File name:

PR1680 - TEKLİF İSTEĞİ - TUSAŞ TÜRK HAVACILIK UZAY SANAYİİ.eml

Full analysis: https://app.any.run/tasks/06cbd53b-1b1b-49bb-988b-b0b7aa4aa4e3
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: May 28, 2025, 09:07:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
snake
keylogger
evasion
telegram
stealer
Indicators:
MIME: message/rfc822
File info: SMTP mail, Unicode text, UTF-8 text
MD5:

CB4AAD53D6A1989EF1D1BD839C27C3F9

SHA1:

0548C6C4AC8D5AA4BE4AB24BB3236CCD45BEB7E5

SHA256:

A1D8B83BB0819DA5EBCC3C0D3E40CB7655B9FF53AA7F105BC7BE1A106D76B6F2

SSDEEP:

12288:OhGD6Zn/Y168qk0BV5Ok5V7X+1b7H0IY9+0NvjyZ05+xOKDNmr1WY8zP+l9qcNfT:OhGJ50BDz+1UI8NvjylDNmr1Az2rlNfT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • OUTLOOK.EXE (PID: 5136)
    • Create files in the Startup directory

      • chiffons.exe (PID: 2084)
    • Steals credentials from Web Browsers

      • RegSvcs.exe (PID: 7996)
    • SNAKEKEYLOGGER has been detected (SURICATA)

      • RegSvcs.exe (PID: 7996)
    • Actions looks like stealing of personal data

      • RegSvcs.exe (PID: 7996)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
    • Starts itself from another location

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1176)
    • Checks for external IP

      • svchost.exe (PID: 2196)
      • RegSvcs.exe (PID: 7996)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • RegSvcs.exe (PID: 7996)
    • The process verifies whether the antivirus software is installed

      • RegSvcs.exe (PID: 7996)
  • INFO

    • The sample compiled with english language support

      • OUTLOOK.EXE (PID: 5136)
      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • WinRAR.exe (PID: 1176)
    • Reads mouse settings

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • chiffons.exe (PID: 2084)
    • Launch of the file from Startup directory

      • chiffons.exe (PID: 2084)
    • Creates files or folders in the user directory

      • chiffons.exe (PID: 2084)
      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
    • Create files in a temporary directory

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • chiffons.exe (PID: 2084)
    • Checks supported languages

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • RegSvcs.exe (PID: 7996)
      • chiffons.exe (PID: 2084)
    • Reads the machine GUID from the registry

      • PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe (PID: 3156)
      • RegSvcs.exe (PID: 7996)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1176)
    • Disables trace logs

      • RegSvcs.exe (PID: 7996)
    • Reads the computer name

      • RegSvcs.exe (PID: 7996)
    • Checks proxy server information

      • RegSvcs.exe (PID: 7996)
    • Attempting to use instant messaging service

      • svchost.exe (PID: 2196)
    • Reads the software policy settings

      • RegSvcs.exe (PID: 7996)
      • slui.exe (PID: 7256)
    • Manual execution by a user

      • WinRAR.exe (PID: 7748)
      • WinRAR.exe (PID: 5132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 1) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
13
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe sppextcomobj.exe no specs slui.exe ai.exe no specs winrar.exe pr1680-tekli̇f i̇steği̇-usaş türk havacilik uzay sanayi̇i̇_xlsx.exe chiffons.exe #SNAKEKEYLOGGER regsvcs.exe svchost.exe mspaint.exe no specs slui.exe no specs winrar.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1176"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.z"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2084"C:\Users\admin\AppData\Local\Temp\Rar$EXa1176.8300\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe" C:\Users\admin\AppData\Local\fornices\chiffons.exe
PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\fornices\chiffons.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2504"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "0CCB0F67-EC83-47BC-A5B4-D3D50E1D0393" "AB44AD8D-8483-41CF-A687-C5CF0B913094" "5136"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
3156"C:\Users\admin\AppData\Local\Temp\Rar$EXa1176.8300\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1176.8300\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1176.8300\pr1680-tekli̇f i̇steği̇-usaş türk havacilik uzay sanayi̇i̇_xlsx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
5064C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5132"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PR1680-TEKLİF İSTEĞİ-USAŞ TÜRK HAVACILIK UZAY SANAYİİ_xlsx.z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5136"C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\PR1680 - TEKLİF İSTEĞİ - TUSAŞ TÜRK HAVACILIK UZAY SANAYİİ.eml"C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
16.0.16026.20146
Modules
Images
c:\windows\system32\inputhost.dll
c:\windows\system32\twinapi.appcore.dll
c:\windows\system32\coremessaging.dll
c:\windows\system32\coreuicomponents.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\windows.ui.immersive.dll
c:\windows\system32\webservices.dll
c:\windows\system32\sppc.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wbem\wbemsvc.dll
5364C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
7256"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msxml6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\ondemandconnroutehelper.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\webio.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\winnsi.dll
Total events
21 214
Read events
19 908
Write events
1 163
Delete events
143

Modification events

(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData
Operation:writeName:SessionId
Value:
FAA57D89-361B-43BE-B0FF-9250DA8AD790
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootFailureCount
Value:
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\0a0d020000000000c000000000000046
Operation:writeName:00030429
Value:
09000000
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData
Operation:writeName:ProfileBeingOpened
Value:
Outlook
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\0a0d020000000000c000000000000046
Operation:writeName:00030397
Value:
60000000
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|57
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.58
Value:
31207D2C205C2253797374656D4865616C74684D6574616461746144656C617965644C6F67696E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468526F6C6C6261636B53657373696F6E4D657461646174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224964656E746974794368616E6765645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557365724368616E676564446961676E6F737469634C6576656C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468556E677261636566756C4170706C69636174696F6E4578697457696E33325C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684465736B746F7053657373696F6E4C6966656379636C65416E644865617274626561745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684F66666963654C656E734964656E746974795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468457373656E7469616C4D65746164617461416C6C4964656E7469746965735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E48616E646F66665C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D65366164617461446576696365436F6E736F6C6964617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468526F6C6C6261636B53657373696F6E4D653661646174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461647474614170706C69636174696F6E416E644C616E67756167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C7468556E677261636566756C417070457869744465736B746F705265616C54696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253387374656D4865616C74684D657461646174614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646134614F535C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D65746164747461446576696365436F6E736F6C6964747465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461647474614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461647474614F535C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614170706C6963303A34502D416464693A34502D616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D653661646174614170706C69636174696F6E4164646974696F6E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614170706C69636174696F6E416E644C616E67756167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D65746164617461446576696365436F6E736F6C6964617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614F535C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C2253797374656D4865616C7468457373656E7469616C4D65746164617461416C6C4964656E7469746965735C22203A207B205C224576656E74735C22203A207B205C22416E64726F69645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224170706C6556335C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224D62755C22203A207B205C225375624E616D657370616365735C22203A207B205C224170706C655C22203A207B205C224576656E74735C22203A207B205C224465766963654163636573736962696C69747953657474696E67735C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D2C205C2253797374656D4865616C74684D6574616461746144657669636545534D5C22203A207B205C224576656E74735C22203A207B205C22416E64726F69645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224170706C655C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22477261636566756C457869745C22203A207B205C224576656E74735C22203A207B205C22477261636566756C417070457869744465736B746F705265616C54696D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22477261636566756C417070457869744465736B746F705C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54616F73222C20225622203A20227374643A3A77737472696E677C7B205C225375624E616D657370616365735C22203A207B205C224875625C22203A207B205C225375624E616D657370616365735C22203A207B205C22446961676E6F737469635C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C224576656E74466C61675C22203A2032207D2C205C224D333635457874656E73696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225368656C6C5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224D66735C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54617267657465644D6573736167696E67222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C2241424578706572696D656E744D657373616765547269676765725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22456E737572654361636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224275736261725468656D6553656C656374696F6E5374617475735C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54656C656D65747279222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74735C22203A207B205C224C6F6164656452756C65735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2253797374656D4865616C74684D657461646174614E6574776F726B436F73745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E655370696B655468726F74746C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254656C656D65747279556C73517565756555736167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E655468726F74746C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E654D656469756D436F73745468726F74746C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2257726974655061796C6F616473546F4469736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657446696C74657265645061796C6F61647346726F6D4469736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6164586D6C52756C65735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253797374656D4865616C74684D657461646174614E6574776F726B436F73744368616E67655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E54656C656D6574727952756C6573436F756E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D697373696E674669656C6444657461696C735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C6573456E67696E65556C73517565756553697A654261636B67726F756E6450726F63657373696E674C6576656C526561636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E54656C656D6574727952756C65734368616E6765645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254656C656D6574727941637469766974794167677265676174696F6E57696E646F77537461746973746963735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253616D706C696E67506F6C6963794576656E74547269676765725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E54656C656D6574727952756C6573496E697469616C53746174655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22566F6C756D65547261636B696E67446174615C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656473746F6E65496E626F7853616D706C696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224576656E7451756172616E74696E65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656473746F6E65496E626F7853616D706C696E67437269746963616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E76616C6964446174614669656C644E616D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253616D706C696E67506F6C6963795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436C69656E7453616D706C696E674F76657272696464656E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F6365737349646C6551756575654A6F625C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466C7573684576656E744275666665725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22556C735175657565546F705468726F74746C696E67546167735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446961676E6F737469634461746156696577657253746174654368616E6765645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224661696C6564526567696F6E526F7574696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252756C654572726F7273416767726567617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526F7574696E6754656C656D657472795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2246696C654F70656E50726F66696C696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247656E65726174656452756C657346696C65496E666F5C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C224C6F6164656452756C6573436F756E745C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2254656C656D6574727953656E74696E656C56616C75655C22203A207B205C224576656E74466C61675C22203A2030207D207D2C205C225375624E616D657370616365735C22203A207B205C2253747564696F5C22203A207B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C224170704C61756E636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224661696C7572655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225072697661637949737375654C696D6974526561636865645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22507269766163794973737565446574656374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2244796E616D6963436F6E6669675C22203A207B205C224576656E74735C22203A207B205C224665746368436F6E666967735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22506F70756C6174655472656543616C6C6564416761696E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22506F70756C6174655265717565737449676E6F7265645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250617273654A736F6E436F6E6669675C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22436F6D706C69616E63655C22203A207B205C224576656E74735C22203A207B205C224576656E744E6F74496E4261736963416C6C6F774C6973745C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22417269614576656E7453696E6B5C22203A207B205C224576656E74735C22203A207B205C2248616E646C654D7361446576696365546F6B656E526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526571756573744D7361446576696365546F6B656E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C224F54656C43535C22203A207B205C224576656E74735C22203A207B205C2253696E6B53687574646F776E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253696E6B4163746976617465645C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D2C205C224576656E74466C61675C22203A20322C205C224C6F636B65645C22203A2066616C7365207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54656C6C4D65222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C22436C69636B6564526573756C745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F776E526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C2254656C6C4D65445C22203A207B205C224576656E74735C22203A207B205C2248656C70466C796F7574436C69636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C7053657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C70526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C70466C796F757444726F707065645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224578656375746564436F6D6D616E645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537562737461746553657276696365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253686F775465616368696E6743616C6C6F75745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656E6465726564526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F63756D656E74416374696F6E4576656E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250656F706C65416374696F6E4576656E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6D6D616E64436C69636B65644576656E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E6C696E6553756767657374696F6E526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248656C7053657276696365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756273746174654F666669636557656253657276696365526573706F6E736544657461696C735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756273746174654F666669636557656253657276696365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252616E6B526573756C7447726F7570735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416C77617973436F6C6C6170736564536561726368426F785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224175746F446973636F766572537562737472617465526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2241707053657373696F6E436F6E746578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225175657279496E6465784C6F6767696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E456E6453746174654C6F6767696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22566F6963655365617263684D69635C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F6E6C696E6553756767657374696F6E526573706F6E736553616D706C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224D6F64656C446F776E6C6F61645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537562737461746553657276696365526573706F6E736553616D706C65645C22203A207B205C2245
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|58
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.59
Value:
76656E74466C61675C22203A2031207D2C205C22566F69636553656172636853746172745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656E6465726564526573756C747353616D706C65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22537461727453657373696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526573756C7447726F7570547970654F726465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254696D696E674D6574726963735C22203A207B205C224576656E74466C61675C22203A2031207D207D2C205C225375624E616D657370616365735C22203A207B205C224D61635C22203A207B205C224576656E74735C22203A207B205C225463696473417070656172496E466C796F75745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E496E666F5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E736967687473436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225472795175657279436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D207D207D207D207D2C205C224465736B746F7055495C22203A207B205C224576656E74735C22203A207B205C2245786563757465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253657373696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65526573756C7473557064617465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65526573756C74735570646174656455785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526573756C74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22497373756551756572795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22496E697450726F76696465725C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254656C6C4D65506172616D65746572697A6174696F6E4475726174696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2254656C6C6D65536572766963655C22203A207B205C224576656E74735C22203A207B205C2250726F76696465724C6174656E63795C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C2254656C6C4D655741435C22203A207B205C224576656E74735C22203A207B205C225175657279526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54657374222C20225622203A20227374643A3A77737472696E677C7B205C225375624E616D657370616365735C22203A207B205C22455544425C22203A207B205C225375624E616D657370616365735C22203A207B205C2270726F6A6563745C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E54657874222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C225265736F75726365436C69656E745C22203A207B205C224576656E74735C22203A207B205C22557064617465436174616C6F675461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F63657373436174616C6F67526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225570646174655265736F757263655461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526571756573745265736F75726365496E7465726E616C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F636573735265736F75726365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F67436163686545785C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446573657269616C697A655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224765744261736555524C5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656164466F6E74456C656D656E74735C22203A207B205C224576656E74466C61675C22203A20323536207D2C205C2250757267654D756C7469706C655C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22526561645265736F757263654D657461446174615C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2257726974655265736F757263654D657461446174615C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22474449417373697374616E745C22203A207B205C224576656E74735C22203A207B205C2248616E646C6543616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225265676973746572436C6F7564466F6E7443616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416464436C6F7564466F6E745265736F757263655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656D6F766550726576696577466F6E745265736F7572636541637469766974795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247657456657273696F6E696E674469726563746F72795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2241646450726576696577466F6E745265736F7572636541637469766974795C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2248616E646C65466F6E7443616C6C6261636B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22446F776E6C6F61644261636B67726F756E645461736B466F6E74735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466F6E744D616E6167657244657374727563746F725C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22437573746F6D5265736F7572636573436C69656E745C22203A207B205C224576656E74735C22203A207B205C2250726F63657373436174616C6F67526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F675461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2250726F636573735265736F75726365526573706F6E73655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225570646174655265736F757263655461736B5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557064617465436174616C6F67436163686545785C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22445772697465417373697374616E745C22203A207B205C224576656E74735C22203A207B205C2252657175657374436C6F7564466F6E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224C6F6164436C6F7564466F6E7446616D696C795C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C22466F6E74537562737469747574696F6E5C22203A207B205C224576656E74735C22203A207B205C22436F6C6C656374466F6E74537562737469747574696F6E55736167655C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E5472616E736C61746F72222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74466C61675C22203A20322C205C224576656E74735C22203A207B205C224D657373736167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224F75746C6F6F6B416464696E54726163655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22416C7465726E6174655472616E736C6174696F6E735265747269657665645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22436F6E7465787475616C53756767657374696F6E734C6F616465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745465787453656C65637465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C617465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C61746564466565646261636B547269676765725C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C6174696F6E43616E63656C6C65645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22446F63756D656E745472616E736C6174696F6E53756767657374696F6E436C69636B65645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224578636C756465644C616E677561676541646465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224578636C756465644C616E677561676552656D6F7665645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224D6963726F666565646261636B566F746553656C65637465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224F6F786D6C5472616E736C617465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253657474696E6773436C6F7365645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C2253657474696E67734F70656E65645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536F75726365446F63756D656E744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536F75726365546172676574537761707065645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22536F75726365546578744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546172676574446F63756D656E744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546172676574546578744C616E674368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22546578745472616E736C617465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225472616E736C6174696F6E496E7365727465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225472616E736C6174696F6E4C616E6775616765734C6F616465645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225472616E736C6174696F6E5461624368616E6765645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22416C7465726E6174655472616E736C6174696F6E4578616D706C655265747269657665645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22416C7465726E6174655472616E736C6174696F6E436F706965645C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22416464496E4C6F616465645C22203A207B205C224576656E74466C61675C22203A2032207D207D207D22207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E54656C656D6574727944796E616D6963436F6E6669672E5558222C20225622203A20227374643A3A77737472696E677C7B205C224576656E74735C22203A207B205C22436F6C6F725069636B65725C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22466C75656E7452656672657368456C696769626C654275744E6F74456E61626C65645C22203A207B205C224576656E74466C61675C22203A20353132207D2C205C22436F6D696E67536F6F6E54435348574E445C22203A207B205C224576656E74466C61675C22203A2032207D2C205C22436F6D696E67536F6F6E48724D616B65526571756573745C22203A207B205C224576656E74466C61675C22203A2032207D2C205C224E6F46696C65457874656E73696F6E49636F6E4D617070696E675C22203A207B205C224576656E74466C61675C22203A2032207D207D2C205C224576656E74466C61675C22203A20322C205C225375624E616D657370616365735C22203A207B205C224E55494469616C6F675C22203A207B205C224576656E74735C22203A207B205C224469616C6F67506F736974696F6E41646A75737465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F67436C697070696E675C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F67426F6F7454696D655C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C225465616368696E6743616C6C6F75745C22203A207B205C224576656E74735C22203A207B205C22466C75656E74535646697273745465616368696E6743616C6C6F757453686F774D65427574746F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2254727953686F77466C75656E7453565465616368696E6743616C6C6F75745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466C75656E74514154437573746F6D697A6174696F6E545549416374696F6E427574746F6E436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C225465616368696E6743616C6C6F7574416C726561647953686F776E4D617854696D65735C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225465616368696E6743616C6C6F7574416C726561647953686F776E5468697353657373696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D2C205C225465616368696E6743616C6C6F7574546F6F4D616E7953686F776E5468697353657373696F6E5C22203A207B205C224576656E74466C61675C22203A2032207D207D207D2C205C22436F70696C6F745C22203A207B205C224576656E74735C22203A207B205C224469616C6F67446973706C617965645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2252656D6F766547656E657261746564436F6E74656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22557365496E73706972654D655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F67436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22526567656E657261746550726F6D70745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2247656E657261746550726F6D70745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2243616E63656C50726F6D707447656E65726174696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224B65657047656E657261746564436F6E74656E745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22466565646261636B5375626D69747465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22434951436C6F7365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F6750726576696F75735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F674E6578745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F67547279436F70696C6F745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224349514F70656E65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F67536574506167655C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F674E6F744E6F775C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224652454469616C6F67446973706C617965645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6E74656E7452656365697665645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224469616C6F674469736D6973734F6E456469745C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253656E73697469766974794C6162656C4170706C6965645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22434951536561726368537563636573735C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224572726F724F6363757265645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224368756E6B50726F6365737365645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C224361726F7573656C496E746572616374696F6E5C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22457870616E64656455495C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22436F6C6C617073656455495C22203A207B205C224576656E74466C61675C22203A2031207D2C205C22434951456E74697479496E7365727465645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756767657374656450726F6D7074436C69636B65645C22203A207B205C224576656E74466C61675C22203A2031207D2C205C2253756767657374656450726F6D7074735C22203A207B205C224576656E74466C61675C22203A2031207D207D207D2C205C225344585C22203A207B205C225375624E616D657370616365735C22203A207B205C224D65436F6E74726F6C5C22203A207B205C224576656E74735C22203A207B205C22547261636B65645363656E6172696F5C22203A207B205C224576656E74466C61675C22203A2032207D207D207D207D207D2C205C2244796E616D69634470695C22203A207B205C224576656E74735C22203A207B205C22446973706C6179546F706F6C6F67
(PID) Process:(5136) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|59
Executable files
3
Suspicious files
15
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
5136OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\olkD389.tmpbinary
MD5:5715D9BA3E40901E221C3FA97B8A26AD
SHA256:CFA54E2CDB6758152170907B8892D84D78301BFCBFC6723160B19ECB751D1966
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\81453D16.datimage
MD5:7A621044E29137E442C530F1CCAE9DB3
SHA256:82CF129A3CCA66152695CCA8BD690F771210E11B7F84EFAEF67437E940532355
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\1E00DE1F.datimage
MD5:A50F656CB5B94D2F52DFCD60B818C71C
SHA256:4FBFE0E80531030B6372FAD28F5ED8048654DA6F32EEE2EE36E52598DED6A43D
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\image8970d4.PNGimage
MD5:A601E79A1F995A0226FD2B6E23E95AB9
SHA256:1E2D6BB0845157E631E15829E253738FB13DD5A027F36740B54047C73B45268F
5136OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:A9D5B23CB31349C3AC9CB1A3812CB641
SHA256:BF158373EBB19B9FB3AB8252A97797639FBA9EB21DD394B6BE6C05AC2441A5CA
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbresbinary
MD5:BFDF5FC85EC4CD658E3D45996E0D4E5B
SHA256:C82C9C5AB71DC6361FF07C0816970A66348E96257E78A4AF2C80C3C0A676FD8A
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\image36b198.JPGimage
MD5:5F4CC89BD601F2591B25BA2BB1051F17
SHA256:9BA8CBF8486FBAA5E1D4129BBF8B9E1AD590191174689F260350FD770FE34335
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\VDP7400O\image36b198.JPG:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
5136OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:596B4E498851188AB5F38C1E5FEA126D
SHA256:F9EC556368880C658E165AA714317C335DEA40913D76887AD4C50E1462757D7D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
33
DNS requests
26
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7532
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
7996
RegSvcs.exe
GET
200
132.226.8.169:80
http://checkip.dyndns.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5136
OUTLOOK.EXE
52.123.130.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5136
OUTLOOK.EXE
23.48.23.11:443
omex.cdn.office.net
Akamai International B.V.
DE
whitelisted
5136
OUTLOOK.EXE
52.109.136.6:443
messaging.lifecycle.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.20
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
ecs.office.com
  • 52.123.130.14
  • 52.123.131.14
whitelisted
omex.cdn.office.net
  • 23.48.23.11
  • 23.48.23.43
  • 23.48.23.66
  • 23.48.23.30
  • 23.48.23.18
whitelisted
messaging.lifecycle.office.com
  • 52.109.136.6
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.130
  • 20.190.159.68
  • 20.190.159.128
  • 20.190.159.71
  • 40.126.31.71
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Device Retrieving External IP Address Detected
ET DYN_DNS External IP Lookup Domain in DNS Query (checkip .dyndns .org)
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO 404/Snake/Matiex Keylogger Style External IP Check
2196
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Address Lookup Domain (reallyfreegeoip .org)
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Misc activity
ET INFO External IP Lookup Service Domain (reallyfreegeoip .org) in TLS SNI
2196
svchost.exe
Misc activity
ET INFO External IP Address Lookup Domain in DNS Lookup (reallyfreegeoip .org)
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
7996
RegSvcs.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
No debug info