File name:

PR1680 - TEKLİF İSTEĞİ - TUSAŞ TÜRK HAVACILIK UZAY SANAYİİ.eml

Full analysis: https://app.any.run/tasks/06cbd53b-1b1b-49bb-988b-b0b7aa4aa4e3
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: May 28, 2025, 09:07:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
snake
keylogger
evasion
telegram
stealer
Indicators:
MIME: message/rfc822
File info: SMTP mail, Unicode text, UTF-8 text
MD5:

CB4AAD53D6A1989EF1D1BD839C27C3F9

SHA1:

0548C6C4AC8D5AA4BE4AB24BB3236CCD45BEB7E5

SHA256:

A1D8B83BB0819DA5EBCC3C0D3E40CB7655B9FF53AA7F105BC7BE1A106D76B6F2

SSDEEP:

12288:OhGD6Zn/Y168qk0BV5Ok5V7X+1b7H0IY9+0NvjyZ05+xOKDNmr1WY8zP+l9qcNfT:OhGJ50BDz+1UI8NvjylDNmr1Az2rlNfT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • OUTLOOK.EXE (PID: 5136)
    • Create files in the Startup directory

      • chiffons.exe (PID: 2084)
    • SNAKEKEYLOGGER has been detected (SURICATA)

      • RegSvcs.exe (PID: 7996)
    • Actions looks like stealing of personal data

      • RegSvcs.exe (PID: 7996)
    • Steals credentials from Web Browsers

      • RegSvcs.exe (PID: 7996)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1176)
    • Executable content was dropped or overwritten

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
    • Starts itself from another location

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
    • Checks for external IP

      • RegSvcs.exe (PID: 7996)
      • svchost.exe (PID: 2196)
    • The process verifies whether the antivirus software is installed

      • RegSvcs.exe (PID: 7996)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • RegSvcs.exe (PID: 7996)
  • INFO

    • The sample compiled with english language support

      • OUTLOOK.EXE (PID: 5136)
      • WinRAR.exe (PID: 1176)
      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
    • Checks supported languages

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • chiffons.exe (PID: 2084)
      • RegSvcs.exe (PID: 7996)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1176)
    • Reads mouse settings

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • chiffons.exe (PID: 2084)
    • Create files in a temporary directory

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • chiffons.exe (PID: 2084)
    • Reads the machine GUID from the registry

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • RegSvcs.exe (PID: 7996)
    • Creates files or folders in the user directory

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • chiffons.exe (PID: 2084)
    • Launch of the file from Startup directory

      • chiffons.exe (PID: 2084)
    • Reads the computer name

      • RegSvcs.exe (PID: 7996)
    • Disables trace logs

      • RegSvcs.exe (PID: 7996)
    • Checks proxy server information

      • RegSvcs.exe (PID: 7996)
    • Reads the software policy settings

      • slui.exe (PID: 7256)
      • RegSvcs.exe (PID: 7996)
    • Attempting to use instant messaging service

      • svchost.exe (PID: 2196)
    • Manual execution by a user

      • WinRAR.exe (PID: 7748)
      • WinRAR.exe (PID: 5132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 1) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe sppextcomobj.exe no specs slui.exe ai.exe no specs winrar.exe pr1680-tekli̇f i̇steği̇-usaş türk havacilik uzay sanayi̇i̇_xlsx.exe chiffons.exe #SNAKEKEYLOGGER regsvcs.exe svchost.exe mspaint.exe no specs slui.exe no specs winrar.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1176"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.z"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2084"C:\Users\admin\AppData\Local\Temp\Rar$EXa1176.8300\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe" C:\Users\admin\AppData\Local\fornices\chiffons.exe
PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\fornices\chiffons.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2504"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "0CCB0F67-EC83-47BC-A5B4-D3D50E1D0393" "AB44AD8D-8483-41CF-A687-C5CF0B913094" "5136"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
3156"C:\Users\admin\AppData\Local\Temp\Rar$EXa1176.8300\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1176.8300\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1176.8300\pr1680-tekli̇f i̇steği̇-usaş türk havacilik uzay sanayi̇i̇_xlsx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
5064C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5132"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5136"C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\PR1680 - TEKLİF İSTEĞİ - TUSAŞ TÜRK HAVACILIK UZAY SANAYİİ.eml"C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
16.0.16026.20146
Modules
Images
c:\windows\system32\inputhost.dll
c:\windows\system32\twinapi.appcore.dll
c:\windows\system32\coremessaging.dll
c:\windows\system32\coreuicomponents.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\windows.ui.immersive.dll
c:\windows\system32\webservices.dll
c:\windows\system32\sppc.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wbem\wbemsvc.dll
5364C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
7256"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msxml6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\ondemandconnroutehelper.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\webio.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winnsi.dll
Total events
21 214
Read events
19 908
Write events
1 163
Delete events
143

Modification events

(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData
Operation:writeName:SessionId
Value:
FAA57D89-361B-43BE-B0FF-9250DA8AD790
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootFailureCount
Value:
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\0a0d020000000000c000000000000046
Operation:writeName:00030429
Value:
09000000
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData
Operation:writeName:ProfileBeingOpened
Value:
Outlook
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\0a0d020000000000c000000000000046
Operation:writeName:00030397
Value:
60000000
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|57
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.58
Value:
31207D2C205C2253797374656D4865616C74684D6574616461746144656C617965644C6F67696E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468526F6C6C6261636B53657373696F6E4D657461646174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224964656E746974794368616E6765645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557365724368616E676564446961676E6F737469634C6576656C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468556E677261636566756C4170706C69636174696F6E4578697457696E33325C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684465736B746F7053657373696F6E4C6966656379636C65416E644865617274626561745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684F66666963654C656E734964656E746974795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468457373656E7469616C4D65746164617461416C6C4964656E7469746965735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E48616E646F66665C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D65366164617461446576696365436F6E736F6C6964617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468526F6C6C6261636B53657373696F6E4D653661646174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461647474614170706C69636174696F6E416E644C616E67756167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468556E677261636566756C417070457869744465736B746F705265616C54696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253387374656D4865616C74684D657461646174614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646134614F535C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D65746164747461446576696365436F6E736F6C6964747465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461647474614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461647474614F535C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614170706C6963303A34502D416464693A34502D616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D653661646174614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614170706C69636174696F6E416E644C616E67756167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D65746164617461446576696365436F6E736F6C6964617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614F535C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C2253797374656D4865616C7468457373656E7469616C4D65746164617461416C6C4964656E7469746965735C22203A207B205C224576656E74735C22203A207B205C22416E64726F69645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224170706C6556335C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224D62755C22203A207B205C225375624E616D657370616365735C22203A207B205C224170706C655C22203A207B205C224576656E74735C22203A207B205C224465766963654163636573736962696C69747953657474696E67735C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D2C205C2253797374656D4865616C74684D6574616461746144657669636545534D5C22203A207B205C224576656E74735C22203A207B205C22416E64726F69645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224170706C655C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22477261636566756C457869745C22203A207B205C224576656E74735C22203A207B205C22477261636566756C417070457869744465736B746F705265616C54696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22477261636566756C417070457869744465736B746F705C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54616F73222C20225622203A20227374643A3A77737472696E677C7B205C225375624E616D657370616365735C22203A207B205C224875625C22203A207B205C225375624E616D657370616365735C22203A207B205C22446961676E6F737469635C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C224576656E74466C61675C22203A2032207D2C205C224D333635457874656E73696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225368656C6C5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224D66735C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54617267657465644D6573736167696E67222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C2241424578706572696D656E744D657373616765547269676765725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22456E737572654361636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224275736261725468656D6553656C656374696F6E5374617475735C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54656C656D65747279222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74735C22203A207B205C224C6F6164656452756C65735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2253797374656D4865616C74684D657461646174614E6574776F726B436F73745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E655370696B655468726F74746C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254656C656D65747279556C73517565756555736167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E655468726F74746C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E654D656469756D436F73745468726F74746C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2257726974655061796C6F616473546F4469736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657446696C74657265645061796C6F61647346726F6D4469736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6164586D6C52756C65735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614E6574776F726B436F73744368616E67655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E54656C656D6574727952756C6573436F756E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D697373696E674669656C6444657461696C735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E65556C73517565756553697A654261636B67726F756E6450726F63657373696E674C6576656C526561636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E54656C656D6574727952756C65734368616E6765645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254656C656D6574727941637469766974794167677265676174696F6E57696E646F77537461746973746963735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253616D706C696E67506F6C6963794576656E74547269676765725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E54656C656D6574727952756C6573496E697469616C53746174655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22566F6C756D65547261636B696E67446174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656473746F6E65496E626F7853616D706C696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224576656E7451756172616E74696E65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656473746F6E65496E626F7853616D706C696E67437269746963616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E76616C6964446174614669656C644E616D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253616D706C696E67506F6C6963795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436C69656E7453616D706C696E674F76657272696464656E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F6365737349646C6551756575654A6F625C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466C7573684576656E744275666665725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22556C735175657565546F705468726F74746C696E67546167735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446961676E6F737469634461746156696577657253746174654368616E6765645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224661696C6564526567696F6E526F7574696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C654572726F7273416767726567617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526F7574696E6754656C656D657472795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2246696C654F70656E50726F66696C696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247656E65726174656452756C657346696C65496E666F5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224C6F6164656452756C6573436F756E745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2254656C656D6574727953656E74696E656C56616C75655C22203A207B205C224576656E74466C61675C22203A2030207D207D2C205C225375624E616D657370616365735C22203A207B205C2253747564696F5C22203A207B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C224170704C61756E636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224661696C7572655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225072697661637949737375654C696D6974526561636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22507269766163794973737565446574656374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2244796E616D6963436F6E6669675C22203A207B205C224576656E74735C22203A207B205C224665746368436F6E666967735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22506F70756C6174655472656543616C6C6564416761696E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22506F70756C6174655265717565737449676E6F7265645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250617273654A736F6E436F6E6669675C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22436F6D706C69616E63655C22203A207B205C224576656E74735C22203A207B205C224576656E744E6F74496E4261736963416C6C6F774C6973745C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22417269614576656E7453696E6B5C22203A207B205C224576656E74735C22203A207B205C2248616E646C654D7361446576696365546F6B656E526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526571756573744D7361446576696365546F6B656E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224F54656C43535C22203A207B205C224576656E74735C22203A207B205C2253696E6B53687574646F776E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253696E6B4163746976617465645C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D2C205C224576656E74466C61675C22203A20322C205C224C6F636B65645C22203A2066616C7365207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54656C6C4D65222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C22436C69636B6564526573756C745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F776E526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C2254656C6C4D65445C22203A207B205C224576656E74735C22203A207B205C2248656C70466C796F7574436C69636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C7053657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C70526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C70466C796F757444726F707065645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224578656375746564436F6D6D616E645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537562737461746553657276696365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F775465616368696E6743616C6C6F75745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656E6465726564526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F63756D656E74416374696F6E4576656E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250656F706C65416374696F6E4576656E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6D6D616E64436C69636B65644576656E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E6C696E6553756767657374696F6E526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C7053657276696365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756273746174654F666669636557656253657276696365526573706F6E736544657461696C735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756273746174654F666669636557656253657276696365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252616E6B526573756C7447726F7570735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416C77617973436F6C6C6170736564536561726368426F785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224175746F446973636F766572537562737472617465526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2241707053657373696F6E436F6E746578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225175657279496E6465784C6F6767696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E456E6453746174654C6F6767696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22566F6963655365617263684D69635C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E6C696E6553756767657374696F6E526573706F6E736553616D706C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D6F64656C446F776E6C6F61645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537562737461746553657276696365526573706F6E736553616D706C65645C22203A207B205C2245
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|58
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.59
Value:
76656E74466C61675C22203A2031207D2C205C22566F69636553656172636853746172745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656E6465726564526573756C747353616D706C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537461727453657373696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526573756C7447726F7570547970654F726465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254696D696E674D6574726963735C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C224D61635C22203A207B205C224576656E74735C22203A207B205C225463696473417070656172496E466C796F75745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E736967687473436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225472795175657279436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D2C205C224465736B746F7055495C22203A207B205C224576656E74735C22203A207B205C2245786563757465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65526573756C7473557064617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65526573756C74735570646174656455785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22497373756551756572795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E697450726F76696465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254656C6C4D65506172616D65746572697A6174696F6E4475726174696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2254656C6C6D65536572766963655C22203A207B205C224576656E74735C22203A207B205C2250726F76696465724C6174656E63795C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2254656C6C4D655741435C22203A207B205C224576656E74735C22203A207B205C225175657279526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54657374222C20225622203A20227374643A3A77737472696E677C7B205C225375624E616D657370616365735C22203A207B205C22455544425C22203A207B205C225375624E616D657370616365735C22203A207B205C2270726F6A6563745C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54657874222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C225265736F75726365436C69656E745C22203A207B205C224576656E74735C22203A207B205C22557064617465436174616C6F675461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F63657373436174616C6F67526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225570646174655265736F757263655461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526571756573745265736F75726365496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F636573735265736F75726365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F67436163686545785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446573657269616C697A655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765744261736555524C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656164466F6E74456C656D656E74735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2250757267654D756C7469706C655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22526561645265736F757263654D657461446174615C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2257726974655265736F757263654D657461446174615C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22474449417373697374616E745C22203A207B205C224576656E74735C22203A207B205C2248616E646C6543616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265676973746572436C6F7564466F6E7443616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416464436C6F7564466F6E745265736F757263655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656D6F766550726576696577466F6E745265736F7572636541637469766974795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657456657273696F6E696E674469726563746F72795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2241646450726576696577466F6E745265736F7572636541637469766974795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65466F6E7443616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F776E6C6F61644261636B67726F756E645461736B466F6E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466F6E744D616E6167657244657374727563746F725C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22437573746F6D5265736F7572636573436C69656E745C22203A207B205C224576656E74735C22203A207B205C2250726F63657373436174616C6F67526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F675461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F636573735265736F75726365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225570646174655265736F757263655461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F67436163686545785C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22445772697465417373697374616E745C22203A207B205C224576656E74735C22203A207B205C2252657175657374436C6F7564466F6E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6164436C6F7564466F6E7446616D696C795C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22466F6E74537562737469747574696F6E5C22203A207B205C224576656E74735C22203A207B205C22436F6C6C656374466F6E74537562737469747574696F6E55736167655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E5472616E736C61746F72222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C224D657373736167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F75746C6F6F6B416464696E54726163655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416C7465726E6174655472616E736C6174696F6E735265747269657665645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22436F6E7465787475616C53756767657374696F6E734C6F616465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745465787453656C65637465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C617465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C61746564466565646261636B547269676765725C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C6174696F6E43616E63656C6C65645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C6174696F6E53756767657374696F6E436C69636B65645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224578636C756465644C616E677561676541646465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224578636C756465644C616E677561676552656D6F7665645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224D6963726F666565646261636B566F746553656C65637465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224F6F786D6C5472616E736C617465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253657474696E6773436C6F7365645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253657474696E67734F70656E65645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536F75726365446F63756D656E744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536F75726365546172676574537761707065645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536F75726365546578744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546172676574446F63756D656E744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546172676574546578744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546578745472616E736C617465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225472616E736C6174696F6E496E7365727465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225472616E736C6174696F6E4C616E6775616765734C6F616465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225472616E736C6174696F6E5461624368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22416C7465726E6174655472616E736C6174696F6E4578616D706C655265747269657665645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22416C7465726E6174655472616E736C6174696F6E436F706965645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22416464496E4C6F616465645C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E5558222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74735C22203A207B205C22436F6C6F725069636B65725C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22466C75656E7452656672657368456C696769626C654275744E6F74456E61626C65645C22203A207B205C224576656E74466C61675C22203A20353132207D2C205C22436F6D696E67536F6F6E54435348574E445C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22436F6D696E67536F6F6E48724D616B65526571756573745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224E6F46696C65457874656E73696F6E49636F6E4D617070696E675C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C224E55494469616C6F675C22203A207B205C224576656E74735C22203A207B205C224469616C6F67506F736974696F6E41646A75737465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F67436C697070696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F67426F6F7454696D655C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C225465616368696E6743616C6C6F75745C22203A207B205C224576656E74735C22203A207B205C22466C75656E74535646697273745465616368696E6743616C6C6F757453686F774D65427574746F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254727953686F77466C75656E7453565465616368696E6743616C6C6F75745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466C75656E74514154437573746F6D697A6174696F6E545549416374696F6E427574746F6E436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225465616368696E6743616C6C6F7574416C726561647953686F776E4D617854696D65735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225465616368696E6743616C6C6F7574416C726561647953686F776E5468697353657373696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225465616368696E6743616C6C6F7574546F6F4D616E7953686F776E5468697353657373696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22436F70696C6F745C22203A207B205C224576656E74735C22203A207B205C224469616C6F67446973706C617965645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656D6F766547656E657261746564436F6E74656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557365496E73706972654D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F67436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526567656E657261746550726F6D70745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247656E657261746550726F6D70745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2243616E63656C50726F6D707447656E65726174696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224B65657047656E657261746564436F6E74656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466565646261636B5375626D69747465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22434951436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F6750726576696F75735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F674E6578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F67547279436F70696C6F745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224349514F70656E65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F67536574506167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F674E6F744E6F775C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F67446973706C617965645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6E74656E7452656365697665645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F674469736D6973734F6E456469745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E73697469766974794C6162656C4170706C6965645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22434951536561726368537563636573735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224572726F724F6363757265645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224368756E6B50726F6365737365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224361726F7573656C496E746572616374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22457870616E64656455495C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6C6C617073656455495C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22434951456E74697479496E7365727465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756767657374656450726F6D7074436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756767657374656450726F6D7074735C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C225344585C22203A207B205C225375624E616D657370616365735C22203A207B205C224D65436F6E74726F6C5C22203A207B205C224576656E74735C22203A207B205C22547261636B65645363656E6172696F5C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C2244796E616D69634470695C22203A207B205C224576656E74735C22203A207B205C22446973706C6179546F706F6C6F67
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|59
Executable files
3
Suspicious files
15
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
5136OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\1E00DE1F.datimage
MD5:A50F656CB5B94D2F52DFCD60B818C71C
SHA256:4FBFE0E80531030B6372FAD28F5ED8048654DA6F32EEE2EE36E52598DED6A43D
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\image8970d4.PNGimage
MD5:A601E79A1F995A0226FD2B6E23E95AB9
SHA256:1E2D6BB0845157E631E15829E253738FB13DD5A027F36740B54047C73B45268F
5136OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:A9D5B23CB31349C3AC9CB1A3812CB641
SHA256:BF158373EBB19B9FB3AB8252A97797639FBA9EB21DD394B6BE6C05AC2441A5CA
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\imagede422e.PNGimage
MD5:CC2EE19DEFF58C63612656A92AFB91BE
SHA256:9B49A52B5ABDB1A49B2BEE0046B64D76B6D5DE5EA5D9444D491427DCA792A859
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbresbinary
MD5:BFDF5FC85EC4CD658E3D45996E0D4E5B
SHA256:C82C9C5AB71DC6361FF07C0816970A66348E96257E78A4AF2C80C3C0A676FD8A
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\1E5740C2.datimage
MD5:E0871A5EB9955BCAB9B8408B19B5AE56
SHA256:1FE6851233F6D8D516E653229B4ABDFC2938EBE1905E0B84AB5E60727CB4268E
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\81453D16.datimage
MD5:7A621044E29137E442C530F1CCAE9DB3
SHA256:82CF129A3CCA66152695CCA8BD690F771210E11B7F84EFAEF67437E940532355
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\image8970d4.PNG:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\imagede422e.PNG:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
33
DNS requests
26
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5136
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1240
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7532
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5136
OUTLOOK.EXE
52.123.130.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5136
OUTLOOK.EXE
23.48.23.11:443
omex.cdn.office.net
Akamai International B.V.
DE
whitelisted
5136
OUTLOOK.EXE
52.109.136.6:443
messaging.lifecycle.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.20
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
ecs.office.com
  • 52.123.130.14
  • 52.123.131.14
whitelisted
omex.cdn.office.net
  • 23.48.23.11
  • 23.48.23.43
  • 23.48.23.66
  • 23.48.23.30
  • 23.48.23.18
whitelisted
messaging.lifecycle.office.com
  • 52.109.136.6
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.130
  • 20.190.159.68
  • 20.190.159.128
  • 20.190.159.71
  • 40.126.31.71
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Device Retrieving External IP Address Detected
ET DYN_DNS External IP Lookup Domain in DNS Query (checkip .dyndns .org)
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO 404/Snake/Matiex Keylogger Style External IP Check
2196
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Address Lookup Domain (reallyfreegeoip .org)
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Misc activity
ET INFO External IP Lookup Service Domain (reallyfreegeoip .org) in TLS SNI
2196
svchost.exe
Misc activity
ET INFO External IP Address Lookup Domain in DNS Lookup (reallyfreegeoip .org)
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
No debug info