File name:

Message.eml

Full analysis: https://app.any.run/tasks/3e2bbad9-f2f3-49e1-966e-df720c115db2
Verdict: Malicious activity
Analysis date: July 15, 2025, 21:36:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
attachments
attc-unc
attc-pdf
amazon-ses
Indicators:
MIME: text/plain
File info: Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
MD5:

C221A0727C186E73B16F94C43894CE6F

SHA1:

D56F5AD2DD669A6707F6FAEFA3600F440725D642

SHA256:

28D26AD3AB224D7612558BADD40ABAB1F4BAF958230936496C666E023A1CDCAF

SSDEEP:

6144:V6BpU5+O7VH1Daw+wkoCt+xltSjzj98Dqq/0M6znwb:V4Y+6VH1DuwkoCtRPWDqkonu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Email came from third-party service (Amazon SES)

      • OUTLOOK.EXE (PID: 4024)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • Acrobat.exe (PID: 4888)
      • Acrobat.exe (PID: 7600)
      • AcroCEF.exe (PID: 2124)
    • Email with attachments

      • OUTLOOK.EXE (PID: 4024)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6384)
      • Acrobat.exe (PID: 4412)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 6384)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.txt | Text - UTF-8 encoded (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
18
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe ai.exe no specs openwith.exe no specs acrobat.exe acrobat.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrobat.exe no specs acrobat.exe no specs acrocef.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2764 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1700"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=2996 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2124"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16514043C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2464"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2108 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3872"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --first-renderer-process --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2380 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4024"C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml C:\Users\admin\AppData\Local\Temp\Message.emlC:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4120"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "102BBAB2-FD88-4DE7-8377-C3D34CA2F968" "6D5950DD-9890-4D51-9E2E-0040B4E6C54A" "4024"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\rpcrt4.dll
4412"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4888"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
OpenWith.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6368"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2724 --field-trial-handle=1600,i,5742474032114870542,6043224408379339936,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
26 659
Read events
26 188
Write events
419
Delete events
52

Modification events

(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData
Operation:writeName:SessionId
Value:
9412D84A-4E91-4929-A84F-6A9A951390B1
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootFailureCount
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Preferences
Operation:delete valueName:ChangeProfileOnRestart
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\outlook
Operation:writeName:BuildNumber
Value:
16.0.16026
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:writeName:Expires
Value:
int64_t|0
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:delete valueName:ConfigIds
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:delete valueName:ETag
Value:
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.40
Value:
7468656E7469636174696F6E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22526573756C7447726F7570546F52656E6465725C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2253656E64576562536F636B6574526571756573745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22576562536F636B657450696E67506F6E674C6174656E63795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22446961676E6F737469635C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C225375624E616D657370616365735C22203A207B205C22486F73745C22203A207B205C224576656E74735C22203A207B205C22496E7365727448746D6C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E736572744F6F786D6C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C61756E6368466565644261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E64436F7079746F436C6970426F6172645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E7365727448797065726C696E6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225365744D65737361676543616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2245786563757465416374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656C65637452616E67655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537461727450616E654C61756E636865725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537461727453696E676C65537472696E6750616E65734C61756E636865725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E7365727444617461547970655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E73657274546578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E766F6B6546696C6573416374696F6E735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E64436F7079546F436C6970426F6172645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E61766967617465546F50616E655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416374696F6E4E6F74496D706C656D656E7465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2242726F7773654E617469766546696C65735C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2238564D65686C6C5C22203A207B205C225375624E616D657370616365735C22203A207B205C22356B69614B3747426B7A505746675C22203A207B205C224576656E74735C22203A207B205C22373139305C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C22385C22203A207B205C225375624E616D657370616365735C22203A207B205C227A424B387872415553554E52497859484E4B55415C22203A207B205C224576656E74735C22203A207B205C22393133335C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C224F66666963655C22203A207B205C224576656E74735C22203A207B205C2253797374656D644D617463685C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C225375624E616D657370616365735C22203A207B205C22496E7369676874735C22203A207B205C224576656E74735C22203A207B205C22536D6172744C6F6F6B75705C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536D6172744C6F6F6B75705F5F5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536D6172744C6F6F6B75705F5F5F5C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2253797374656D5C22203A207B205C224576656E74735C22203A207B205C2241637469766974795C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2253797374656D68633863674F6A46515C22203A207B205C224576656E74735C22203A207B205C22383635335C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D207D207D2C205C22556952756E74696D655C22203A207B205C224576656E74735C22203A207B205C224F6E50616E65436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E74656E745365727669636550726F78794F6E436F6E6E656374696F6E436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E436F6E6E656374696F6E436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F636573735265717565737451756575655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E64526571756573745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E50616E6552656164795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22576562536F636B6574436C69656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65496E636F6D696E674D6573736167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436C65616E50616E6553657373696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22437265617465576562536F636B65745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E6557697468536561726368526573756C745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E53535248746D6C52656164795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E65576974685353524A7346696C655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F63657373526571756573745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E65576974684E6574776F726B4572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E50616E65436C6F73696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E446174614D65737361676552656365697665645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22437265617465486F7374536B696C6C4576656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6F7469667950616E6557697468496E446F6346616C6C6261636B446174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D6F6E69746F724C6976656E657373416E645265706F727449664572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E50616E6548796472617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E4F66666963654A734C6F616465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C61756E636850616E6543616E63656C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224E6174697665536561726368526573756C74735265717565737465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E646F63536561726368436F72655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E644D6573736167654532455C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225365617263684C6F63616C50726F7669646572735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22536561726368446F63756D656E74436F6E74656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22536561726368436F72655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726570617265536561726368436F6E746578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250616E65416374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22536B696C6C735C22203A207B205C225375624E616D657370616365735C22203A207B205C224C6F63616C5365617263685C22203A207B205C224576656E74735C22203A207B205C224C6F63616C5365617263685C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E496E74656C6C6967656E745365727669636573222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C224F7074496E5C22203A207B205C224576656E74735C22203A207B205C225573657252656A65637465644F7074496E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F774469616C6F675C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C6561726E696E67222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C656E73222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C6963656E73696E67222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74735C22203A207B205C22436F70696C6F745374617475735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22436F6D70617265427573426172735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224C6963656E73696E67427573626172416374696F6E5C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C22487244697370617463685375625461736B53746172745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22517569636B56616C69646174696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253617665416C6C536B75696473546F52656769737472795C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2257616974546F52657472794865617274626561745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536561726368466F7253657373696F6E546F6B656E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224E554C56616C69646174696F6E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2256616C696461746553657373696F6E546F6B656E5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2243616E52756E4665617475726543616368655C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22506572666F726D4C6963656E73696E674E6F74696669636174696F6E735C22203A207B205C224576656E74466C61675C22203A20323536207D207D2C205C224576656E74466C61675C22203A20312C205C225375624E616D657370616365735C22203A207B205C22466C6F77735C22203A207B205C224576656E74735C22203A207B205C2253686F7753756250726545787069726174696F6E4469616C6F675C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C2253686F77537562736372697074696F6E506F737445787069726174696F6E4469616C6F675C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C2253686F774E6F537562736372697074696F6E466F756E644469616C6F675C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C22536561726368466F72534341546F6B656E5C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224C5655585C22203A207B205C224576656E74735C22203A207B205C224E6F456E7469746C656D656E74735C22203A207B205C224576656E74466C61675C22203A203439343038207D2C205C224E6F456E7469746C656D656E74734578706572696D656E74547269676765725C22203A207B205C224576656E74466C61675C22203A203439343038207D207D207D2C205C224F6666696365436C69656E744C6963656E73696E675C22203A207B205C224576656E74735C22203A207B205C224C6963656E7365436F6D706C657465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224C6567616379416374697669747953756363657373436F756E745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224C656761637941637469766974794661696C757265436F756E745C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C225375624E616D657370616365735C22203A207B205C22436C69656E745C22203A207B205C224576656E74735C22203A207B205C224653686F756C6441637469766174655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C224865617274626561745C22203A207B205C224576656E74735C22203A207B205C22577269746543616368655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225265616443616368655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22517569636B56616C69646174696F6E5C22203A207B205C224576656E74735C22203A207B205C224C6F61644C6963656E73655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2246756C6C56616C69646174696F6E5C22203A207B205C224576656E74735C22203A207B205C224C6F61644C6963656E73655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C2250726F706572746965735C22203A207B205C224576656E74735C22203A207B205C224765744C6963656E736543617465676F72795C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546F6B656E697A654C6963656E736543617465676F726965735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225570646174654C6963656E736543617465676F726965735C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224272616E64696E675C22203A207B205C224576656E74735C22203A207B205C2247657441707056616C75655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2247657450726F6475637456616C75655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253686F756C645573654D6963726F736F66743336354272616E64696E675C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2254656E616E745C22203A207B205C224576656E74735C22203A207B205C22496E697454656E616E7449645C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C224E756C5C22203A207B205C225375624E616D657370616365735C22203A207B205C22466574636865725C22203A207B205C224576656E74735C22203A207B205C224765744E756C4F626A656374466F724964656E746974795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2246657463684D6F64656C46726F6D4F6C735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224765744C6963656E73654665617475726573466F724964656E746974795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2243726561746552657175657374426F64795C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C224D6F64656C5C22203A207B205C224576656E74735C22203A207B205C224765744C6963656E736543617465676F72795C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22476574416C6C4C6963656E736543617465676F726965735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22446573657269616C697A655C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C225061727365526177526573706F6E73655C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2243616E52756E46656174757265526573756C74735C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224D6F64655C22203A207B205C224576656E74735C22203A207B205C224765744D6F64655C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C224170695C22203A207B205C224576656E74735C22203A207B205C22437265617465526571756573745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2253656E64526571756573745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2252656365697665526573706F6E73655C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2253746F726167655C22203A207B205C224576656E74735C22203A207B205C2247657453746F72616765506174685C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224C6F61644D6F64656C735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C22476574556E766572696669656453746F72616765506174685C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224C6F61644D6F64656C5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2252656E616D6546696C65546F55736555706461746564486173685C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2256616C69
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|40
(PID) Process:(4024) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.41
Value:
646174696F6E5C22203A207B205C224576656E74735C22203A207B205C22517569636B56616C69646174696F6E5C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D2C205C2256616C696461746F725C22203A207B205C224576656E74735C22203A207B205C224D61746368696E67486172776172656449645C22203A207B205C224576656E74466C61675C22203A20323536207D207D207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C6F6F6B7570222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4C756D6F73222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D33363544657369676E6572222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D3336354A756D707374617274222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D4155222C20225622203A20227374643A3A77737472696E677C7B205C225375624E616D657370616365735C22203A207B205C22436C69656E745C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D4C222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C225541504576656E7453696E6B5C22203A207B205C225375624E616D657370616365735C22203A207B205C224F49534F70746564496E5C22203A207B205C224576656E74735C22203A207B205C22315C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224C6F67534947535369676E616C5C22203A207B205C224576656E74735C22203A207B205C22325C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22315C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D2C205C224D6F64656C446F776E6C6F61645C22203A207B205C224576656E74735C22203A207B205C2250726F636573735265736F75726365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225570646174655265736F757263655461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F675461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F67436163686545785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526571756573745265736F75726365496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22506F6C796D6572536572766963654572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F63657373436174616C6F67526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F776E6C6F61645265736F757263657346726F6D436174616C6F674173796E635C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D53546F646F222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A2032207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E4D616B6572222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C225344585C22203A207B205C224576656E74735C22203A207B205C2253746172745265636F7264696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2246657463684D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22417574686F72697A655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466574636853637269707446726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466574636853686172656453637269707446726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574416363657373546F6B656E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F61644D6F6E61636F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225075626C6973685363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756E5363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574557365725065726D697373696F6E735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253746F705265636F7264696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2244656C6574655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C61756E63685461736B70616E655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F674974656D5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E74656C6C6967656E63655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224475706C69636174655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22417474616368536372697074546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446574616368536372697074546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265616453637269707449647346726F6D576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265766572745363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686172655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E697469616C697A654D6F6E61636F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22556E736861726553637269707446726F6D416C6C576F726B626F6F6B735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6E73656E74546F52756E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466574636853616D706C65735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D61726B46756E6374696F6E417267756D656E744572726F725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D61726B4C696E7465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225472616E73666F726D5363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6D70696C655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265636F6D6D656E644C696E6B735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F61644368756E6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6164417574684C6962726172795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765744F7267616E697A6174696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574436F6E73656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22507574436F6E73656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F63616C53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416464427574746F6E546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765745069636B65645363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224665746368526563656E744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2246657463685363726970747346726F6D446F63756D656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656D6F7665526563656E745363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574416C6C53637269707456657273696F6E7346726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756E46726F6D427574746F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574477261706853637269707446726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E697469616C697A65416374696F6E48616E646C65725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F7079436F64655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6752756E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416464536372697074546F576F726B626F6F6B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574436F64655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756E74696D6552756E6E61626C655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22507265706172655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466C6F6174696E674469616C6F675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225072656C6F616452756E74696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225072656665746368546F6B656E4F6E4465736B746F705C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574557365727346726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F774F7248696465427573696E6573734261725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657452756E74696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224170695365744C696E7465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574576F726B626F6F6B4964735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765745072696D6172794964656E74697479456D61696C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224665746368526563656E745363726970744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D6F76655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657446696C654E616D65436F6E666C696374735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22564241457863656C4576656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224372656174655363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22566965775363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224372656174654E657750726F6D70745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F4E6F7453686F774261636B67726F756E645265636F72646572416761696E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22536176655265636F7264696E67496E4261636B67726F756E645265636F726465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574466C6F77735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224261636B67726F756E645265636F7264657253746F7048616E646C65725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F774261636B67726F756E645265636F7264696E6755495C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253746172744261636B67726F756E645265636F7264696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2244656C6574655265636F72646572416374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224564697461626C65496E74656E74456469745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2243726561746552756E74696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22476574496E74656E744461746146726F6D5363726970745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224564697461626C65496E74656E745061727365725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657444656661756C74456E7669726F6E6D656E745C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C22476574557365725065726D697373696F6E735C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2246657463684D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22466574636853637269707446726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C225075626C6973685363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22466574636853686172656453637269707446726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22556E736861726553637269707446726F6D416C6C576F726B626F6F6B735C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2244656C6574655363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2253686172655363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224765744F7267616E697A6174696F6E5C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574436F6E73656E745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22507574436F6E73656E745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574477261706853637269707446726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224665746368526563656E744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574416C6C53637269707456657273696F6E7346726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2252656D6F7665526563656E745363726970745C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574557365727346726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22476574576F726B626F6F6B4964735C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224665746368526563656E745363726970744D6574616461746146726F6D53746F726167655C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224C6F6752756E5C22203A207B205C224576656E74735C22203A207B205C22496E7465726E616C5C22203A207B205C22
Executable files
0
Suspicious files
210
Text files
18
Unknown types
7

Dropped files

PID
Process
Filename
Type
4024OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bintext
MD5:FCAEB316E0CCE213F9BC8FD0FEB5D54B
SHA256:28FDBCFFEA1AFA8BC16F33EF460B32B9E819F5F357716A994BD133CCD60A4EF6
4024OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:2B9EA5F48A466F136E92EE1CEFB0C1C6
SHA256:2F2AA2FB1CC5D87D80819EBB3B7E61F56C3FC418194A2FFBBBDAF690A077B877
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbresbinary
MD5:00032D490D3B8DD50254EFAA69968BCC
SHA256:7F0629A54922664B63AB7DFB1A72AD894B3305C81AC79A98165219FE47418E4D
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707.pdfpdf
MD5:97FFE9601381B542AA6021A150CE2598
SHA256:C91808666B0C4BA77F494DF26A950425F5265F6787DE4F31994D4B503FEB6114
4024OUTLOOK.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Ader
MD5:BA2E856E003AD5AAB689936628217AF8
SHA256:27631132DFC8179561317DCAAA3881E0B7FE85B46776F52B0E48291F722F92FF
4024OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\TBQHIL0L\lNV_00707 (002).pdfpdf
MD5:97FFE9601381B542AA6021A150CE2598
SHA256:C91808666B0C4BA77F494DF26A950425F5265F6787DE4F31994D4B503FEB6114
4024OUTLOOK.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Abinary
MD5:34BF57A99E64D115E6F2D2C55290A27C
SHA256:A1A8AD21713515B0E3FCCA0D0E5DCCA913D01543B1C6A3C9AC768B345EC41C30
4412Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.jsonbinary
MD5:837C1211E392A24D64C670DC10E8DA1B
SHA256:8013AC030684B86D754BBFBAB8A9CEC20CAA4DD9C03022715FF353DC10E14031
4412Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTINGmp3
MD5:DC84B0D741E5BEAE8070013ADDCC8C28
SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2612
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4024
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7408
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7408
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4888
Acrobat.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2648
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4024
OUTLOOK.EXE
52.123.129.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4024
OUTLOOK.EXE
2.16.168.119:443
omex.cdn.office.net
Akamai International B.V.
RU
whitelisted
4024
OUTLOOK.EXE
52.111.231.8:443
messaging.lifecycle.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.241.14:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted
omex.cdn.office.net
  • 2.16.168.119
  • 2.16.168.113
whitelisted
messaging.lifecycle.office.com
  • 52.111.231.8
whitelisted
crl.microsoft.com
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
self.events.data.microsoft.com
  • 20.42.72.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.128
  • 20.190.159.75
  • 40.126.31.131
  • 20.190.159.23
  • 20.190.159.0
  • 40.126.31.2
  • 40.126.31.73
  • 40.126.31.128
whitelisted

Threats

No threats detected
No debug info