTFhzVFAwZz09LS1sRkxiR0N6TVRJL1JWQmRqLS11dFhxWVBiSm0wSTlldndCckVlVFRRPT0=?cid=2262276963>
                        Attachments:
                        • weekly-finances-report.xlsx
                        Key Value
                        Message-ID<6722469b9cfd3_824a43169ad@169.254.137.29.mail>
                        Return-Path<noreply@psm.knowbe4.com>
                        DateWed, 30 Oct 2024 14:45:47 +0000
                        FromOneDrive <no-reply@notice-onedrive.com>
                        Reply-ToOneDrive <no-reply@notice-onedrive.com>
                        Tobwallman@palliser.ca
                        Subject'Weekly Finances Report' has been shared with you
                        Mime-Version1.0
                        Content-Typemultipart/mixed;
                        Content-Transfer-Encoding7bit
                        X-PHISH-CRID2262276963
                        X-PHISHTESTThis is a phishing security test from KnowBe4 that has been
                        dateWed, 30 Oct 2024 15:45:47 +0100

                        Icon Hash:c4e1928eacb280a2
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 30, 2024 15:52:48.569761038 CET53610651.1.1.1192.168.2.8
                        Oct 30, 2024 15:53:18.819318056 CET5354148162.159.36.2192.168.2.8
                        Oct 30, 2024 15:53:19.510416985 CET53640181.1.1.1192.168.2.8

                        Click to jump to process

                        Click to jump to process

                        Click to dive into process behavior distribution

                        Click to jump to process

                        Target ID:0
                        Start time:10:52:31
                        Start date:30/10/2024
                        Path:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                        Wow64 process (32bit):true
                        Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\'Weekly Finances Report' has been shared with you-1.msg"
                        Imagebase:0x1d0000
                        File size:34'446'744 bytes
                        MD5 hash:91A5292942864110ED734005B7E005C0
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        Target ID:3
                        Start time:10:52:40
                        Start date:30/10/2024
                        Path:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "143D4FE8-01BA-4276-95D5-3E05BC125111" "7244AA12-D62A-4B2F-A63D-2B351ACC5F92" "7280" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
                        Imagebase:0x7ff71dc80000
                        File size:710'048 bytes
                        MD5 hash:EC652BEDD90E089D9406AFED89A8A8BD
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high
                        Has exited:false

                        No disassembly