File name:

Message.eml

Full analysis: https://app.any.run/tasks/3e2bbad9-f2f3-49e1-966e-df720c115db2
Verdict: Malicious activity
Analysis date: July 15, 2025, 21:36:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
attachments
attc-unc
attc-pdf
amazon-ses
Indicators:
MIME: text/plain
File info: Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
MD5:

C221A0727C186E73B16F94C43894CE6F

SHA1:

D56F5AD2DD669A6707F6FAEFA3600F440725D642

SHA256:

28D26AD3AB224D7612558BADD40ABAB1F4BAF958230936496C666E023A1CDCAF

SSDEEP:

6144:V6BpU5+O7VH1Daw+wkoCt+xltSjzj98Dqq/0M6znwb:V4Y+6VH1DuwkoCtRPWDqkonu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Email came from third-party service (Amazon SES)

      • OUTLOOK.EXE (PID: 4024)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Email with attachments

      • OUTLOOK.EXE (PID: 4024)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6384)
      • Acrobat.exe (PID: 4412)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 6384)
    • Application launched itself

      • Acrobat.exe (PID: 4888)
      • AcroCEF.exe (PID: 2124)
      • Acrobat.exe (PID: 7600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.txt | Text - UTF-8 encoded (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
18
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe ai.exe no specs openwith.exe no specs acrobat.exe acrobat.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrobat.exe no specs acrobat.exe no specs acrocef.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2764 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1700"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=2996 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2124"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2464"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2108 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3872"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --first-renderer-process --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2380 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4024"C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml C:\Users\admin\AppData\Local\Temp\Message.emlC:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4120"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "102BBAB2-FD88-4DE7-8377-C3D34CA2F968" "6D5950DD-9890-4D51-9E2E-0040B4E6C54A" "4024"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\rpcrt4.dll
4412"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4888"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
OpenWith.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6368"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2724 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
26 659
Read events
26 188
Write events
419
Delete events
52

Modification events

(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData
Operation:writeName:SessionId
Value:
9412D84A-4E91-4929-A84F-6A9A951390B1
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootFailureCount
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Preferences
Operation:delete valueName:ChangeProfileOnRestart
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\outlook
Operation:writeName:BuildNumber
Value:
16.0.16026
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:writeName:Expires
Value:
int64_t|0
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:delete valueName:ConfigIds
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:delete valueName:ETag
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.40
Value:
7468656E7469636174696F6E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22526573756C7447726F7570546F52656E6465725C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2253656E64576562536F636B6574526571756573745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22576562536F636B657450696E67506F6E674C6174656E63795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22446961676E6F737469635C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C225375624E616D657370616365735C22203A207B205C22486F73745C22203A207B205C224576656E74735C22203A207B205C22496E7365727448746D6C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E736572744F6F786D6C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C61756E6368466565644261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E64436F7079746F436C6970426F6172645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E7365727448797065726C696E6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225365744D65737361676543616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2245786563757465416374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656C65637452616E67655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537461727450616E654C61756E636865725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537461727453696E676C65537472696E6750616E65734C61756E636865725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E7365727444617461547970655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E73657274546578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E766F6B6546696C6573416374696F6E735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E64436F7079546F436C6970426F6172645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E61766967617465546F50616E655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416374696F6E4E6F74496D706C656D656E7465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2242726F7773654E617469766546696C65735C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2238564D65686C6C5C22203A207B205C225375624E616D657370616365735C22203A207B205C22356B69614B3747426B7A505746675C22203A207B205C224576656E74735C22203A207B205C22373139305C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C22385C22203A207B205C225375624E616D657370616365735C22203A207B205C227A424B387872415553554E52497859484E4B55415C22203A207B205C224576656E74735C22203A207B205C22393133335C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C224F66666963655C22203A207B205C224576656E74735C22203A207B205C2253797374656D644D617463685C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C225375624E616D657370616365735C22203A207B205C22496E7369676874735C22203A207B205C224576656E74735C22203A207B205C22536D6172744C6F6F6B75705C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536D6172744C6F6F6B75705F5F5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536D6172744C6F6F6B75705F5F5F5C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2253797374656D5C22203A207B205C224576656E74735C22203A207B205C2241637469766974795C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2253797374656D68633863674F6A46515C22203A207B205C224576656E74735C22203A207B205C22383635335C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D207D207D2C205C22556952756E74696D655C22203A207B205C224576656E74735C22203A207B205C224F6E50616E65436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E74656E745365727669636550726F78794F6E436F6E6E656374696F6E436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E436F6E6E656374696F6E436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F636573735265717565737451756575655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E64526571756573745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E50616E6552656164795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22576562536F636B6574436C69656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65496E636F6D696E674D6573736167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436C65616E50616E6553657373696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22437265617465576562536F636B65745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E6557697468536561726368526573756C745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E53535248746D6C52656164795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E65576974685353524A7346696C655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F63657373526571756573745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E65576974684E6574776F726B4572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E50616E65436C6F73696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E446174614D65737361676552656365697665645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22437265617465486F7374536B696C6C4576656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E6557697468496E446F6346616C6C6261636B446174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D6F6E69746F724C6976656E657373416E645265706F727449664572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E50616E6548796472617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E4F66666963654A734C6F616465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C61756E636850616E6543616E63656C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6174697665536561726368526573756C74735265717565737465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E646F63536561726368436F72655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E644D6573736167654532455C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225365617263684C6F63616C50726F7669646572735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22536561726368446F63756D656E74436F6E74656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22536561726368436F72655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726570617265536561726368436F6E746578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250616E65416374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22536B696C6C735C22203A207B205C225375624E616D657370616365735C22203A207B205C224C6F63616C5365617263685C22203A207B205C224576656E74735C22203A207B205C224C6F63616C5365617263685C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E496E74656C6C6967656E745365727669636573222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C224F7074496E5C22203A207B205C224576656E74735C22203A207B205C225573657252656A65637465644F7074496E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F774469616C6F675C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C6561726E696E67222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C656E73222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C6963656E73696E67222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74735C22203A207B205C22436F70696C6F745374617475735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22436F6D70617265427573426172735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224C6963656E73696E67427573626172416374696F6E5C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C22487244697370617463685375625461736B53746172745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22517569636B56616C69646174696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253617665416C6C536B75696473546F52656769737472795C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2257616974546F52657472794865617274626561745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536561726368466F7253657373696F6E546F6B656E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224E554C56616C69646174696F6E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2256616C696461746553657373696F6E546F6B656E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2243616E52756E4665617475726543616368655C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22506572666F726D4C6963656E73696E674E6F74696669636174696F6E735C22203A207B205C224576656E74466C61675C22203A20323536207D207D2C205C224576656E74466C61675C22203A20312C205C225375624E616D657370616365735C22203A207B205C22466C6F77735C22203A207B205C224576656E74735C22203A207B205C2253686F7753756250726545787069726174696F6E4469616C6F675C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C2253686F77537562736372697074696F6E506F737445787069726174696F6E4469616C6F675C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C2253686F774E6F537562736372697074696F6E466F756E644469616C6F675C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C22536561726368466F72534341546F6B656E5C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224C5655585C22203A207B205C224576656E74735C22203A207B205C224E6F456E7469746C656D656E74735C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C224E6F456E7469746C656D656E74734578706572696D656E74547269676765725C22203A207B205C224576656E74466C61675C22203A203439343038207D207D207D2C205C224F6666696365436C69656E744C6963656E73696E675C22203A207B205C224576656E74735C22203A207B205C224C6963656E7365436F6D706C657465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224C6567616379416374697669747953756363657373436F756E745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224C656761637941637469766974794661696C757265436F756E745C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C225375624E616D657370616365735C22203A207B205C22436C69656E745C22203A207B205C224576656E74735C22203A207B205C224653686F756C6441637469766174655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C224865617274626561745C22203A207B205C224576656E74735C22203A207B205C22577269746543616368655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225265616443616368655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22517569636B56616C69646174696F6E5C22203A207B205C224576656E74735C22203A207B205C224C6F61644C6963656E73655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2246756C6C56616C69646174696F6E5C22203A207B205C224576656E74735C22203A207B205C224C6F61644C6963656E73655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2250726F706572746965735C22203A207B205C224576656E74735C22203A207B205C224765744C6963656E736543617465676F72795C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546F6B656E697A654C6963656E736543617465676F726965735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225570646174654C6963656E736543617465676F726965735C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224272616E64696E675C22203A207B205C224576656E74735C22203A207B205C2247657441707056616C75655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2247657450726F6475637456616C75655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253686F756C645573654D6963726F736F66743336354272616E64696E675C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2254656E616E745C22203A207B205C224576656E74735C22203A207B205C22496E697454656E616E7449645C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C224E756C5C22203A207B205C225375624E616D657370616365735C22203A207B205C22466574636865725C22203A207B205C224576656E74735C22203A207B205C224765744E756C4F626A656374466F724964656E746974795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2246657463684D6F64656C46726F6D4F6C735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224765744C6963656E73654665617475726573466F724964656E746974795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2243726561746552657175657374426F64795C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C224D6F64656C5C22203A207B205C224576656E74735C22203A207B205C224765744C6963656E736543617465676F72795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22476574416C6C4C6963656E736543617465676F726965735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22446573657269616C697A655C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C225061727365526177526573706F6E73655C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2243616E52756E46656174757265526573756C74735C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224D6F64655C22203A207B205C224576656E74735C22203A207B205C224765744D6F64655C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224170695C22203A207B205C224576656E74735C22203A207B205C22437265617465526571756573745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2253656E64526571756573745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2252656365697665526573706F6E73655C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2253746F726167655C22203A207B205C224576656E74735C22203A207B205C2247657453746F72616765506174685C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224C6F61644D6F64656C735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22476574556E766572696669656453746F72616765506174685C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224C6F61644D6F64656C5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2252656E616D6546696C65546F55736555706461746564486173685C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2256616C69
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|40
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.41
Value:
646174696F6E5C22203A207B205C224576656E74735C22203A207B205C22517569636B56616C69646174696F6E5C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2256616C696461746F725C22203A207B205C224576656E74735C22203A207B205C224D61746368696E67486172776172656449645C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C6F6F6B7570222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C756D6F73222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D33363544657369676E6572222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D3336354A756D707374617274222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D4155222C20225622203A20227374643A3A77737472696E677C7B205C225375624E616D657370616365735C22203A207B205C22436C69656E745C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D4C222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C225541504576656E7453696E6B5C22203A207B205C225375624E616D657370616365735C22203A207B205C224F49534F70746564496E5C22203A207B205C224576656E74735C22203A207B205C22315C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224C6F67534947535369676E616C5C22203A207B205C224576656E74735C22203A207B205C22325C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22315C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D2C205C224D6F64656C446F776E6C6F61645C22203A207B205C224576656E74735C22203A207B205C2250726F636573735265736F75726365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225570646174655265736F757263655461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F675461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F67436163686545785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526571756573745265736F75726365496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22506F6C796D6572536572766963654572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F63657373436174616C6F67526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F776E6C6F61645265736F757263657346726F6D436174616C6F674173796E635C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D53546F646F222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D616B6572222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C225344585C22203A207B205C224576656E74735C22203A207B205C2253746172745265636F7264696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2246657463684D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22417574686F72697A655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466574636853637269707446726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466574636853686172656453637269707446726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574416363657373546F6B656E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F61644D6F6E61636F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225075626C6973685363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756E5363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574557365725065726D697373696F6E735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253746F705265636F7264696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2244656C6574655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C61756E63685461736B70616E655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F674974656D5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E74656C6C6967656E63655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224475706C69636174655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22417474616368536372697074546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446574616368536372697074546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265616453637269707449647346726F6D576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265766572745363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686172655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E697469616C697A654D6F6E61636F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22556E736861726553637269707446726F6D416C6C576F726B626F6F6B735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6E73656E74546F52756E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466574636853616D706C65735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D61726B46756E6374696F6E417267756D656E744572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D61726B4C696E7465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225472616E73666F726D5363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6D70696C655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265636F6D6D656E644C696E6B735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F61644368756E6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6164417574684C6962726172795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765744F7267616E697A6174696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574436F6E73656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22507574436F6E73656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F63616C53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416464427574746F6E546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765745069636B65645363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224665746368526563656E744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2246657463685363726970747346726F6D446F63756D656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656D6F7665526563656E745363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574416C6C53637269707456657273696F6E7346726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756E46726F6D427574746F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574477261706853637269707446726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E697469616C697A65416374696F6E48616E646C65725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F7079436F64655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6752756E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416464536372697074546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574436F64655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756E74696D6552756E6E61626C655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22507265706172655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466C6F6174696E674469616C6F675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225072656C6F616452756E74696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225072656665746368546F6B656E4F6E4465736B746F705C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574557365727346726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F774F7248696465427573696E6573734261725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657452756E74696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224170695365744C696E7465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574576F726B626F6F6B4964735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765745072696D6172794964656E74697479456D61696C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224665746368526563656E745363726970744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D6F76655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657446696C654E616D65436F6E666C696374735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22564241457863656C4576656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224372656174655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22566965775363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224372656174654E657750726F6D70745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F4E6F7453686F774261636B67726F756E645265636F72646572416761696E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22536176655265636F7264696E67496E4261636B67726F756E645265636F726465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574466C6F77735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224261636B67726F756E645265636F7264657253746F7048616E646C65725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F774261636B67726F756E645265636F7264696E6755495C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253746172744261636B67726F756E645265636F7264696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2244656C6574655265636F72646572416374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224564697461626C65496E74656E74456469745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2243726561746552756E74696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574496E74656E744461746146726F6D5363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224564697461626C65496E74656E745061727365725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657444656661756C74456E7669726F6E6D656E745C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C22476574557365725065726D697373696F6E735C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2246657463684D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22466574636853637269707446726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C225075626C6973685363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22466574636853686172656453637269707446726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22556E736861726553637269707446726F6D416C6C576F726B626F6F6B735C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2244656C6574655363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2253686172655363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224765744F7267616E697A6174696F6E5C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574436F6E73656E745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22507574436F6E73656E745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574477261706853637269707446726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224665746368526563656E744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574416C6C53637269707456657273696F6E7346726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2252656D6F7665526563656E745363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574557365727346726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574576F726B626F6F6B4964735C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224665746368526563656E745363726970744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224C6F6752756E5C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C22
Executable files
0
Suspicious files
210
Text files
18
Unknown types
7

Dropped files

PID
Process
Filename
Type
4024OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707.pdfpdf
MD5:97FFE9601381B542AA6021A150CE2598
SHA256:C91808666B0C4BA77F494DF26A950425F5265F6787DE4F31994D4B503FEB6114
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707 (002).pdfpdf
MD5:97FFE9601381B542AA6021A150CE2598
SHA256:C91808666B0C4BA77F494DF26A950425F5265F6787DE4F31994D4B503FEB6114
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_TableViewPreviewPrefs_2_82975A8504F216408FE49B974F3E1AB3.datxml
MD5:0E092DB99AEE99FDFF9B5B222C732CFD
SHA256:D1614AD99ADED9F6F5C1BE7FE7FFA5124BD04A526580DA3818EA8A954E852AA6
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bintext
MD5:CC90D669144261B198DEAD45AA266572
SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
2124AcroCEF.exeC:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old~RF179599.TMPtext
MD5:D012E5B4EB91B61F6E8AE2F8EC3C623E
SHA256:1BDA750084F20306722008016420E1912BA608CA8EFB9C661F7E7EFCF5E89673
4024OUTLOOK.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Abinary
MD5:34BF57A99E64D115E6F2D2C55290A27C
SHA256:A1A8AD21713515B0E3FCCA0D0E5DCCA913D01543B1C6A3C9AC768B345EC41C30
4024OUTLOOK.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Ader
MD5:BA2E856E003AD5AAB689936628217AF8
SHA256:27631132DFC8179561317DCAAA3881E0B7FE85B46776F52B0E48291F722F92FF
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707 (002).pdf:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
4412Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTINGmp3
MD5:DC84B0D741E5BEAE8070013ADDCC8C28
SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4024
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2612
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7408
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7408
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4888
Acrobat.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2648
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4024
OUTLOOK.EXE
52.123.129.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4024
OUTLOOK.EXE
2.16.168.119:443
omex.cdn.office.net
Akamai International B.V.
RU
whitelisted
4024
OUTLOOK.EXE
52.111.231.8:443
messaging.lifecycle.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.241.14:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted
omex.cdn.office.net
  • 2.16.168.119
  • 2.16.168.113
whitelisted
messaging.lifecycle.office.com
  • 52.111.231.8
whitelisted
crl.microsoft.com
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
self.events.data.microsoft.com
  • 20.42.72.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.128
  • 20.190.159.75
  • 40.126.31.131
  • 20.190.159.23
  • 20.190.159.0
  • 40.126.31.2
  • 40.126.31.73
  • 40.126.31.128
whitelisted

Threats

No threats detected
No debug info