Windows
Analysis Report
FW Expiration Pending Support Care HIPAA Acknowledgement Form 2024.eml
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- OUTLOOK.EXE (PID: 6896 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\OUTLO OK.EXE" /e ml "C:\Use rs\user\De sktop\FW E xpiration Pending Su pport Care HIPAA Ack nowledgeme nt Form 20 24.eml" MD5: 91A5292942864110ED734005B7E005C0) - ai.exe (PID: 6192 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\vfs\ ProgramFil esCommonX6 4\Microsof t Shared\O ffice16\ai .exe" "7A8 78081-2B7C -49F8-B191 -8B71F04F6 AFC" "7D45 DD20-BFB0- 4C1B-8DE0- 1C5790D14B FD" "6896" "C:\Progr am Files ( x86)\Micro soft Offic e\Root\Off ice16\OUTL OOK.EXE" " WordCombin edFloatieL reOnline.o nnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD) - chrome.exe (PID: 2980 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// na3.docusi gn.net/Sig ning/Email Start.aspx ?a=52a62e0 8-52ab-4de b-9961-052 cba101116& etti=24&ac ct=07df84b 5-c8f5-4e7 f-a831-b60 5f464f6f9& er=4156e78 7-bddd-48b f-b932-532 9c6a60a23 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA) - chrome.exe (PID: 7056 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2124 --fi eld-trial- handle=198 0,i,266719 6118707451 285,131808 9279766632 9255,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- cleanup
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | OCR Text: |
Source: | HTTPS traffic detected: |
Source: | Memory has grown: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: |
Source: | Key value queried: |
Source: | Window found: |
Source: | Window detected: |
Source: | Key opened: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | Key value created or modified: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | Process information queried: |
Source: | Queries volume information: |
Source: | Key value queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 2 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Modify Registry | LSASS Memory | 12 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Extra Window Memory Injection | 1 DLL Side-Loading | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Extra Window Memory Injection | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cdn.optimizely.com | 104.18.65.57 | true | false | high | |
www.google.com | 142.250.181.100 | true | false | high | |
api.mixpanel.com | 35.190.25.25 | true | false | high | |
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | 84.201.208.68 | true | false | high | |
arya-1323461286.us-west-2.elb.amazonaws.com | 52.43.183.255 | true | false | high | |
na3.docusign.net | unknown | unknown | false | high | |
a.docusign.com | unknown | unknown | false | high | |
docucdn-a.akamaihd.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
52.113.194.132 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
52.43.183.255 | arya-1323461286.us-west-2.elb.amazonaws.com | United States | 16509 | AMAZON-02US | false | |
35.164.51.148 | unknown | United States | 16509 | AMAZON-02US | false | |
172.217.19.227 | unknown | United States | 15169 | GOOGLEUS | false | |
172.217.19.238 | unknown | United States | 15169 | GOOGLEUS | false | |
104.18.66.57 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
104.18.65.57 | cdn.optimizely.com | United States | 13335 | CLOUDFLARENETUS | false | |
172.217.17.67 | unknown | United States | 15169 | GOOGLEUS | false | |
172.217.17.78 | unknown | United States | 15169 | GOOGLEUS | false | |
20.42.65.84 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
23.64.59.59 | unknown | United States | 812 | ROGERS-COMMUNICATIONSCA | false | |
52.111.252.18 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
84.201.208.68 | default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | Poland | 34390 | NPLAYTELEKOM-AS-PONPL | false | |
23.218.208.109 | unknown | United States | 6453 | AS6453US | false | |
142.250.181.100 | www.google.com | United States | 15169 | GOOGLEUS | false | |
64.207.218.235 | unknown | United States | 62856 | DOCUS-6-PRODUS | false | |
35.190.25.25 | api.mixpanel.com | United States | 15169 | GOOGLEUS | false | |
74.125.205.84 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
23.54.81.216 | unknown | United States | 20940 | AKAMAI-ASN1EU | false | |
52.109.76.243 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
IP |
---|
192.168.2.17 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1562769 |
Start date and time: | 2024-11-26 00:57:12 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | FW Expiration Pending Support Care HIPAA Acknowledgement Form 2024.eml |
Detection: | MAL |
Classification: | mal52.phis.winEML@17/80@24/226 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, backgroundTaskHost.exe
- Excluded IPs from analysis (whitelisted): 52.113.194.132, 23.218.208.109, 52.109.76.243, 23.64.59.59, 23.64.59.19, 52.111.252.18, 52.111.252.16, 52.111.252.15, 52.111.252.17, 84.201.208.68, 64.207.218.235, 23.54.81.216, 23.54.81.195, 20.42.65.84
- Excluded domains from analysis (whitelisted): omex.cdn.office.net, na3-da.docusign.net.akadns.net, slscr.update.microsoft.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, a1737.b.akamai.net, login.live.com, e16604.g.akamaiedge.net, onedscolprdeus02.eastus.cloudapp.azure.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, na3.docusign.net.akadns.net, a1864.dscd.akamai.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, prod-all.naturallanguageeditorservice.osi.office.net.akadns.net, prod-inc-resolver.naturallanguageeditorservice.osi.office.net.akadns.net, ctldl.windowsupdate.com.delivery.microsoft.com, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, docucdn-a.akamaihd.net.edgesuite.net, fe3cr.delivery.mp.m
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: FW Expiration Pending Support Care HIPAA Acknowledgement Form 2024.eml
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 3.471639254206456 |
Encrypted: | false |
SSDEEP: | |
MD5: | 75FAE2659A70261DE8AA9972E3B4BE17 |
SHA1: | 3BFFBF6FDE223F37AD01F9E3D20CBC70405C03C0 |
SHA-256: | DB391338A43494301C50D005D3C019AF70660E4E7F88E2C496E32F2401D22E1C |
SHA-512: | 361AC0B9620780FF3AE4B03F03926D319B6F00F3A5AEC747DB89B9CD064BAD2BA6CB839F036CF7285E4F4E148CA5D70EFFEB736EB2A04C22B3E2C2540E7FC40D |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 231348 |
Entropy (8bit): | 4.391049036419561 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3B6B7A6CF6DD8AD35564A10CEAECDD50 |
SHA1: | 1628E0464BA8EA356AE240F80F441A6E0FEEB4B1 |
SHA-256: | 4B6EA29C753824B00B10ABF022715649E1B00E3BA8312F6DACE4BC91FDD178DE |
SHA-512: | DF2E997461F09DE45AAC5233EBA2007313D289217408329F776F0AB4B0896F5DED086D54974DD7D7B5B833FE5B1216C445D8C51DBFCCF0304AEFD91A07879A39 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 1869 |
Entropy (8bit): | 5.088726879529934 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4EEA7CFA81FD72200ADB72D5161EA722 |
SHA1: | CB2AD6B7DE2F7AB42FE5592E3766856C5FDF0DA7 |
SHA-256: | 3E1C7280ACBC7B833DBAC7AF8190006BED1643D73142B7CA866970913C08C5BB |
SHA-512: | A1A2053BA3B21A4BE1713E88C25C5CADA60A343F40F84CA6E060ACF1E485C72E40C800B5FE5A4F339787B8A6D969A8AD84F434AA3D835CE3C74CC9CAFAF87ACA |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 521377 |
Entropy (8bit): | 4.9084889265453135 |
Encrypted: | false |
SSDEEP: | |
MD5: | C37972CBD8748E2CA6DA205839B16444 |
SHA1: | 9834B46ACF560146DD7EE9086DB6019FBAC13B4E |
SHA-256: | D4CFBB0E8B9D3E36ECE921B9B51BD37EF1D3195A9CFA1C4586AEA200EB3434A7 |
SHA-512: | 02B4D134F84122B6EE9A304D79745A003E71803C354FB01BAF986BD15E3BA57BA5EF167CC444ED67B9BA5964FF5922C50E2E92A8A09862059852ECD9CEF1A900 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\FontCache\4\PreviewFont\flat_officeFontsPreview_4_40.ttf
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 773040 |
Entropy (8bit): | 6.55939673749297 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4296A064B917926682E7EED650D4A745 |
SHA1: | 3953A6AA9100F652A6CA533C2E05895E52343718 |
SHA-256: | E04E41C74D6C78213BA1588BACEE64B42C0EDECE85224C474A714F39960D8083 |
SHA-512: | A25388DDCE58D9F06716C0F0BDF2AEFA7F68EBCA7171077533AF4A9BE99A08E3DCD8DFE1A278B7AA5DE65DA9F32501B4B0B0ECAB51F9AF0F12A3A8A75363FF2C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bin
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 322260 |
Entropy (8bit): | 4.000299760592446 |
Encrypted: | false |
SSDEEP: | |
MD5: | CC90D669144261B198DEAD45AA266572 |
SHA1: | EF164048A8BC8BD3A015CF63E78BDAC720071305 |
SHA-256: | 89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899 |
SHA-512: | 16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bin
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 10 |
Entropy (8bit): | 2.6464393446710153 |
Encrypted: | false |
SSDEEP: | |
MD5: | B288ACEAA981E02B301499F8E860ABAE |
SHA1: | 853ED7283145A8469989AFD0F77EAA39DF0A4A74 |
SHA-256: | CABC11EF29CAA0E7209BF952B6BAE07F845C5EFF2D1E26D69F75309634DBB4F9 |
SHA-512: | 9ED5497B42DAD05A8C92D470CBECEB546B545BFA56A428E1C5AA08D38B51CC15A7E0909EF9C7BB4A7AB1F712F811CD852FFE1781CCB7DC180DC51A39682E9D80 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4096 |
Entropy (8bit): | 0.09216609452072291 |
Encrypted: | false |
SSDEEP: | |
MD5: | F138A66469C10D5761C6CBB36F2163C3 |
SHA1: | EEA136206474280549586923B7A4A3C6D5DB1E25 |
SHA-256: | C712D6C7A60F170A0C6C5EC768D962C58B1F59A2D417E98C7C528A037C427AB6 |
SHA-512: | 9D25F943B6137DD2981EE75D57BAF3A9E0EE27EEA2DF19591D580F02EC8520D837B8E419A8B1EB7197614A3C6D8793C56EBC848C38295ADA23C31273DAA302D9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4616 |
Entropy (8bit): | 0.13700485453793962 |
Encrypted: | false |
SSDEEP: | |
MD5: | 52145A21FF960A4754322BD17B6C46A4 |
SHA1: | 1D8D712612292A20CDA27889C776740F62A7463B |
SHA-256: | 79614FB5AB1AE205998FB10FF6868DD7FA9BAFEACA73D0D92528A1A0E57F5EC9 |
SHA-512: | CF6C5EF626F286B13ED9C4FF0794C239F908D5F99D4E38ECC63979F81C76F18674D15747789D5F9A0B82BAD958F006140E5116AFCB30A941BA09F7BF8F392D07 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 0.04450027198542196 |
Encrypted: | false |
SSDEEP: | |
MD5: | FFAE20A77367BB1487DF5D358FF895BA |
SHA1: | 81A30567D0E8904B87726774942FEA1237250EF1 |
SHA-256: | C1D08E8816341597C91D611B6963F12D0627594A494ED1EC74E6B0147F55F0B4 |
SHA-512: | FBBBDB1F5E7225E4F86469774D612563D3D6C8EEA7DF81ED1AF21B5C90A95558B9C990F89DCDC94D3900FD64AA7FFEC35938CC0CE1993DEB1ED45CA3691FC13E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 45352 |
Entropy (8bit): | 0.393626816947564 |
Encrypted: | false |
SSDEEP: | |
MD5: | D4E56BA6F1377EA1744911370869F247 |
SHA1: | CF3BE9DCE0B3AF400EAE4C22E9708250ADB1864D |
SHA-256: | 84C4419100BBDC2F344B6CDFE48B4BE1D8205DF310E0D20DC23C842D741D0AE5 |
SHA-512: | BF50CF4454F4BA6DE2BB7F78F87CB16D87E76900466A1E5D89F5DF80D3A5727E3727AC45194B1250F9E19D97C42659E1D6BAE47031E916696366C8CBE03E47DB |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2278 |
Entropy (8bit): | 3.8539686727831954 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2EDB5F0E85B58450024DF15DB9220E1D |
SHA1: | E6D730B34DBEB17695A216564AE5B827A0052F2B |
SHA-256: | E45D827344C6EBD6A4BD7F20CDF70434B596CFC613FE0AB88253FF01FD805940 |
SHA-512: | F725E0E5BDDA493579A316975316186671CCB70071D63CF8C21B1EC5B5E532CB556D3F88F21DA5CFF6C1C0AB4AFED4A1600E65C8D58D8B8CB0E953D3C6A99ACF |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2684 |
Entropy (8bit): | 3.908282060671273 |
Encrypted: | false |
SSDEEP: | |
MD5: | 467A0EE6A55C8419E88FB936C2AFCC75 |
SHA1: | 7DCAEAA35E069A182A1CCDFE6F128E69DA3F3BF3 |
SHA-256: | 533E36F086EC2552D4F12C2BD7C32E99FAE087C933D3CE487297DED2B954FB61 |
SHA-512: | 7FB18292AD1F2BCF9771C9EF11802AA3B33E1990551118FDFAE12C5D095EF6E6964568AE291523293026EB296787DBC8988D43EE55F16E19279AEF091FBC5559 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4542 |
Entropy (8bit): | 3.99342278617096 |
Encrypted: | false |
SSDEEP: | |
MD5: | FC78E18C6668418868D3D3C12CABE6D1 |
SHA1: | 9974737DF32C61AE1104E5E5B5F64081E1CB114A |
SHA-256: | DAC1B43D0AED89BE7E9762F31A604035D4F4D75C6A301CD74A342BB52BDCB065 |
SHA-512: | 55106B92431D04E41E6BC9DCF020DC8A6BC17743AC89D34A4D3C6A4784C49605859A6824E67F0B90BBAED34F6E335338D2498F5AE50C7284C9699E929C4D90D7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1782 |
Entropy (8bit): | 5.77311811423247 |
Encrypted: | false |
SSDEEP: | |
MD5: | 834A4209CE463FEE69EA2D053CEB95BF |
SHA1: | 0C4456B733F1F8A823BD3B3AC71766A5FBA2B326 |
SHA-256: | 8B6CB44CE509E5AC3E586EFC604FAC0831E861B70A042C9F984A54A511F41F54 |
SHA-512: | 6F297D563391ED11B46D5F2CEDE2DA013569AA9678C9CBC7401C19739E235D5B1C66B0B3688F8745DBE89E0A7F5FBE85EBA2293F01C099923F4F810436822A15 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{02002EA7-6A12-4C04-BAE1-9ED0B06E93A9}.tmp
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 49088 |
Entropy (8bit): | 4.160289326139006 |
Encrypted: | false |
SSDEEP: | |
MD5: | 01F33155C998260E4B2EBEDF3A6F74E7 |
SHA1: | 327623684585D0A4F2488E074E7A703B2F0E8225 |
SHA-256: | C728EFD46DC36685C65A99D77E40361EC9B17B246DCB788B0BBE69462A4A4CCF |
SHA-512: | 1D019AA8FD187F8EC0F6F3152DF9E276245A71D709F406C45D9A1C04D8B50684B686E5A16D2EAE06729D6D8CF327A91CF1703E99CB5A2B2DF541C4A6EFB47FCA |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 32966 |
Entropy (8bit): | 7.976643656543348 |
Encrypted: | false |
SSDEEP: | |
MD5: | FF815D5C160DCF604CC8C1CE3EB4B480 |
SHA1: | 6E582061703AE0800D59A951654D34F03AF6566F |
SHA-256: | 832FFA5710A9C9D96248CDD073AB2145B3A70AFF5831685F5BE4885D8AD1193A |
SHA-512: | FAAEBB481D5B869C7FC6D35912BF0408271A73F1299B988D51BFDD27AAA7F3EFCECCEFBAD57C195A173B30C3DA1757230DC3E4E5182CC628E90EEEF86CF01262 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2042 |
Entropy (8bit): | 7.773707672923882 |
Encrypted: | false |
SSDEEP: | |
MD5: | 96D8807F272D946A37AD501C0E688BD4 |
SHA1: | 1AB2289435C63BC32BD76968F5B5AC421A50DF59 |
SHA-256: | DA97D0D672285ECAAB74BCE2B8D40B178759FC099A1DE15A60BA199B864A7888 |
SHA-512: | 67B9D41EF400E726A4FC96AEDDE1DB56804A9C8BD8C0DD76A25DEF9A321499CB3504F01FB4C664EB9D50AB206D656B8743E48C2A3F9C8E66FF9B5ADDB469A820 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\GO30WR0E\docInvite-white[1].png
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2555 |
Entropy (8bit): | 7.88910627682238 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6A78B0944A1DA4F3892D0F4A0163DA25 |
SHA1: | EDBEE8BAECF4D272F1B52BFA4C823DDC50E5486D |
SHA-256: | C9903CB4027BD617227A5F968C1B48883F9FFC3C140A629C418A413A3C14991C |
SHA-512: | 1ECB84B1B369B7CF3BFA9184B527B9AB5885B1A8BE20A4AA408619D769379DC96ED56616400149381F14204C193FF359C86D7A7113089C6510A109705BF0C089 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 2684 |
Entropy (8bit): | 7.901894652512653 |
Encrypted: | false |
SSDEEP: | |
MD5: | B4F8F0DCDA279711CB9224C2239323D4 |
SHA1: | 3C1B1B68CD9D2D25FF5D7FB2C7A61271DFFBF41B |
SHA-256: | 53D92718DD6001A4EBF49D631AB9DF5B8194E6AF220790B1D8CF57164E38C6B0 |
SHA-512: | E97F783AF2EECCAFD684BDDE181C1509414997D2970405CC2AD7B9182439EF471EE6BF58253E6661A7B4491DD80523CC23C4544B0F9CF5AA0E9BFF4F20E7CA92 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NB937L4Q\icon-download-app[1].png
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 445 |
Entropy (8bit): | 7.318768335834397 |
Encrypted: | false |
SSDEEP: | |
MD5: | E03518ED70845F60E54D995516FC7814 |
SHA1: | F70C7019C0989B62CC691B6CD34859D8FC506C01 |
SHA-256: | 6F1AE1C2D727A21E023D4C687EDBD6FB7AA97BE003E3B17E4E6A2505F2B2B82C |
SHA-512: | D8E73BE08FDC026BF5733C276E165AB9E93F562F99A4AFAAC46C9097CB6CE80FC45BA0FF9733391EC1A51727B1A1715394D03F6F167CFA22D8B4720D053B7E22 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1732579067543392600_BA754FBE-C2D9-483D-A0C2-6E8BEEEF5CD7.log
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.01387970725849909 |
Encrypted: | false |
SSDEEP: | |
MD5: | A47052B1196462B404575F9E1382113C |
SHA1: | 4A2EE1E28A840470804ADC1FE6DDEC85595E1F34 |
SHA-256: | 35878CE05486EED1A29453C7EAC32C771F7A257A78066DF72DABC34054BBB499 |
SHA-512: | 8F430A5F7E4D0597F2DF7392BFB9D68EB7BBDD877F57F0572750223337002A5C48CE8A654CBBB703CE4D253490508360B93D2D27B68FD7BFA7398A92EAFDD893 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1732579067544139600_BA754FBE-C2D9-483D-A0C2-6E8BEEEF5CD7.log
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8F4E33F3DC3E414FF94E5FB6905CBA8C |
SHA1: | 9674344C90C2F0646F0B78026E127C9B86E3AD77 |
SHA-256: | CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC |
SHA-512: | 7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241125T1857470348-6896.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 204800 |
Entropy (8bit): | 4.896234251993631 |
Encrypted: | false |
SSDEEP: | |
MD5: | B890060E8B90E3020166E162C89C9A61 |
SHA1: | 23D9A350FDD9B0DCFC4DEACA5E6F6EB44362BD3B |
SHA-256: | DD30B511C3E78ECEFA22B70882D9E782114C488438E6313829AF2E9C33C38A4E |
SHA-512: | 261F5D6D3113017EB872B5BE97239882958DD2CD2E0D805A085F7EB0BDF0E81CB149ADF044C4449F5412E3E3C465D956C5256AE984DD04267148931C5D2AFE41 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 30 |
Entropy (8bit): | 1.2389205950315936 |
Encrypted: | false |
SSDEEP: | |
MD5: | 40B0707A5CD82D7B8E8BC2817A27279D |
SHA1: | 53878CC0A90BED8C929E25A16E2C435792CF45E6 |
SHA-256: | 98FA4CEAC697E335BD5A68FB1D399E172C087E6CB756EFEA57D0D425479EA61F |
SHA-512: | B33E5FCF2409F621EC79D769F7848D44020A1E59281C4E8189547A600D6CBC51D06AFD7AED550CCD29DB63DA3B78F0DC1775967F71B9F965E59A7701931A8614 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.6697626309766027 |
Encrypted: | false |
SSDEEP: | |
MD5: | 185E94A7172C76D487A25E5935D26E34 |
SHA1: | 9C32179963228229F64D0E6B200B54ECCE5FAB0F |
SHA-256: | 9B084581FBC942A71668D0079E01036DE74E49A38C965B6DDCE05EDCC346FE21 |
SHA-512: | 22C779128F5D758ED252DD3226A44A8242EE7C730654B77E21F53F0461F8D02D09847AB8957D5D1D525239545F20773F62E17C4AC320B2F5A69683890925E787 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 18 |
Entropy (8bit): | 2.725480556997868 |
Encrypted: | false |
SSDEEP: | |
MD5: | A5E51FDFAF429614FB5218AB559D299A |
SHA1: | 262EC76760BB9A83BCFF955C985E70820DF567AE |
SHA-256: | 3E82E9F60CE38815C28B0E5323268BDA212A84C3A9C7ACCC731360F998DF0240 |
SHA-512: | 9B68F1C04BDE0024CECFC05A37932368CE2F09BD96C72AB0442E16C8CF5456ED9BB995901095AC1BBDF645255014A5E43AADEE475564F01CA6BE3889C96C29C9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.993141443191904 |
Encrypted: | false |
SSDEEP: | |
MD5: | 57F15829AF9DA04BA3CABBF5DDD14556 |
SHA1: | 0FC0569E437CF1EA6EDE4DB3AD13B04422E31A30 |
SHA-256: | 6F991BFF13391BC12D3C4B368B79CF320ABF5136BD966D93C6112399D7461452 |
SHA-512: | 78D745B390A5C7A2427B5DCA3A3973D212222A893D69EDA1CF922B654354C247EF74724C371F73A4E6BBAC4CF12FE52F022803A366C6DF9F2D86B69336A0F376 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.0087439057692045 |
Encrypted: | false |
SSDEEP: | |
MD5: | F543579C246844B8858FF714DEFCAF79 |
SHA1: | 7F7D7BFDED94ABE0BE5F69311AFE35253BEB63EB |
SHA-256: | 66096CECFA54E6ED7A7DA0F070AB45CF8CFAD71EFD3E5A3D92B1D93E115C24EF |
SHA-512: | 65364A0A24235940476260279988A6968576C870F8797AE2CB13B397617DD020740750EBA754B417D23A37982C8048DA73EB648E11D05A4D598E342C10ED7E37 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.017813334750449 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7696441C7F4F42D75FEE7F7EE636F834 |
SHA1: | B7DD3ADBD21AE39D06665116B16245ACDA9B0095 |
SHA-256: | FA5F87F4049C9779C928DB265ED99B8505E52BA466AFE8629CCD4D119B4B5704 |
SHA-512: | 1D00642144490B2CA3073707D8483EE05A8FE12D72D45F628BA6F31C5F8756BDD6597072829DB662461EF2BF69344AED039C0F6450637837EBDBD75FEADAFE88 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 4.0055939939081515 |
Encrypted: | false |
SSDEEP: | |
MD5: | 97B0F9492DC4136175907C923B166A51 |
SHA1: | 89FB97494D101B28293FAF3400FEDFF45E3E466E |
SHA-256: | 94F5CBF52B0DB7A625A402270178FA99BE6DBD16173084B23344C966D5A24A96 |
SHA-512: | A0E5353552447FB95949CC60ABB9B6BC2D473E65D0C0A7B5834424981722DC6C804B9A63D88EA29E71E6A251E74CD1FD0E3F8BCE8F5EBD5B7F89BB466A44C98C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9941367262172314 |
Encrypted: | false |
SSDEEP: | |
MD5: | A2CD18BF140409C94A127CB7DC2FAE03 |
SHA1: | 3F5E64E8CA3C506EB5994E32C9AFB49F7D5C2675 |
SHA-256: | 69F61F5F4EEFC454037C67B91BA5D903418B2AD39AA56A2B4EC76BEE7C825C62 |
SHA-512: | B467C51D7130AD80E89358344249EC07E639C45CD1BEFE88503C64624A9F75D9D2E317F9E0C63A2B2057A8FB66A49EEB9C33030E767BDAEDA7A4302D7CADE19F |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 4.004806605572436 |
Encrypted: | false |
SSDEEP: | |
MD5: | 203A186250E1D168FAB8319EC26D5FCD |
SHA1: | 9A110ABD0F8754FFB2CC9E8A437AA09F2E546243 |
SHA-256: | 062BEAAEAA94F00C36CE5876A893B81B9C667E6F17BB1A8D73D95403FFA25343 |
SHA-512: | E165BFEFC03E62649AA16C645B65692CA2D8294081675E72AD7EB06A3595D308A9FF8AEF5306E984C2CFADB10D4B16505783E59772F8BFF532BAA3E0446F4FBF |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 271360 |
Entropy (8bit): | 3.449416622308556 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2828ADA174AE5C92C0D1FC9A5BD6C31F |
SHA1: | 8BE90AB5ACCD3921AFAD4F640B96E73142E83DE7 |
SHA-256: | EB0C46B89DC959B47AB2E6BCD80CF7D4FBA2A90D6831795C651B9D1A411E7103 |
SHA-512: | FFA20B1219DD59B92EAF8F1F97C2881D0B2387F49BB6FD6CA0FC8ED234B3A2548C0C4CB1945865C828F80443B04AEECF93CBCCA077C677B965A290818F69DCF6 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 4.530887898272419 |
Encrypted: | false |
SSDEEP: | |
MD5: | 501A4B5C3D64819539C7D6AB06302E0B |
SHA1: | 2336132FBD4399A3B5F9C4B8CE03D4FCFCF92BF7 |
SHA-256: | 5BE0129A9A128F7EA7BC1FF702EEE5FEAA99F36D1D67592B72646FC9600D7BB2 |
SHA-512: | 1F76EC40AC9446B4F8556B48E90911720073A1715D4D1F23F5B004A191894088609F3E3CFA0A293B3D76CAB99B96EEE0C68921ED3045FFE38F0D4D5211367B16 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 31159 |
Entropy (8bit): | 5.242540707783587 |
Encrypted: | false |
SSDEEP: | |
MD5: | 48BC933608F733A9283F2218C73A941F |
SHA1: | E04E625C70A5E8505B77A51D82D9A73AFA9F3547 |
SHA-256: | FCBC395A3D24699D9229846A30C9FE245D77A7AFDBC8386838A03A837C6672AA |
SHA-512: | DED1BDD62FAAD01AF0B6F05A28A8D8721080B862EFDD5866EBDB4672A21A8EE15D3965B523C691784B7EF8817296707D5A3217F7B8CE713B212520EE9170329B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17500 |
Entropy (8bit): | 5.316856666332215 |
Encrypted: | false |
SSDEEP: | |
MD5: | BC03940CFAB2484BAC8A2D41FE9E4C53 |
SHA1: | 7E050C5FA27B3792A117745CBB1C63D42FF117EF |
SHA-256: | 0E1D410DD2C0ABB80B9FA543A104A97D927A411D3D8A81FE614BD7D6ECEF632D |
SHA-512: | D7099E1D5920D25683208C2DFF6122D4116D69E6141F0A6F7D5B0C1F0D1DF1DE69E139952A0BD809630527A93ED69E4310BF836E4D2850E3D7E4622E899C515C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 107050 |
Entropy (8bit): | 5.52879253457099 |
Encrypted: | false |
SSDEEP: | |
MD5: | C9A178E87EF9D67207B744DD8252556E |
SHA1: | 32A11476141AE8CC9E0881E56743DFA0DBC0843E |
SHA-256: | 4298AB8A22EEDA2DEEEACBA50E9AB4E86696CEF95E639F4ACB8DA89C8187809E |
SHA-512: | 24979165888C055E80601CB5787F8062127FF64BFDA8BFD18D0E5597557D832524E0731C8FEEE6F13F0143D305AF8E113033B07BBCA54F35F2A317E5F7F6ABF2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 119521 |
Entropy (8bit): | 5.282600334417372 |
Encrypted: | false |
SSDEEP: | |
MD5: | 57DF0E34273CB75DC3A46C4F4C805D84 |
SHA1: | 88D61F0784F25731D468B72F0F48319A112A0414 |
SHA-256: | 48E41A664A5F60ACEEAAA1C32BCC7FEBFEF091C3B79AA62F2429B03B18152F76 |
SHA-512: | A4DB244A0CABB4F33870A89D8AEE20F1D107CB8E7036D5B250113B1DF6FA8891ADDF10DC835246FAAB5B2E680AC73856B13AB99E5AD736E7C19431A4B4E442BE |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 903952 |
Entropy (8bit): | 5.339089010265062 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5B34F77F2A7BDCD695F205886AFC5F3D |
SHA1: | 90629FA500198EA078AC71FF3FBE0A7BB7EF9DC2 |
SHA-256: | 2726B24B18B694BB1992FFBFC096078BC5054EFF0A41E6CE32077178145D34F4 |
SHA-512: | 16AFA7360412D33A39DD62CB3E10DF88D21064BFE5A85CA74A3994B56688E608F928A11AE77C2ADAD35225961DD01D9979F9E552A8CD8598A52C6DF40AA27809 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 10045 |
Entropy (8bit): | 5.2965890952604955 |
Encrypted: | false |
SSDEEP: | |
MD5: | BEB8B66AB72084608723E3FE8054C93A |
SHA1: | 6829D76B076820BBC0080D16CDF69EC3450582EC |
SHA-256: | 8D7B65A0D96C9BAB1972D98C546E3BEE9F2BCE67AA10CACBCDC6274D6BD5F766 |
SHA-512: | C7042C995166583ABFD7E753EBEDA999E8031787DDFEDBBDFC7AA8C10B9F766651315DBE29280F62A7908410C8948126C51629B5B42F77654FCE8D3298D28973 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.4942.js?cs=2a007fef5724a6152eed |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9548 |
Entropy (8bit): | 5.251903031243172 |
Encrypted: | false |
SSDEEP: | |
MD5: | DB19C71E2E3A20DB637D018D5B641ADE |
SHA1: | 64059292B782CCBD0334898D7D742CE7D4B3DCA5 |
SHA-256: | A2E7FF838CF122F5AEB0A62B298553EB3318A34E1AFA2C45CF62FDB6B7CD5EED |
SHA-512: | 1B939CC18E2DFB5B1837EDDFC51C9191FDDBE647A3809DD8CF354E6C79DB4AFD6716D74F480729AB52EC2BB58EB7165E608456FC86E2E37D73230C8390BD3C94 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.9904.js?cs=a40b3681b8f8b6c693e2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 345147 |
Entropy (8bit): | 5.372408329602014 |
Encrypted: | false |
SSDEEP: | |
MD5: | 66CB0BA84C866A3247B18C4E5ED80356 |
SHA1: | 1F68BB87B3113200EE4D51E8FA0F1D4D0F2EB34C |
SHA-256: | B4452B79618142577FB11DDAC0AF96DB53868A97A79D7F944D6A5E59517E9676 |
SHA-512: | 98C1DEE6D164BBD95E2CCFE69CC07936C6E539C45BEB59385E0AC03ADF365DCF245DAD9D253267AF74D757D129DF35592186215A84E75D0B78791A820890299F |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.4759.js?cs=dd4878f0dd17b3327969 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13996 |
Entropy (8bit): | 5.411528102699808 |
Encrypted: | false |
SSDEEP: | |
MD5: | E7E019E41003F5579677352C65822381 |
SHA1: | E54EC42B7E034BD95776E856A826A02E9FF4C0F5 |
SHA-256: | 09F919ADF0A7F4C3EE28D2547F000283D2C3F9C9B2C4BCB41511882F25756B8B |
SHA-512: | A974614226241C240EFAA5E04BF9B4442B5AF2B18FB491E4B2B73ED4BDB3D6AC110D07DD0212BC8104C418E70EDDD3C73E4AA83131D4FCE576EC5B2D96F23774 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 61944 |
Entropy (8bit): | 5.304447875025489 |
Encrypted: | false |
SSDEEP: | |
MD5: | BF3A9D5151C8B9D586CCEE2347368C3B |
SHA1: | C86D8899D703C46EE2E3660ED7D0FA48423D8CEB |
SHA-256: | 0A9CD92388893914A5DEC03A5D7CAB4832A9912C1B30E5B5FF0EF67D61CC6D2B |
SHA-512: | ECFA1CAC35A7D02E42A0D73479FDEAEDD1377E9DAB3CC01EE0E0AB08278A64FE944C4C0E506B6D37CFDAA0A0FCE4AC8368FCED838D095D28E2F7D9426A7920D7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 631 |
Entropy (8bit): | 5.161960443143843 |
Encrypted: | false |
SSDEEP: | |
MD5: | C7FF0481BA4714B2A8EC37C636E9F48E |
SHA1: | B143A63B5285650603ACC063565B3769621063F0 |
SHA-256: | 38D3B5338C0DC8754CA866D7068A7089A49C1167E240669BF8FF0ABD17B4C3E9 |
SHA-512: | F0C1EADFB2DB6A27094AEEB919B131CB10EF2C4250D5A7A698665D7085C33CC2D6C5AA6E1F699384B2709C4E411B2A7A39BBA95FA0A0FEE98DD14329607A5F07 |
Malicious: | false |
Reputation: | unknown |
URL: | https://a.docusign.com/ds_arya_wrapper.min.js?f=1 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 46239 |
Entropy (8bit): | 5.323637453572971 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9FF6C771D8F1571EE4ED5A15C75741C8 |
SHA1: | 402F8577AE1E7175F354A7F3532CF90CAA61040D |
SHA-256: | 647E0D35687A333F02B80F7C4605EA7B32DAF7A4314C5654B1F1F825AAFB9CF7 |
SHA-512: | 86455944731ED9D64979E6E3F261F1E04ECC728CBBD95D29905260B26BAD141BB987466ABCE5CD70013424AF8700160DA8F4CDB13027659C08B49D4C371EEC9D |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.661.js?cs=9f9ef8c4690411d24923 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17031 |
Entropy (8bit): | 5.306521448060462 |
Encrypted: | false |
SSDEEP: | |
MD5: | DEC04B57977555D02A949E88B04CA086 |
SHA1: | 68CBDFCC8A9B00B93B4681986B88941C229F4FD9 |
SHA-256: | 1E78776195DAC7AF74183205A1916FD78F21F150FFCF62F8D9AB0491D8DD6F41 |
SHA-512: | 74C9499FD8D11C7BF856B5ADD280601298A10482A9D25537A1865FDC6118ED7663B3ECEABC879BE566543FAEFF60C81092C446949F8A055D0AD92C26BA326454 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.2088.js?cs=2de7373c65c21923c5a6 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85044 |
Entropy (8bit): | 5.1891096742958975 |
Encrypted: | false |
SSDEEP: | |
MD5: | D625021888FB263923D555D11F4D41A4 |
SHA1: | F0274774A841DF73E1FBC138ABF0A9EB4F64AFA1 |
SHA-256: | 45643151800C77DBB83D3D24C5D90BD5BB989BB11E7E862F533584C00D9352D6 |
SHA-512: | 659A02FE9C416A8A6FD08FAF9ACC15DE266826612330A36A84B58D7040F81523DD20CB0700AF86CD82AF63DE656D858FB459AAF0AD574CBEE0BEFBC5DA09A9B2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 127211 |
Entropy (8bit): | 5.390308144034802 |
Encrypted: | false |
SSDEEP: | |
MD5: | CD34838FD5BB396CB816821D6E77F649 |
SHA1: | 18BC0B2FAB1124614B321526237D980363A735B5 |
SHA-256: | FFE96356B533198165293502713767D2FD6A0645F979BA5D0D21B1592404668D |
SHA-512: | BD4271F7483D97B71E7FCC23B0C13A4D01FAC228E6D241329592C770E99EF6CCC341A7B8B8AAAC675C237723977955DDC6114782B3A1D57B1AA719E2115A11ED |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 119869 |
Entropy (8bit): | 4.18401975910281 |
Encrypted: | false |
SSDEEP: | |
MD5: | ECE7A224F69AB2205D90900589AE1D05 |
SHA1: | 3D861B816A5DA892C8A88D5755A5537C036239DE |
SHA-256: | FFA8C6A4CE199BFD9E32B05E0E4DECE330C6A577FB3A0E8518291619C658C486 |
SHA-512: | EEF4BDD54AF95BE42224FFE605BB627293DAEA0C58A50B328ACC8B56040C81FDCB5EC8406F56856FC617A552E4D6DD28BB892467666889D27F03EE8BFCD16D7B |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/v/static/mixpanel-2-2-1b.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 485328 |
Entropy (8bit): | 5.849285959572288 |
Encrypted: | false |
SSDEEP: | |
MD5: | 06573B4089B6AE15BA75CDA15CDC26DC |
SHA1: | AB9BB4BF549A58346755D5F5682ABB0C68BF4014 |
SHA-256: | 94F1B29EA884DD3C743B21B789169206B93364AD249DE66EF6F7A073C83824DE |
SHA-512: | 02444971483BA13654323821FF2504135F928B7DAD68D2BC11AD1A3623C2C9AC61EB9D9401602752B7FE7CB9B6E64E45F9C2C20A1748CF7E4FBCB37AF9C90FC8 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.7991.js?cs=41ac448436650aa906e9 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 398830 |
Entropy (8bit): | 5.723161832804715 |
Encrypted: | false |
SSDEEP: | |
MD5: | DAAD01ADC359B47B49908A74ECD07F2D |
SHA1: | BE29F6DC813A64F11D18E08CE79734E535DC8721 |
SHA-256: | 56409FCCE2E54B4570CB4A69827D0000CC0530A67A41B911516A2D90C61F2F71 |
SHA-512: | E716C88D56DF5431DA387E8730DEE1A0E2FEEDC17137599A1DCF4373FE392EA57D1444FD1DBF0497BF7A01DD03F596EF393B70E51EC4B331D0B97E1062F400AD |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.2191.js?cs=829a8778baf83ab1c4c1 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 91852 |
Entropy (8bit): | 5.15613176351478 |
Encrypted: | false |
SSDEEP: | |
MD5: | 82A99203D8F176022C5C5894591C1978 |
SHA1: | A7F9F02E9C09A9E2CEF865CA57C24E86EEAB88B6 |
SHA-256: | 9471F5DC3C5BB27444DA82E4B80E056FB2F9AB4E020FDA0482C4070801E1BA51 |
SHA-512: | DA3DE6E4C387F1C4B668EDA4981BB8A8A378F63A6BDBE5810054B9C8455DEFBBD0CF336383BCAEB6237CA7CAB6F70CA6CC17CA079C50F710E0424543405D2A94 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28542 |
Entropy (8bit): | 5.379722889825617 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1317A57B938133F1C22F70606779D939 |
SHA1: | 129E47D1946C50AE3338EA3F5A73634FF9DF2347 |
SHA-256: | FB67EF14210E956333D25A5586E120ECF3AAACF4CAF7C61E9699E82D6E5766E0 |
SHA-512: | 37F4D91FAB5D5148D9AF851E36BC7F931717463E490986284898AEA8E222E142F0B52D8BE43288B3AAE373124507DB438C6EB6746FB56E845B77A8802F940E10 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 148254 |
Entropy (8bit): | 5.312609346851331 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6AF741F5310E43427B2A14CA21A4250B |
SHA1: | 1EB292B49588E755BC2D8B0A32D137B7F2892AC8 |
SHA-256: | 37E8D2F7EF20885AD907BFC83FFDC21ED318BB0F05C3D64D146212B738B7A830 |
SHA-512: | 6AB525A79CE18D7BB164C21CFC1DEC2DBC730B378C673ADE3F7AB2E849411ABA78C681625C90E92C178ADE42F925074B1CA4B696CCBC1A57DE6FD8BA3954615B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 36374 |
Entropy (8bit): | 5.0734452911471974 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0ED07B1FB00F2FFF56C8FF113CAA18C7 |
SHA1: | 5A95A2018CF0004706E3C7E95DDC678DAD6F426E |
SHA-256: | 9E4B24CBC3D4CAE2BF90AE2F48AE43C490CDA68D05373399808B2951A1EF5193 |
SHA-512: | AC85F799A537A0B77121F76AF8F46B9B9C2290E58EB6F15536F0E48594C579C6EE9B0A6F97B20B768DCE4F515CC95FA1E2A5C69E5B49D82F4E870A046D5510E9 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.optimizely.com/datafiles/MUGKFLCdCtxUSgrSTyhbw.json |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 240748 |
Entropy (8bit): | 5.092451370734677 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2C73DD9B48CB342C5FEB81C8A378B291 |
SHA1: | FA52BCA3CF57FFE2FBA82D3C923B1A3DE1E38E76 |
SHA-256: | DA90AEA8421C31DDAB9FADDF17FC9D1F7EE9B466786C8113F0C523DB8CB3F00C |
SHA-512: | FA16248370983FFFE7DD3E1F68B988FF24D11633CC61C796EE285D06CB4368FBF647CE7805B57B6736038D7E961FD242529D7254938CB6F38217DFC1759B4047 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/olive/17.20.0/css/olive.min.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 259784 |
Entropy (8bit): | 5.364810568708785 |
Encrypted: | false |
SSDEEP: | |
MD5: | 661EE6E67109C19C4F1231FA688B2B10 |
SHA1: | C4D4466C0A8D1F52DAE1D209A26F29D43A88AFC8 |
SHA-256: | 4B57DB57C5DBCC7B491ABA41E551E89F744E79CEEE79AA42AC6C22244C662487 |
SHA-512: | 1DB724B084CB89666AAC2C4A010731B6FE0329BC2B80DC27231476D5F935CCC4ABC713C552875AD03656B69A98622AE8469D69793BACA08B73259FB94790A674 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 24771 |
Entropy (8bit): | 5.16649553919226 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3A048EA7BE88ABF0FEC5899DF72EA291 |
SHA1: | 9E55AD7A3831A792FD826A40CE75845737D9097D |
SHA-256: | AE697CD440125DBC55C2C885FF02503330876535812CE1EF53918E5FE42D74D8 |
SHA-512: | B97D812BEE3386702A3A7EF1EE5CE992E47B5EC2B758508482088456680156A408FCC4D9D4A2AB7FC3B18EEF3D23FFF0BB2E16698AC323E063F4FDDF6E4A3B61 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.9028.js?cs=22872eaeb7dadb7137d1 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 74443 |
Entropy (8bit): | 5.342806467692451 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9F5EDE38B0D1D7FE0EE6E2A72BB52655 |
SHA1: | DD7C0784B957C8103AEEF4200A1B658EFFDE28C5 |
SHA-256: | 83F8ECFA94B75E542672E438B4CFA06B7A819F78CD130BDD700FD2269EE4C44E |
SHA-512: | DC978E280B74078254CE1EA21A319BFF87027A0291EA10FEA353A35039021549DB4E280792A6F0477EF14512EFEC52D13BE2A9509760F7781C8DEA041BF1D536 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.6693.js?cs=3bb8fb45a63a282fc513 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 348802 |
Entropy (8bit): | 5.446933234812093 |
Encrypted: | false |
SSDEEP: | |
MD5: | ED516E6BE9429849D1704B6C35A417EA |
SHA1: | 4C88BE47B062EDF1C2745B7355C057EB55388B02 |
SHA-256: | A7CBAB07C5097E23745F62CA8B5914F1B93938258D670E23F2D18B5CCC3C323D |
SHA-512: | C9E5CC564B19250947E4AE8C4E5DFF64DAE1B35911D9DC755B0F0A04B13C9DD260C2E73B236B5835149C4AA300065109403B69D8886A1D8C90057DBF0178387B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 8136 |
Entropy (8bit): | 5.128500116202406 |
Encrypted: | false |
SSDEEP: | |
MD5: | 692906E147A4306A10623B24511EE10C |
SHA1: | CE92C758DE9440D5195B04E2F71A57476F2EF444 |
SHA-256: | F7B86D4053EF73B861F31139C0A3FC374CC14310E84261131FA0A34F4C92138E |
SHA-512: | 42B69323BA7119E8463343DFDAFB65536D458F96E7615FCDD7583B515DF0276A2EE95271BDFA0B9DF1D3A3F6A4901CA9458C070166D09D398240E1AD8BE20051 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.1946.js?cs=3ef732a0608ed868f4de |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 28145 |
Entropy (8bit): | 5.111932567512103 |
Encrypted: | false |
SSDEEP: | |
MD5: | F03BC80FE19576E53EE79979463F9024 |
SHA1: | 3B2AE70F8ECC97DDA978AE7473146C83BE499262 |
SHA-256: | 955EC39E298442113983D14E7EBCB49C8C57F301E88A3DAA05705AD34556286B |
SHA-512: | 5D16125CB1C83A9C7863FDCF019714CDDE1A20D3F453D29D9E312A7669D6A5025807F45DA647E554C72862AA20688862CFBA5ABAF2736FB508293D0C2477EFC4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.1882.js?cs=24c1d6df45358823acd7 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 197180 |
Entropy (8bit): | 5.034348131679163 |
Encrypted: | false |
SSDEEP: | |
MD5: | CEEB59F1BBE389D85F0C979D844BF008 |
SHA1: | F80ECC9AD12577493D269217EBE8C78FC37DCDB8 |
SHA-256: | BC7851B900A19E676C51C4BDE04639CC0B27E47C384370AB517C5BE72EA01DA5 |
SHA-512: | 8E4C8B6219F9DC13CEBCC442AF622D22CC1EF7FD9158C2B9824E038DD529BCD2CCEB8F08D62E2D525DBC16A57565D90F8C3B08363EA196FA2E36C5B054C77593 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.5889.js?cs=f1f6116f126a2a72f4ae |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 33014 |
Entropy (8bit): | 5.3799032238217945 |
Encrypted: | false |
SSDEEP: | |
MD5: | 30FE3DC6C28C79767CC85DFB34E487EB |
SHA1: | 3A11F5A934DCBD5B9475D7B2B750C7DF3FAE1E30 |
SHA-256: | A8E02E733FAB3CEE73485F3C26CC6CDFB7C3DEE3C1FBDDFBEC38F59D375F06D3 |
SHA-512: | D0C6E399760624835536EE08F855A08009C66213F1352550515BC07EEB9B1757A3B57BDDDE8B181B2B6D1B01D0D565CA6D71238568C86194AF7037DC8B90A7FB |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.9350.js?cs=b852bf7f83744943d133 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16889 |
Entropy (8bit): | 5.305771559126156 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7E0A5ABCB31199770B38DD9A0F557491 |
SHA1: | D4719F356E6800A6F664BCE7B3DDF7715607E5A3 |
SHA-256: | 0EE7DF63AA74F1623D01D69A016D845FD9024854A2F034D229ADE68D801DE4AA |
SHA-512: | FD96C650BE8A5714BA3A92BD6EBA045B5CBDD9666163BE3701B9357F2046F9966C9FFFEACE28F69713695B2351ADA9268511286680D2CC722A78D5DCAD260E7C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 84993 |
Entropy (8bit): | 5.266878130239354 |
Encrypted: | false |
SSDEEP: | |
MD5: | 388BD04B69B4A51F32438DCEFC4BA950 |
SHA1: | 2628528AAB473325DFB08F0F8B27F8A9CC4A3C06 |
SHA-256: | F7AAB38FBB9AA270C41CFAC7E8A9CF9DD8DF3FC830C702183000D1ABDF236A8A |
SHA-512: | 2BF22B5E6E3C4B59945A9741783149F5D37653683B6A2793065A257F556072A92124F2995040CE060734574B98210A93CADA67EC6A6132EB5E1C2331C7866D1E |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.6826.js?cs=8b9a2edefbbda32cdf88 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 410704 |
Entropy (8bit): | 5.3600762660869385 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0F2CD48BDA5FB302C59EEDA4A9E9FAF7 |
SHA1: | 1E16F644C4C8A5AE131527814C7A9CA2E70A58C7 |
SHA-256: | 39F70165A1906138A5F5378223DA0C66933EC5FE1F70356D13D8E373C2686869 |
SHA-512: | 24679277C7F95CE46C2DD908F9B6339EB754F9DD678D4886C3D9005BF307915A9680E176CCCA006000B82885603006914C20276E9BA06044C0E539C759EEE762 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 67961 |
Entropy (8bit): | 5.037518214459591 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2F6738F90BAF8FD114F4E28D487E1CD9 |
SHA1: | 2735F84AE90C6478933E994286AFAAA8963B2136 |
SHA-256: | 4606370BE9E4BBE2053A4CBD3FA3E206AD15781EA465F8C0C3484170B6996678 |
SHA-512: | B807B57EE3F2107761DBFE9E27968968220DB08556954F76753870AEF75CB09759C379A0A5CD2E361BDC42A601072D86D99394216C3ADBA9D51C17B30E0847FD |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.8002.js?cs=0e59cfbca464a8e95496 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 136176 |
Entropy (8bit): | 5.178395204770072 |
Encrypted: | false |
SSDEEP: | |
MD5: | B996140AA55B4DCEFBE20B0EC96447B3 |
SHA1: | 5C715DD38582604148904BADAF0342982195F698 |
SHA-256: | 54C6DB3FC48C1F54FAD197E91744DA04EB8FB584FBDB581A5C1E92CD6E72E12D |
SHA-512: | 529A34EEEE2EB0765F549CBD667238928DA1C57CC48B41B5674CABA9098E44E7706B0B7F7B3FB9A22C69CD5ACF29EB0546DCAC4515FA2E298C72A7CD5B034561 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.olive.js?cs=e0740911f01cf8fd8c81 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98773 |
Entropy (8bit): | 5.267898464164609 |
Encrypted: | false |
SSDEEP: | |
MD5: | 43A277E2F62386005C60540A68415F97 |
SHA1: | D69D78D6D10FF760F8068D87CE9C8ADB7A3E656E |
SHA-256: | B0F3FD10B52D4869B8ECBE459D12217E8BB8CF9E8B638546EFFBA3D377BF51ED |
SHA-512: | AD4FF273D1CDF04A266A2E8DEBF6214689B7413276629FB595E30AE63FF69B46937F14299BE1B236B57FB07AF7818977C0A138ACAF9F5DF1BABD145068925DA7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7244 |
Entropy (8bit): | 5.279544393318315 |
Encrypted: | false |
SSDEEP: | |
MD5: | 72BE693F43302A8D874D1632E088EA1F |
SHA1: | 9FF645EF334ED114EE6CE366FA4F4B9FBB0DF649 |
SHA-256: | D2AE279844F8C0AEE147FA90ACE67575A6FEE5D56521BC553291646171FBF214 |
SHA-512: | 6370B9957E68C3F714C3D180D1B65697210D06ABF0A9E46F4E273E7C411E18A6272574823159C7063970921788A60400CFBA652C9EA8897F451C75FBB190FFF1 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3728 |
Entropy (8bit): | 4.718277261919778 |
Encrypted: | false |
SSDEEP: | |
MD5: | EC396047518A7FEF11D53D1B4F6BE65B |
SHA1: | E3BEC4CDAF5567641517A23019ADBFA2328B0A7F |
SHA-256: | 8F77CFC832517C619BC1B8D82A6A478EE18D97442B4C78B006B0286CEC91E1A8 |
SHA-512: | 34AD62B5CC5EE5C950F340D65800102AE1CD06D34D24A611E7AC2CB9F23308AC96AC669D3B226C258DC6F862D985030EC3D5BB29609ECFEDF34E14F8F48529EB |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20112 |
Entropy (8bit): | 5.3678378968826435 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6FB7E52A614B256C595653C357859C65 |
SHA1: | C37CC73DB881AF06249CC48EE699F99D0D07A952 |
SHA-256: | 6F74076F7C78230921B3E5D7591B7E410DE1102EE726DD5C8CCC72BC3028C6A3 |
SHA-512: | F7D977E44BC508E3D391F3D8C1F923747CE9D58B740AFD67FB338FC0A324BEEC69932EF66221B8611FBE6902AF0BAD9A62625E3F684FBB28A40AF11159076B48 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 126880 |
Entropy (8bit): | 5.464041228525119 |
Encrypted: | false |
SSDEEP: | |
MD5: | 38FE1AC6F7802BD4A7CB50998DD847EE |
SHA1: | 1F729EF646053FFB10097FED54FF61E7C5F437A9 |
SHA-256: | D1453DD658E92F2F73254893295635E304D4365579B0B72A1D847ACA44BD692E |
SHA-512: | 8EA8D01D3D80094E3BF97ECE1924B50C7FC8255D0C902B1808CCE93E1F3BD5DF3DA7AA10C81D64861AD1CCCFA16C1F0A2FA428718C46F67F566B74A04ADD624F |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/production/1ds/widgets/@ds/signing/24.11.38-8/signing_iframeless_mobile.2126.js?cs=cad4365e2c2c48ad7299 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20032 |
Entropy (8bit): | 5.490698444145211 |
Encrypted: | false |
SSDEEP: | |
MD5: | C02F42AD6A3725BF2856CB80B2A99A02 |
SHA1: | F42507B8E248CD804240CCFFA7E9787BAB14F2D1 |
SHA-256: | 68E6BB187BC0CAB3D9968CFBA124A68EF78289CDB2FC8194387AAACF7A730948 |
SHA-512: | 1985E7D315EC03FF554EE6866DCF8E8D59D6B23830A26C2BE758B1C7BD6EDC364A5377BB5C2F87ABA8A9D6C56AE88A5D0E7280823DB2B4EFE534B129E7DAD6E3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4954 |
Entropy (8bit): | 5.237648060613005 |
Encrypted: | false |
SSDEEP: | |
MD5: | E88D2659A955F0E1BE25B1F310458621 |
SHA1: | 072CCD61F941F37CDDE25954582AD9624F092E73 |
SHA-256: | 41A7957A1FAEDE768283CA6C2A8E262FDE64CC7E190E91372E8C064D09D8EA7A |
SHA-512: | CF6727C34DEC981312483D37A4E140D59A31B84E32CFDE1F6D6EDA88E6815E2ED2533ACC4792E3FE35B64C63F1E9530B9C9192A2D4F727674DFFFECFF5144F26 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 326 |
Entropy (8bit): | 6.860674885804344 |
Encrypted: | false |
SSDEEP: | |
MD5: | AFE00DB89CE086B91A541C227EDBF136 |
SHA1: | 961B2EE6FB39C4D515BDC49EC1BA688B0916F104 |
SHA-256: | E11827C678AF8519E702F364E525AC34509CAD49F8D839677E089949EDDA060E |
SHA-512: | 85F265A917E83BA92FEDB2152FBFADA273FCFF2937A85B080641307FD2E61D0138493162883E016796C9F68062A01D79DA60F546EFC2CB1FB4078760EB3451F0 |
Malicious: | false |
Reputation: | unknown |
URL: | https://docucdn-a.akamaihd.net/olive/images/2.63.0/global-assets/ds-icons-favicon-default-16x16.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 487758 |
Entropy (8bit): | 5.533069487831044 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2CAA8D62C8FE6C1A1C79020F2009EA96 |
SHA1: | CE29AF377761577BB77BDA38681DB915259C9CA5 |
SHA-256: | E108946EF76C3B64F68DAACA5A67045C3F7FF01B52F648680F66364BCC233501 |
SHA-512: | 104F30C7715B7D5947A7799EB2E7D2AA19425FB7D3A7CFBF7F61FF7B004A8EED84C12B118AD2A8A06DAAEB969B02344D44E391C2DBB7751ABD9A3CC05BBB26DE |
Malicious: | false |
Reputation: | unknown |
Preview: |
File type: | |
Entropy (8bit): | 5.965238460270429 |
TrID: |
|
File name: | FW Expiration Pending Support Care HIPAA Acknowledgement Form 2024.eml |
File size: | 42'797 bytes |
MD5: | 63e3c96b5b6b003cbf76e93366dfc448 |
SHA1: | ec106a42c03b9d318cca209aa246c47f902641ac |
SHA256: | d3a10154ed35ebb629c6d51680ce422a7e5c4e1fcf9b716bc1ef01e9219df745 |
SHA512: | 73c67038d3b67b2f2815761110829fd49e9ad6e4242a0737094ba1a24bb5a44227d48da63dd4edce37dbfd69078ce3bf9aa5a26555b38ece7b8243b56d528d49 |
SSDEEP: | 768:Iuf1PY5OtoTVdqA+Gt5/LAXv/j6Ek21Tdu4KDIVHe1:Ic1g5OtoTVdD+Gj/LAnj6ESaHe1 |
TLSH: | FB135B1ADA9524D751F310F8B0177B46A7912D5EE3A28AF0B07AB1777E8E452334338E |
File Content Preview: | Received: from DS1PR13MB7100.namprd13.prod.outlook.com (2603:10b6:8:216::16).. by PH0PR13MB5615.namprd13.prod.outlook.com with HTTPS; Mon, 25 Nov 2024.. 18:13:12 +0000..ARC-Seal: i=3; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=pass;.. b=lRkgYwC |
Subject: | FW: Expiration Pending: Support Care HIPAA Acknowledgement Form 2024 |
From: | Armando Villanueva <armando.villanueva@24hrcares.com> |
To: | 24HR IT HelpDesk <ithelp@24hrcares.com> |
Cc: | |
BCC: | |
Date: | Mon, 25 Nov 2024 18:09:11 +0000 |
Communications: |
|
Attachments: |
|
Key | Value |
---|---|
Received | from BL1PR12MB5301.namprd12.prod.outlook.com ([fe80::2ba4:b394:4d10:ce01]) by BL1PR12MB5301.namprd12.prod.outlook.com ([fe80::2ba4:b394:4d10:ce01%5]) with mapi id 15.20.8182.019; Mon, 25 Nov 2024 18:09:11 +0000 |
ARC-Seal | i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=J0uAbNXQtM+vLtfrZc/xskXCExoDe8v9l7Wgvr23QDKdtn4rcRVpr1F9cFq3Cl2E1DSkiQ/eFaNSmXhaCLpE3JZD1f/rII0YDoGbUogBEl6L1a/o+V7xv6JcNSSSsieRpNTJbHSt1YzUuXHNRYLqGfsfG3I5xb0DZqEW6KRjYPz469bn3fH3+km6Uk+YnYmkvlN0CCz3C2OZAPJmdUjjLPjObZKzbMch2I1Qxq6qEzvnTp8Wf60taRSb5mWzWFCC53sthYbr+YYCQP8zThBMxBcs3nZKQp8uNCIJnZDvd1Jz9jKy4kMyVhS3Ye6/gmEnikDZ0Eni4CTzZZW8eHDRfw== |
ARC-Message-Signature | i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=PAACSiuzkPtQSk/xePvw8ATgswj3AzNVZqfJC3FhpQs=; b=v3s30ZWEZUO0VG8LZTaASpKkLWu4KBfYtGWHDypf7O/pDsvLe8EPjLPaNPJO0n4jl9IevivPrfyryqYxGXzNc8gFvRsFL1wsNl13Xr1l8qaKow4pVyBIfwblWiSCRoBOaNkm0OiI9q7AABIrWp6d5ruGptYdrU4Ke4O26hp3EVT0BTXVUXp+mk6bd0JJLNkJgeJOjAVu4A9Klls0xHdG0RSFrbIL+sRTzQG4ZRRFzPaNjd0T0CMyOHv2UNPrlEvSPiycFTsQI3Cn059xpQqmOvbpX/dTu59IDh76QqQnjXoCMPm4kAOWKY0ZrUXxOO7/wqQioR7ZIsrg3ZCfInOp6g== |
ARC-Authentication-Results | i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=24hrcares.com; dmarc=pass action=none header.from=24hrcares.com; dkim=pass header.d=24hrcares.com; arc=none |
Authentication-Results | spf=fail (sender IP is 205.139.110.120) smtp.mailfrom=24hrcares.com; dkim=fail (body hash did not verify) header.d=24hrcares.com;dmarc=fail action=quarantine header.from=24hrcares.com;compauth=none reason=451 |
Received-SPF | Fail (protection.outlook.com: domain of 24hrcares.com does not designate 205.139.110.120 as permitted sender) receiver=protection.outlook.com; client-ip=205.139.110.120; helo=us-smtp-inbound-delivery-1.mimecast.com; |
Authentication-Results-Original | relay.mimecast.com; dkim=pass header.d=24hrcares.com header.s=selector1 header.b=cqaCMO4s; arc=pass ("microsoft.com:s=arcselector10001:i=1"); dmarc=pass (policy=quarantine) header.from=24hrcares.com; spf=pass (relay.mimecast.com: domain of armando.villanueva@24hrcares.com designates 40.107.94.132 as permitted sender) smtp.mailfrom=armando.villanueva@24hrcares.com |
X-MC-Unique | 7DnEBUDmOPOPQu40ftsUJA-1 |
X-Mimecast-MFC-AGG-ID | 7DnEBUDmOPOPQu40ftsUJA |
DKIM-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=24hrcares.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PAACSiuzkPtQSk/xePvw8ATgswj3AzNVZqfJC3FhpQs=; b=cqaCMO4sF06fpa5CcPZssqZd16Z4KBRu0H/f5EMC4VEO3+7D8s6nxGl05W802doJOLCk3SG1RekJNdD9eAhJTr9qiubpgo4BRclnctLwjYzX5PJQE5RIt3K/7cc/i0Wg84WiHE7QynHFd18/4S9d8lTTZw1E/uQ60R3vuNuDK14= |
From | Armando Villanueva <armando.villanueva@24hrcares.com> |
To | 24HR IT HelpDesk <ithelp@24hrcares.com> |
Subject | FW: Expiration Pending: Support Care HIPAA Acknowledgement Form 2024 |
Thread-Topic | Expiration Pending: Support Care HIPAA Acknowledgement Form 2024 |
Thread-Index | AQHbPlKG9s38GZoVeU2dAr3+OgdCWrLITYIg |
Date | Mon, 25 Nov 2024 18:09:11 +0000 |
Message-ID | <BL1PR12MB53013386F6752C94AA35C7698C2E2@BL1PR12MB5301.namprd12.prod.outlook.com> |
References | <ca1f41d1d08f4a39848b7df60503f41a@docusign.net> |
In-Reply-To | <ca1f41d1d08f4a39848b7df60503f41a@docusign.net> |
Accept-Language | en-US |
X-MS-Has-Attach | yes |
X-MS-TNEF-Correlator | |
x-ms-traffictypediagnostic | BL1PR12MB5301:EE_|DM4PR12MB7622:EE_|BN2PEPF000044A2:EE_|DS1PR13MB7100:EE_|PH0PR13MB5615:EE_ |
X-MS-Office365-Filtering-Correlation-Id | f2580f9f-6ac3-4fb4-9083-08dd0d7c5982 |
x-ld-processed | f6d4f09d-81a8-4f0c-9385-3c6ca8d9ea14,ExtFwd |
x-ms-exchange-senderadcheck | 1 |
x-ms-exchange-antispam-relay | 0 |
X-Microsoft-Antispam-Untrusted | BCL:0;ARA:13230040|1800799024|366016|376014|69100299015|8096899003|38070700018 |
X-Microsoft-Antispam-Message-Info-Original | MuhGgtlUSHzBVJbCXwb+sN1STUZlSSPBoC6BMSfgrTuRrY1CpvcgwvbN+pI+LGrclOyO1IokLlCRVzfMpBqJhOHZ6n7OepKwLVN1ZqYroZpHDkPnDiOqWtDFdJDGk8rLSth7NqC3SQEE2ho7A1mQYFX0Vr1Rc10zQmqtPsYsmSIayhvX6AGr3hrLBSKTRW31eHlWL1ekXXfcMfu6SL/0Jkt6ZYgoz4Ja+ezXhLO5yvkXtZMiZ/JYkQPg+1v5L5STk4gCX5mhH702NhN9VjBWO51+Nc0iavuj5TXpBrCf0OMqTF61mYAF9FscvaFgrKNlb5lhumgjCrGDTaJQOpulfEw3mB+MF1HVh8cgpQHI//B91CAnri6Ht0g5nQF0xFdrky0oSJZfzymkPz4s358HjrERh5AUpNAHhG4JMvB35Z3ycyNucQl+QXcrI187meDceOppq2rpyDEetuKIN4PhwqgmjmTFZ6uS9u7bVdT3DXf9PZ574zhwfq4roSYJ45ZpSoy9gVB5n+RMa+EQB7nPm14tGrzX0jxKcmwNnJV0WmUnpMLtmpQwwns0pTkgf+WGxp/2/KobNUm1jUvYI4p6MRFhIuqmFwuaTWxtc9NT5ADyD+qHtAVR4z+VhNPZBBJr7kyoXgKKCNl2T+wfmGPfwE9k6aQ2nPbz9++AR9jV9l33tg70Q9DArDceRqtefxHWzdgiP2hkvdILbIhBLHAGNRB9Iu6yibcOCG7P7dc10qJQuM8bUK+09AiOZSl5jkRA0/8VHW/3NCDeeM0RFNKEHN+MB7re5khF6iBKmyBmdQdQzXgmGST6FmqOB4PolzJyhaW/5qSMgknOrD9MT7byB4OLCymdSUDeSpFtDfnkDIGL6TjYp0HloJmh1/yvMoV2o3YR+HlRIqkLH3eX3/GnHHYBNtbKZftNs6j7izJAwPEZ7vHBWq2wdUPbpw+75amV52vcZQcmvfwl85//xzZain1EUlLpEcCtQB5iPhvExSzRQcAdOOCdLMVPfYk/pIDqclNvGMcX7elXTAJh4fjt6ApWE4rqoNObR+CDHmvqawoZVwPoxSDFqCz7lhnnscB9RqBZU1GrnMpkfKuiJKc6qc6UXbH/o5qBRrDOko0TkUt/dXO5d7cw3VYNu0/L4rVxwY1V4CGiRARPRZjlv5BDxyrif2lMVz4U2vjrD+4lX3Vq1HCtDlDZptJgELhRVm3eiCripld3YkC1oZGiYfPjYl+A8qY6PVGfRV5BcqjiMSbUfsVY44FMHAmhueAmNBLERBT48VuHznHLCyN/Ar6oqLbSsWn4WjNZ4DPrPKSi2X16yNGq8nNhzczeN+MSFoHocQo2BBV05VzDp+wN5TMxQQ== |
X-Forefront-Antispam-Report-Untrusted | CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BL1PR12MB5301.namprd12.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(69100299015)(8096899003)(38070700018);DIR:OUT;SFP:1102 |
X-MS-Exchange-ForwardingLoop | support@mydatapath.com;9ef5d077-23c6-453f-94f9-7809c35a837f |
X-MS-Exchange-Transport-CrossTenantHeadersStamped | DS1PR13MB7100 |
X-Mimecast-Spam-Score | 1 |
X-Mimecast-MFC-PROC-ID | 4YvloeTEPZoIVu7TqJvlvR0_cZzyRl0fegOTHYMG8hU_1732558184 |
X-Mimecast-Impersonation-Protect | Policy=Default Impersonation Protect Definition;Similar Internal Domain=false;Similar Monitored External Domain=false;Custom External Domain=false;Mimecast External Domain=false;Newly Observed Domain=false;Internal User Name=false;Custom Display Name List=false;Reply-to Address Mismatch=false;Targeted Threat Dictionary=true;Mimecast Threat Dictionary=true;Custom Threat Dictionary=false |
Content-Language | en-US |
Content-Type | multipart/related; boundary="_004_BL1PR12MB53013386F6752C94AA35C7698C2E2BL1PR12MB5301namp_"; type="multipart/alternative" |
Return-Path | armando.villanueva@24hrcares.com |
X-MS-Exchange-Organization-ExpirationStartTime | 25 Nov 2024 18:09:48.5313 (UTC) |
X-MS-Exchange-Organization-ExpirationStartTimeReason | OriginalSubmit |
X-MS-Exchange-Organization-ExpirationInterval | 1:00:00:00.0000000 |
X-MS-Exchange-Organization-ExpirationIntervalReason | OriginalSubmit |
X-MS-Exchange-Organization-Network-Message-Id | f2580f9f-6ac3-4fb4-9083-08dd0d7c5982 |
X-EOPAttributedMessage | 0 |
X-EOPTenantAttributedMessage | 9ef5d077-23c6-453f-94f9-7809c35a837f:0 |
X-MS-Exchange-Organization-MessageDirectionality | Incoming |
X-MS-Exchange-Transport-CrossTenantHeadersStripped | BN2PEPF000044A2.namprd02.prod.outlook.com |
X-MS-PublicTrafficType | |
X-MS-Exchange-Organization-AuthSource | BN2PEPF000044A2.namprd02.prod.outlook.com |
X-MS-Exchange-Organization-AuthAs | Anonymous |
X-MS-Office365-Filtering-Correlation-Id-Prvs | 7a89551c-e85b-4b49-f7d2-08dd0d7c439c |
X-MS-Exchange-AtpMessageProperties | SA|SL |
X-MS-Exchange-Organization-SCL | -1 |
X-Microsoft-Antispam | BCL:0;ARA:13230040|31092699021|5073199012|5063199012|4073199012|4123199012|69100299015|1032899013|22103399003|82310400026|35042699022|2066899003|8096899003; |
X-Forefront-Antispam-Report | CIP:205.139.110.120;CTRY:US;LANG:en;SCL:-1;SRV:;IPV:CAL;SFV:SKN;H:us-smtp-inbound-delivery-1.mimecast.com;PTR:us-smtp-delivery-1.mimecast.com;CAT:NONE;SFS:(13230040)(31092699021)(5073199012)(5063199012)(4073199012)(4123199012)(69100299015)(1032899013)(22103399003)(82310400026)(35042699022)(2066899003)(8096899003);DIR:INB; |
X-MS-Exchange-CrossTenant-OriginalArrivalTime | 25 Nov 2024 18:09:48.4531 (UTC) |
X-MS-Exchange-CrossTenant-Network-Message-Id | f2580f9f-6ac3-4fb4-9083-08dd0d7c5982 |
X-MS-Exchange-CrossTenant-Id | 9ef5d077-23c6-453f-94f9-7809c35a837f |
X-MS-Exchange-CrossTenant-AuthSource | BN2PEPF000044A2.namprd02.prod.outlook.com |
X-MS-Exchange-CrossTenant-AuthAs | Anonymous |
X-MS-Exchange-CrossTenant-FromEntityHeader | Internet |
X-MS-Exchange-Transport-EndToEndLatency | 00:03:23.5534301 |
X-MS-Exchange-Processed-By-BccFoldering | 15.20.8182.018 |
X-Microsoft-Antispam-Mailbox-Delivery | ucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(930097)(140003); |
X-Microsoft-Antispam-Message-Info | tzkmajanKDhkPsZQ+5GFOfemXF1m7J6V8S0S2ySix4FEgxdWWiSx4U9DijBRZ9gs2V97avROjIPquKZRkn7DhSFW8ayEajkrUuaQ1X6G7qgo2UltQ7smWsUffwCfzHYFDjrAZaeQNnSMvuPJPc7b7kK01wztEVdW52wgpl2ADEeDuhzPCPPOu3L960MNHVyw1cusqJPblWFRkBJ5mCTDTDfg4LtJv3xOoxpCOTwNiW/r9bqiqkxiZmSGfJ74HwfQOZgHCo5G1fgkwJEaOeWlFX2rnEJlrYJLhSIOdTVqOfTMecD+a2OFLmn/+q2HkaE0O/+hEMdzXAfDhohPCp4imbA+H/vLu/E/gn4R9jzit73kS1ZFVefMkHnuXtlhBNRJB5+sfKhsdrtO908FIIzA7Kj+bQgfjgoWo4AAtEm0pnNkwy16esnQKtngXEDmddo11yVq79YXq4PqAh9We0fpLLYHHiCfQv7NXqv4q01iwkvWCCBHbqrKH1cTiVMl4oXFwUpV0/t8UvrOI7whMWAq6ne2AfOJ4BLZc/lZYbx5AgNu/jsykaMRDf6h52F2svHC9xN+8kWbEQqm0YX/ev0k1M2kI5KE+oFDiPa3+UMC1FC7I05zhux6gS7eMH8u8Y9d1cn01Dl135PvngUw3G09Y1Mfd+jAnmIJpi7SCtEg7a7XIfJy2kTgBR0a4vd5zZr7S/svBASwdH/QCZPJRmNu7L4AXSYByHRFVXTdIi8mvSR2pX6aJrKkDaikoatvgHneW0BuZdNDAs12MPghrjUTt145axt6OfnEvtsfgKAWUBLQmBPYdbV+BE/rVyupncP3w/QW6xB3ihjtnm/Mrr1egjUxqh4dPNa7JUcxbomENHwxWKZo4iiUdWwan1dC5igSDxPbC5E2FPpfQIU4TmkBVNorMkmB8mG/oOl6m8ciHQ1ZsQI7PonH2fv0VAyo7i/LOVDZ3DKZc1Sj2YxCiFNzALDJV8mAL8UpkYZd3q21085gyRifbzwtAbQMXwziaG1VyBY2B/x8BmzEcjimN4ZzR7FzQ0MpvOIoPq17qeWm/IzqAp3ILni/479YCDTGMdpXakaC+AQz8gF3WZjiFVmiMrAG8wSrJiFPONwmiIs3hNzw0TDYHl2J536M6yXpExwXAmyuQgPWiyp23Ra5EhE70x1f8biwQrok3KwWfSsbYa/S7eU7URBGCwLu+1sEIB5wHYYV8+GfIhYqXNf1U6rTS98T8EEeIGtJcAZ/4pu5rAg4Le3cOqx9RMtxcmtd6Mr3tU8prPcQpuGWNjywt2Xb9mxFSTVwJ7LNfwzGAz4/a+WWEWeuT3KnAFzWCMuTEbfxW8Q9gsEq6wEg6wIgw5mn/wNYwd8UlRZYCYKnt8qKbwfJU1YbwmK/6aMPLYpEpKsn8LexmVycB3p2EJgX4rMYRMqr6FeoyMGNwM3ESyF6CWM0iOPzJORh1b1WTCAvvFczrf1TiM/CCC0fBC/GKOrIj9mNPuYNlB4/2UOhmA2eE9C9qEt/LddApQOndpZgG+Z3pNNJx6AxNy0/S7edsOnblnV+KWOSFjTWSIFoexxszbPUomQ60w8ZZIUzdjYm86W/5nlFOLJlGU1509nAgRDPGImzuvK2/Zcg3j/fKYYDYC3jdt29/sixjMZuO4DTuiNeTyP/fXcfXjWYdlP/074VioYe9LG/8sFA5cJYneLOnk+iXUJ69lqMeiDISuqn8bRALivHZ0rShRuNbGeIEVouyh0RTItc0siy22sytibYjS/nlZTEIDV7VDiDo12KI20pDnmGEOO0T4kYaU8gVbzs1Q+vBC7wu5a0s3cMJVAppObnJPMDYtUVx4hii/XN5TjS7qy7/FO53sGZCeXrcaSd01a9BBKqTiG3AanPg0moXJlwhIEaSozH3uyCAJzmdQZ3OjnMr6iG63zncPT+p1Ywuv1DjNMbe7Vce/bPsBGgfjy7yrSa+8cqzs3DrhJHQ+fo15LhAT4MYUzVlXwsSWMXhYKMzCC6SJkVoLnpGJRNNvEGGhBtJjdmGQfzuFqqqy+iDPQE54xQgj7T9M5LbObOxoH2LUYcVzy+ML5SHfsqwFQIPn07eKhatmZur7sTkslW8KgkTWANCaCjU5FfAC4K42ftRkgihp+B3w73uinW8ItyxYXmYuyhacx3VipO6If9fdlWCpCrmISEWZ8rOge8T2PjEbvSTErf+c0F0bcnL81teV22+Ntj5vp9MI1KsiGM |
MIME-Version | 1.0 |
Icon Hash: | 46070c0a8e0c67d6 |