| URL: | https://powerpoint.probuildsllc.org/#YWRhbS5wYXJlbnRlQGR5c29uLmNvbQ==%20data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAArwAAAGKCAMAAADZr2JcAAAAS1BMVEVHcEyYa1//jQpbuAVhh3ZzdnFzdHOFgGl0dHNzdHL/Txf5twUApfIApfIApPJ0dHRzc3MApfL/Thf/ugBauwD+ugBZuwBZugBaugDDZwRaAAAAD3RSTlMAvU6eS2vhJMCZlZ6Pm5tbbu/fAAAf2klEQVR42uydbZOqMBJGp/YCgf1Caosi/P9fugIJ5A0SEMUZz/HOiNoGhvvYdied8PMDAAAAAAAAAAAAAAAAAAAA8OcR6VcvNBHubsX6wG9GuPcfYQIAAAAAAAAAAADwdsRfPepPMgEAAACA3x1eirTdARMCXfi9aZ3wt4KqnnD7g0wQNQAAAAAAAAAAAHwGB3vp7+n3Z8wCPk5OaBYAAAAAiLMBAAAAAADg9yRxjEsAAAAAAEEwQTAAAAAA7ER04mmbtMnuYjTrM2I/3vwkEwAAAACAg4H37zEB2BWL+F0mAAAAAAAAAAAAAL8EOvnhT0pSHN+ZSLfy4Sbw97X/KZ8evjmQ5tHrtQpkAScEt1FQLdLflOK2g96sbP8kEwAAAAAAAAAAAAAAAPhexLMGmaNQ4swzn20CAADwXTHB1a2J9HMiK+wQn2oCX6l9AAAAAAAA+PNZIvMxAQAAAAAAAL6kF4D0Ha7QVZ7SxM+zF2YVP3kFvyJx7O5+xOeawCe5y889rk/s8EXKAAAAAPAnAnIAAAAAAAAA+AzoO4BvVzezgNDJpdbXXdFJnHxVfJAJAD4YAAAAAAhtAV08o5vcXEbsm6eX7RW/9ZSK9J+KCT4KAAAAAAAAPjOt/2wTuEkY4pzJKwQpXDsR+RVb0eYdJsDHZbMDUPyGv0Bc9zn9ThPL+L+X8B/d2r9LKA/83+LWvtif/e8S/qtbG3rVTbde35yNB/rRvsk//l/gBvF2GfQpA8QLnyre7ph4/3Rg8K4li/9k6PuCsKHv+jEueNyNvx+Mznb8Pf6MLy8mOsIITPC8cI94h0mZg1IPXQ7D0A1q/BkfjKIdHve9MZluERPEC3eIdxid6TBqtBu3B32bf+kXLJMuaoJ44ZaYtze3fowPHqhpu+/m0KBbDaZb1ATxwi3iNa7VuFWP9eXVLDBBvHCPeIflZzDbU1AwdM5t0L9jJogXbknYOidw0H267oYdNERNEC/ckrAtccG4tXpg7WPdkGHLBPHCLZ53cqmDca3GofarM+7TJogXbol5Ox0PzKMRJhtT9uBwv5iouMm2ePdGXsTG7ztMEq/Cp3peNdffdHMVTj//qLUoZzUxj30TPC/cJF639qYPq3GSJogXbgoblihgSNSUqfyqsrPrmuYavN4kK3agCOeQyUsStjlomO57D/3Evkmu5/2dwWTO1CAkmspqXiFeZVK1Rwg7FueMsWyn49pxHPjxzJLNTbeYCWED3BE2qLG6QQ1zN64yQ2jdMHrYufpGS3dYehtCE8QLNyVsU72jjg3mGKE391NPg+7tVTrCiJggXrglYfPrbswgxGOrHzo7YNg2Qbxwi+fVDrUz3blLP66TmWkT1UdNEC/c5nm1cx3UWqn7yN6mfjLjbS3/G5og3i8UoihGxL3inedSDErpqhs9WWLu1h2scl8zUyg0QbzfpduiqdtWjrSyrZpS3CTe3psoMc+t7KxJlv4tYoJ4v4iiaX3Km8Q7TaDsdR6mc7FusAfW5mKc3k3XXBPE+z3SreXsc22au8Rrvv/NZAkztecRIHR6okS/mnRRE8T7LQFDIyPc6XlNNDAlX71bh9MrrygyarIv3vuHK0XZPCjy2qEgctvtVu0Y5c5IfXts3SbeWYVqu/JGzaXneyb/rhGCCB4E9bXiYNtichf7sZm/zCkC3tKuEWs7K9jI9z7xhjdvanCGyaGwoaljnJJLGWupCd1Fq8+5rAVO9jTlFO1O0pWtc7tLvOsqTl0/zGs5jVU3aq5PV70KxtciJofEW0u5qGk6DePj7Jjfa8prZfypvRNW2SYVen3C7+qTqH/uT9jUg2EaoFDTak5mIG18qDuBxwqcQZntmMlh8bqnYNo8kz4ErYx44q1ckwYVnszVKrnJrTFvF64jknx+OLvEad1GKY+fzybakCve0ntVFujwFPWaptlb06O7PO+wduaabGzwZ1L0Vn9v1OQK8dbHfUGkFek3VPkWuN6TQUO79C60Tn/D3b0N3ZKF7azXOywr6z23uHRtCc0+E4ej0TLSiv8pENI3qY5+RBCujr5WsTr3dyZs8wyfeZH+dWrw9NtMK1adlbzFTA6KV/q3KYU77BKrWCvSE29oghDPON4lS1lStboshBBFWcfFWxRv8LxqrShTJi5QenTCXWhvUFbo4Jgc9rwy8lMd/iKLtCK93oYiMJEo8Vy/jrSyaymrVZuiDMRbNFUsNX5FYY5xo8vsSneOZbeYLJ7XM7ki5j2csjVtRvAcxsUVSjzR1RCc5J1p12Wz9d/5mqoyZYrR1exOdcWYruddTEwnmW9yjXjr585nvJnq+cQQpvTC+ZYUm8pdvljf4HnXmZVTN+5YX67MIqbzunrKX2wvNDkjXhmmW+Lo+Yy2Unv+2TMpkeKJTkl7TE1u9TeOwYIxeYt49QVV5hX0ev9qKU7gYJZPD02u8bzHUrYqz/MKooZL+hoyTmIjU1Hgi6rKlCkb673Lrinrxd5MA/JNLhLvEWEVbWb0UbqnlJ6vC0LeJicJeUfYYNY4V7oLd/AH0vRq/3pCUNTk35Eu0m3xWh9Wcf4jUEfjC/3xKDYOMlgVB5FviXczamjc0Ys3iHdcAWfOxpS5JKvSm/16+dYlYYubHKxt8Evx167DA6dzs5WgkaI2Fg2SPN3LayO2AuNEwcMrCnNMvc20Bs60PS/zNC2Ks/bybpscLczZIv9LvdxuJPIJEGMZZv48QdgXb/uTI9739PMqXWs+Z2Rd5/zTC+rsm5yPeeXJlK1q22t63CC7ZyeVmzTtDQmbqb3p9y6cPZuoCy6c7Y6wNVaVUn7K5oyuNfanQCLeV4h3nTwxjq5tiXc1ad/ieZeCnGG/LGfX5JTnnaVX2pOh2rbYTaZE6L0fbyvdKVUZ4hXbGZnIyzq/TLxualElwob2XTGvtaC/lYItJTfm6X2TMzGvzq+KNhWwxrNf6zwV8kQTcFK8Mi3e98W86+javNyTmtcVmboT7Gu968qdqMn5qjK5dgXM/7IcXWOXilXC9QuI9zPE+46Y18we3gkbhsVkuDBs0GF9cyJlc9K1piBhe33CZlfz7sS8a6Fv+6aqsnnqpbW8f2eui72szqtNVNzktHgfMW9xfJTNHTQrCnm9eIl0A/GuAt7pbdifUnx5P2+vg4VpWf9u7vcd9BjE48nBLkefx9hCk1P9vHOcUOqacrnEEXktLEFvKwq5vlu2hA0v6W34yJi3u4Jnwga/ezCtPeHFGeXVYYMoyqauqkdwUlXj4EYhjr69bMrdd017MLuoju/CHOLxI3T2nPvW4/287xkeXq6AOY89OMVk/XqN1nWIImby78g3cO1pT3gDFcmT2Xjm++ItXVJdYaIc6/qCkqGm8M1c1heaKtXjPC0Qmt7FTi93UwUDPVkLjTpvlKk9r39d476jKqPU7qBT7b5a/Lx2Wf/BmuNjhiyGYGH/iMm/Lc2KpOdtghqbVMomKs8L7IvXa73Y/YgV0XqfKSKpnMIIIa3UpF0mxonGeZeI6keG0291K1m1F2UVO7xZLgnlSrlUN7vzgKvYnoPxz/Vd8VYif9FqUr+sq6y3lsOZC3V6vbEI15qCGZgcDxuWsZhmzr+Wx+mUrbSH08ZByMZ+dyDeyllcq91xb6KsHFPp/ic5iyEKufy3TFveSJR+R6CIaYFQN/uxW3k46yIp3eVNkVZ2pFu7OwpaCSf2VDs72mpl26R+reftXLc6Vd104RVXIianR9hmP1u5cySLZD+Z9XE3YcTaQh12K1tDesWuR4tNDF0HRBpHvNJMK2iNeJtlVSmdPYpAQCZPXUzsVtKVb8LNdoNW9qXr7ChoJdhzK9OHm29S//y9hK0JgthExlUcfHuVGTbslBkbGTvidU3CWDwM35vIIhPhjmI1x8vfXrWy3WslK0twPpjtdrVz1uFmm7wobDAZWbQ0p1/Kcnq9iHrE5EnxbqdsIp2upcSbF/OWbQb74i3lrnhF1ebS/Jw8yCojScjfc3sprxDvYEbY1NDpcTbrEtpDbxZ46peQIWLypHhzUjYR7Serf67xvHXCfci0eGOzmYXtNGXKS607ik8sL6WzVliu5y12drRbT1rlHm6WyasStqX6xl4Op3ef3jV5VryF+/dWqS5Hdyrw0553O2RwV+YKxLtG00tiOK+zqjdF6DR9k/h9TL2FbxppJZnfhvdeK7XrefMON8fkdb0Nhn6qvdG1Y1ZNmTYxS5v6JifFu8aR1XoC9gLTwB3YDcrw9Fu9De12b4OowvMtZSBhX7zSXiTcfKjMIsHzprC1u/Zc2CbSXWrcmNSRo/RMYq1EB8d2dxS0UnvizTrczL/oRdceXi8o3FkXFu6Wie+dvXZOYPKs581P2YrDb056XlGfiAiFdN1y/DtW7Hxzb8wl2QydUpFNPOYtkjsKWml2Y97cVt4S81pf/r0dH6zXZ1VBZBGYHF9ceulVaXQk69Qxb4+y1dZ0TdOPWi89NJuLSy8NR7rK6la6JsG80MhovXDqOGVb+h1H9kTF0Wl6U0Ujj72nvAGHYuNd7uPISHpyR8Fjs+fqyOEmTV7SVTYsF7Ey9Y7KL4hUKZOnPW/G/KetdO1Zz7ux5Jms6vEKQk1dbXaV2essV21kPMp8Bit3KeblQGuzg2C15rCfrQ5M6qksYVqn8f/cXYmS2zgOdU3xrN0tcsurZP7/SzdtSyRukrLs6cSdTidumJBsEMTxALTUmWZkEVePciYkUc2wKc2lZ0jeJLwdtPu3PA3ob9Kh94o4b8XCS463YAeLKhLxxAOKopEsJikc+gCOVRIACsR95GPVhReZf+DZCLcHJoF4gjZTEpHIDQMPEuzSxT3pLCBsqeMPkQyPW+MkO+fQH4QkiA8aYcC/ze+ARO7e2A6L/PnMB++uW3fTDpKfIsmc8EYMicRHMZl4oLhsQULmZbMMKJkLS5MWhCSXD7LZwF8LutbuZkMsYw4xF3vSgx/W93+l7wo9p4R5fxOc2fH0jcuAfkBgzo+ff/eS4UdOgsx8l0hOlAHt43uaNvO7mbQ7qrLL5iBJe3dyhcl1ZvP2OUGC5s3gWnYSJcgaVJu3dGMZvtalp+ZNmKRWkUPEtvnXwoE5CsUsgXShsHd6nfPXnyCE2wCJJbx9lY/VsP1syJsfP3rT8//B+G7vmMNJXpgGlKGW2NEcX0IUtZdyktRe+fjBsQ1g0hUR3ljQZCJiG9AzOHNgDuy5zsaYumPDFYS3TxpsASAEHvfi4Ra0GDUhk7Y6uMisc8ZfTogV13ElRR0wi39d8mhBnEsecVF4gUOa6aGzf0BedNcgSYLaUz9RA/Z8nXTSARIDVei8bTbI4enETIZRiUm7okRAMoudhVLHDdmcYyLNsxgmGqxSzb4NJwYS/1aPJMczXcUIaRVfUmlEIp2ONrCU7vxokMoH4zg7PmLq3RZRQyDZqKwyNXzmKO2rK5zl6TZI85ax5v1zxy7hhFhGz1czjxsQnB/71D1pwGzeAvG5TgqTNZLpNzzWSThNtpFmNgoha+xmhHeFMwMVZQsRNNfu6bcX3qg4bNItoslUksvmGRD4Vc0bTo+5Yjav9tpAyPLYl20+ZD+fyVCjqSM5HKvMvCaZd+PrNTbvH6J5JV0XcKA0ylLPPbqM60+Spq6ZK+JwTcvKdEwuvF6Nj8Ave3tEIrz9JgsvSxhZDQULbxjYGORC48vC+2favGK0oTleRcmP7qnO4zsRR6doHXNatOH5l5NiO2W5105s0bUyin0WmKLNU85sCzh5BJIZ+YaMM0zd+pGexnfkSZz3cGiL2ausgFX+ZJtXALvYllXWjv+M0SBmhg196qGsW5LICMW1dNrZDc2hAQuPyhOAhqVTaMbT60NfpSCEm2n1VtFiRZc1aDrSVpEnC14Y3Loo8PbXmuaFXnomYl1lObsBkBN1eFOpFPUs+oeVQCIpMmyl4QNz2OIEFmPMQh3/klen1i1zrobquMphi/+95PGffbX747H9+mqPbf/Gz1sk278u0bwPM61a49u7zZtvtxWbt0g2r39hiCG1eYNueC45WgEGm8C4Ts9H3gY/CJRVCDWY5nx8CaGyMrZ5i52kuEZ4/w2Ed9u/7lA+sdjCL4HkIuGl53jUXxb1eMJ0tIFoiqXJ3XGupTvdH0NTNSsKXRyZaInvq5zRu3FZZ/RrhXfbfsnj85s/7sePeyO7iyTrwnsACvCnnhvA4NmEjzrPz2/aQDoXZN5JeN5uzTluv+zXsjShLVac8/Vm0qmpo+H+8LWi0gSH3FzE8gF/UAvlM1zFKIpHWTS4vGOat46jDfAiP615lYesd8FjTXh17FEsCAMeeCJXcrbTSVRZGaKg7GgDjFU4/V7BPY33h9OQZa4I6HijTUmaAoLhbYPuyMC0TaDKyieEd6NmQ/vP/o+Nmw2c5CqzgfwOiEQ0zq2T1cPxlbndHc/7PAyi5fI3U32uiSA4RsBFJdxFCQQSROshIJI6y7lfrqehiG71mnHedpEfMRsEQ4E+dd+6ASGRXKV5qeLJyt73tws0b6zDTt5jzTtAyoRV5R7V40BCHjdVyLXv8rES9Zqn6/C815sNLz/Wbd5ahXJyEhuo0C8LKKgahURAU0ii5m0kjiEJap10aajNewCtSlFNSkgylzHtMAw6fdpVGFMBkGix0xghmdo26I6I8JbFzuj1A5oX2AX7n+1hP2y62SCQLGre4y0VhLf34H6QeCxoe/YmWYHjmuSkMhNeDxmtTiUGDpshvLGeE96e2M08YHWshjxBKiuRkEwcKwXfUX4tPfwRm3fjJu3WZXaThJeTrArvgQ3nGNMIUOWgY2SGeHFeDWEleUMp0BNxNOfZriW+YjYoZLNQXnbcF0ljOlahCyIEWPlGQuKnOYtmA2A0wPMW62bfZjZsE+aB9ovLbF5mODnhjQ22Yz1r8/qpgbovCa9lRxr6D2Ax8CtiwhGBiqIzMGUcCYmfMRsMmxczGqAp9GlA79a8u4vW/LS7ZDgQkvPCy/an6LI5XENoy3syfSZVeMu30ryauPtiTG4G0ntq26jX+l0dNmLWtsgZzAmzDBslWTYbRp1hSEFFQk2xjDkBdSHD5ssQ/T4TKjt6lSnhJ9jCYNpt6uh5pr5iLoQE5IADiwNW2gZn+o4890TKKFSGSt/9R8wGOT18H6eHz0cb+i1mI6/ZEj063gnFeatSSVHF0DFhtC68sB+4EW2AffenhLd3/JLnQeWCSGDLiYzdr04ys23wHXn6mdRRI0Q8RvoTcd6mXxHYBpu5XbY3mWRVeEE7tix7vajvm0cVvk5aEHhsUiyiNhJHYUDtWlbjvKgTuIV2qYO6YQHJ0xwtuS4uBxgmg3ljB/csIJnm3C7Xff9owx2pVI67kaMNlOSyDJuQMKOvCKMXnM2w5XXNO2xJnuY6l+t4Gs0Q92HQXzeszmb0VwNzPiu8IOULgY/bmOTCaANzex15wo/S+NMZNuKhrAJzWpW+4bAl2Bdipuo3kx5/hqZMJHBWQO9BPGhxyh3Nxh3hqe9lPPW9fCbaoGpeRXRFkks1LyPwA110tjN6uBASeZtSRmP8RCLzKcxrSEZrVDI6bWzRp98HjC6EyratJdl2qd2UDBsjOSm8SqWTJ23Sk+ySLEQb5JhCIu0Nz4DR7WjDs1sH6J4wNE2AdzdB7xIZH9Xv3oNVZjhHPFYNv8/rNu/n8LzMJngEcQ9NLJsNiGQ5Pdx9/Ky5OQdJxXVdTtnxVpfI2rt0VwJGr2Y3clPzVjgwz5Tx0vypkWnielJ3LjGWuze6MyJZisMrneCM7sjTPVg7I9VsQNfyjwBzNlxGIUXQKMm1ZoPWMlc7sc5WUtAeHzVebjawGk8/lsW1K/Jaa5GwVkphcv7+ZgPJqRlmAyNZd9iKlXSKBZEUkOj02o7vJHKG7SBxIo5A7NA1FSqz47zPggZQoJBmorzN75nxIUm3hCakCXhP05zf3HTkM5DIjSQphOe309iGMrBhKYnQa1zAjfVJOlJYuVRBASXa0dtdrnmZYnQrajSfuBJ3CWd/+x00L6+koGaCYPMSku1is0EfQJIn3rT5OWx+bgifbcw+v00PrIwrb5+LBux8zdkxoaIKCEcTzXWFcxE7zK432pPLRt5TScGqKw/jgFgUrOriTKhsAjGiVQ3E8YIrndEZm7QgvDPAHIZWMSEypFfr5NVoyKN0HedTwJzwT5kN766kGJ2MfmU86fkJmHl6curjPPDrZkNrNDrhsxkHfTTGaWs36MoVnBfMhnF28I0OWzMbsPErmg33V7ANFURUsgHHqjDmqReYJ0gi1FmgVZwQ3ISMsuEZ5ROalytATYYQ1Jy09Y9VH6et9p0OdJyUPni52kqTEGjCOywKfF8ZEI4uHEFcOUlBSFbNhjKEuPIxH0UVkVxR1baJ5y2sMzr57KvSBYzPpChzwuvYjcj3zJG6Du+VFHXJE9sFuFpJObu8bxDuSRxn4zEEPqh3ClcR+ql9R7PhfrnZILtseSqxuTKHTWxEw4/o+MTBGHPYhveLhpPxXgsxYRLSPCU+n9Fmzxa5H3nic6r4DohJG2UlGgSG6xcrGZaN1nHvMBtAxuxQrN1aIPHdrnsxyRmHbTAnIfARlBq4ZFBJUaxRVl6adYmGpD2GlRkTMEeaVxgoxVqFOGmeVBT8w0AnUbmAB3aizck4P8TX5iyh/YlBoMYt2PDQvlVcSu9PD7fQw6B6GJOsl74XpXoYxsUL6vCkO9+pk4iaF63ibuqv8SrZf3XT9DkZEzC7qT1II8A41F4ADDiEWjmJp9nonSTkJsDR4/mJLK2RayXx8scq4N5q4SRec8XqYMRjoox+fWZfrHwO+/jW3z/aAJHjuntf0IQpq4gwd5Kq9SprJI4du5Uxwi5cz1Ll9QwbcFFRrq2yzuqEJJkJvZBSCtIqWcxmWozYKll2xcYZNqGVJWD0JuElZUC0xekm1bDdX6lhmwo+sgBpmFuwLE3ApPXk+AxuBfqs+1YEPcfLSHhjQE3dgbjgVQBJEHBAkATtqr4K9ZHamB+VEVslGVJpjTC89THdIqO3ad6N43dxJcWAZL0MqB2R2cJtoeRwnsSUSNOAqpEk9UWaAC2M0qZmQ5lz2G6kEJPMKxZ/MiGsMil9ygmcTUZsFTHYMlfDdkPgVfrzPTbv4KF3QH1DrzIrQBonCRc1r11Orl3rfJzXUO9677FoJ/QmLvAqzgsZNiEsSD6Wd5cB3bFavStmAyZZTlKUiQ5IvvfHstG2ufXsl+BTAa0ixuk9Juk9lWCjmFc0b7McKinqpfW/Wqg5VkIiriK+RS7ojNgqaiwZMQr2ZyszenO04Y6SFHc92sBIro/z8rynn1hQrB6ewFY5xAoMIkYSfNphe4ZTAeamoiKHOp5TxSdnCaskbd/ofhReRdUkHjMKtn0kM3qz5qUOm9hyRCRZ1by90s8S3gwMfgsTNepVhn7tdNFibgz8T6k8w9b7u5eJ+86g892h3AtepValGulw2ApwhOgqVmJbZERXsbAP6HKDmU9UGL1DeFGpxMZ+4JIK1rdhe0slhZT+yrMLlhOa96bXkpeLNO9xgFe+LNJQ8sEtal68ih9zFjVvx0FHG+1bp8CVvnxO8/IkBbYeZLOBkpwQ3joB40pzM9KyWYAZJiHZMRcKga/6+JJpVBndIYKHDzee001mUi5K2gTFIWdpU/Z/JmdLJKQOtm8qM3pXtAEFFO6wiBj9GtQJEZL3aF74PqTbmzXv7dmIRtO9dHBUrCgxV2Zv3qdKMOJgn1gC5FIhFjhYJcVpzlVaBefDTXU6LuaMMqO3JSmYkcArKUh/vRcybDnl1P/4OVJTLyRrxYx/a3/MTpbfxLA68ddS+4qPH/O3H3OSe934kQT+urh66oV9c9aTnBN6E/OQXJi6FW/vLsCk+nXbVPADJFkS3m/+iF9ggx5ACsm7eDUL98Wizyf5AgDMvvL/7d1ta+owFABgGJflw+i+hP7/v3oFq2vS9NXWVH0eYYPt2Ioc42mal+tgi64VvDxz3Yu7nbm7SFtx5tVv4vdtgEPvRR45nje/lVZeMacQ8k7J270x4V+4OPYUV8985j7PX3Wa5C8HDYksdpXFubENW3ob+FgHtry3aUDt7D5seYjkpUbyPrwfxeqbFEje/W5SDHbAjHE4kCFbqywNkbxUSN7B7OG/UjebL1Goee8hkpc6yTu6K2s6MHIqRPJSueW9TsL8a1ZjeSurQojkpdIF22A3oP7SIiProqchkpeKvQ0TW1nF2MY4uZWV5KVeyxvz3oZ2sNxTzHsbNi8ujeTdfUOVNl/itB1d1j8PkbzU6m2YnWE5FyJ5qVbzPnWtMiTvYTMp0mphepVIYxuonrxtdxFWqBPyZfZKIZKXir0NE6Nv2mSG5vKZFOuHi4ZNIVsGxO5yFM5wwdZvWkduDMd8wsX2FXOQvFVa3rjDHDYk755DIrN6oI35Ig1tPv0yDZG81Cwbku2pelthZuVCLIZIXqq0vGlZmy7cXx7POwyRvNRoeUujyuL0DpgP1rxh2cX9fFjY5US6GV64bIj52IZ8+M1Yy9sLOUnLG050FJ5S847uljIyGL0Q8nN0tkhLybtg3YZ7esbpljcJUfNyhpq3HXTojm/f2urn5QxdZe6wcXzyNk3z+9tcHkVN97Ppft4f/WdcDnFbXu1nF1/KTN7mE7Yhgx+6bAu7HCj41AEAAAAAAAAA8NpC8msqZMlhHjuRMTgAAAAAAAAAAAAAAAAAAAAAAAAwL5z+9GcKAQDf+0/5zlUhAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACcTa29oexsBQAAAAAAAAAAAMBbCIsCwsKYcERIGP4zf1FnCgHgbF9lyAMAAAAAAODDWe8LzvAB8TGTY88KCa8RAqBlVz0AAKDOVQoD8IH+A2neTmsS6R8NAAAAAElFTkSuQmCC |
| Full analysis: | https://app.any.run/tasks/be28b4f5-049b-45f2-bacb-905c3ae1f9f8 |
| Verdict: | Malicious activity |
| Threats: | Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations. |
| Analysis date: | March 24, 2025, 22:12:16 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | BE4FEFA1DF84FC40A010B1653AD822A1 |
| SHA1: | 2FADCDABCC240EBA4C7DF11AA86951F5BEA3702C |
| SHA256: | B5FDC8FD58564C12AD37F4AD7C2038D7D568295535D3C16F0611C86D35C08369 |
| SSDEEP: | 192:DbtQyk6/XRS2tsMsmZKVcoMf2ujwZElif7hL3U8zOQztP4tKjY:PtU2Ez/M5jmElifFuQrY |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 864 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2148 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6444 --field-trial-handle=2328,i,10368134677555096853,1180295129127408783,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2148 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6272 --field-trial-handle=2328,i,10368134677555096853,1180295129127408783,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2560 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x300,0x304,0x308,0x2f8,0x310,0x7ffc88455fd8,0x7ffc88455fe4,0x7ffc88455ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 4380 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://powerpoint.probuildsllc.org/#YWRhbS5wYXJlbnRlQGR5c29uLmNvbQ==%20data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAArwAAAGKCAMAAADZr2JcAAAAS1BMVEVHcEyYa1//jQpbuAVhh3ZzdnFzdHOFgGl0dHNzdHL/Txf5twUApfIApfIApPJ0dHRzc3MApfL/Thf/ugBauwD+ugBZuwBZugBaugDDZwRaAAAAD3RSTlMAvU6eS2vhJMCZlZ6Pm5tbbu/fAAAf2klEQVR42uydbZOqMBJGp/YCgf1Caosi/P9fugIJ5A0SEMUZz/HOiNoGhvvYdied8PMDAAAAAAAAAAAAAAAAAAAA8OcR6VcvNBHubsX6wG9GuPcfYQIAAAAAAAAAAADwdsRfPepPMgEAAACA3x1eirTdARMCXfi9aZ3wt4KqnnD7g0wQNQAAAAAAAAAAAHwGB3vp7+n3Z8wCPk5OaBYAAAAAiLMBAAAAAADg9yRxjEsAAAAAAEEwQTAAAAAA7ER04mmbtMnuYjTrM2I/3vwkEwAAAACAg4H37zEB2BWL+F0mAAAAAAAAAAAAAL8EOvnhT0pSHN+ZSLfy4Sbw97X/KZ8evjmQ5tHrtQpkAScEt1FQLdLflOK2g96sbP8kEwAAAAAAAAAAAAAAAPhexLMGmaNQ4swzn20CAADwXTHB1a2J9HMiK+wQn2oCX6l9AAAAAAAA+PNZIvMxAQAAAAAAAL6kF4D0Ha7QVZ7SxM+zF2YVP3kFvyJx7O5+xOeawCe5y889rk/s8EXKAAAAAPAnAnIAAAAAAAAA+AzoO4BvVzezgNDJpdbXXdFJnHxVfJAJAD4YAAAAAAhtAV08o5vcXEbsm6eX7RW/9ZSK9J+KCT4KAAAAAAAAPjOt/2wTuEkY4pzJKwQpXDsR+RVb0eYdJsDHZbMDUPyGv0Bc9zn9ThPL+L+X8B/d2r9LKA/83+LWvtif/e8S/qtbG3rVTbde35yNB/rRvsk//l/gBvF2GfQpA8QLnyre7ph4/3Rg8K4li/9k6PuCsKHv+jEueNyNvx+Mznb8Pf6MLy8mOsIITPC8cI94h0mZg1IPXQ7D0A1q/BkfjKIdHve9MZluERPEC3eIdxid6TBqtBu3B32bf+kXLJMuaoJ44ZaYtze3fowPHqhpu+/m0KBbDaZb1ATxwi3iNa7VuFWP9eXVLDBBvHCPeIflZzDbU1AwdM5t0L9jJogXbknYOidw0H267oYdNERNEC/ckrAtccG4tXpg7WPdkGHLBPHCLZ53cqmDca3GofarM+7TJogXbol5Ox0PzKMRJhtT9uBwv5iouMm2ePdGXsTG7ztMEq/Cp3peNdffdHMVTj//qLUoZzUxj30TPC/cJF639qYPq3GSJogXbgoblihgSNSUqfyqsrPrmuYavN4kK3agCOeQyUsStjlomO57D/3Evkmu5/2dwWTO1CAkmspqXiFeZVK1Rwg7FueMsWyn49pxHPjxzJLNTbeYCWED3BE2qLG6QQ1zN64yQ2jdMHrYufpGS3dYehtCE8QLNyVsU72jjg3mGKE391NPg+7tVTrCiJggXrglYfPrbswgxGOrHzo7YNg2Qbxwi+fVDrUz3blLP66TmWkT1UdNEC/c5nm1cx3UWqn7yN6mfjLjbS3/G5og3i8UoihGxL3inedSDErpqhs9WWLu1h2scl8zUyg0QbzfpduiqdtWjrSyrZpS3CTe3psoMc+t7KxJlv4tYoJ4v4iiaX3Km8Q7TaDsdR6mc7FusAfW5mKc3k3XXBPE+z3SreXsc22au8Rrvv/NZAkztecRIHR6okS/mnRRE8T7LQFDIyPc6XlNNDAlX71bh9MrrygyarIv3vuHK0XZPCjy2qEgctvtVu0Y5c5IfXts3SbeWYVqu/JGzaXneyb/rhGCCB4E9bXiYNtichf7sZm/zCkC3tKuEWs7K9jI9z7xhjdvanCGyaGwoaljnJJLGWupCd1Fq8+5rAVO9jTlFO1O0pWtc7tLvOsqTl0/zGs5jVU3aq5PV70KxtciJofEW0u5qGk6DePj7Jjfa8prZfypvRNW2SYVen3C7+qTqH/uT9jUg2EaoFDTak5mIG18qDuBxwqcQZntmMlh8bqnYNo8kz4ErYx44q1ckwYVnszVKrnJrTFvF64jknx+OLvEad1GKY+fzybakCve0ntVFujwFPWaptlb06O7PO+wduaabGzwZ1L0Vn9v1OQK8dbHfUGkFek3VPkWuN6TQUO79C60Tn/D3b0N3ZKF7azXOywr6z23uHRtCc0+E4ej0TLSiv8pENI3qY5+RBCujr5WsTr3dyZs8wyfeZH+dWrw9NtMK1adlbzFTA6KV/q3KYU77BKrWCvSE29oghDPON4lS1lStboshBBFWcfFWxRv8LxqrShTJi5QenTCXWhvUFbo4Jgc9rwy8lMd/iKLtCK93oYiMJEo8Vy/jrSyaymrVZuiDMRbNFUsNX5FYY5xo8vsSneOZbeYLJ7XM7ki5j2csjVtRvAcxsUVSjzR1RCc5J1p12Wz9d/5mqoyZYrR1exOdcWYruddTEwnmW9yjXjr585nvJnq+cQQpvTC+ZYUm8pdvljf4HnXmZVTN+5YX67MIqbzunrKX2wvNDkjXhmmW+Lo+Yy2Unv+2TMpkeKJTkl7TE1u9TeOwYIxeYt49QVV5hX0ev9qKU7gYJZPD02u8bzHUrYqz/MKooZL+hoyTmIjU1Hgi6rKlCkb673Lrinrxd5MA/JNLhLvEWEVbWb0UbqnlJ6vC0LeJicJeUfYYNY4V7oLd/AH0vRq/3pCUNTk35Eu0m3xWh9Wcf4jUEfjC/3xKDYOMlgVB5FviXczamjc0Ys3iHdcAWfOxpS5JKvSm/16+dYlYYubHKxt8Evx167DA6dzs5WgkaI2Fg2SPN3LayO2AuNEwcMrCnNMvc20Bs60PS/zNC2Ks/bybpscLczZIv9LvdxuJPIJEGMZZv48QdgXb/uTI9739PMqXWs+Z2Rd5/zTC+rsm5yPeeXJlK1q22t63CC7ZyeVmzTtDQmbqb3p9y6cPZuoCy6c7Y6wNVaVUn7K5oyuNfanQCLeV4h3nTwxjq5tiXc1ad/ieZeCnGG/LGfX5JTnnaVX2pOh2rbYTaZE6L0fbyvdKVUZ4hXbGZnIyzq/TLxualElwob2XTGvtaC/lYItJTfm6X2TMzGvzq+KNhWwxrNf6zwV8kQTcFK8Mi3e98W86+javNyTmtcVmboT7Gu968qdqMn5qjK5dgXM/7IcXWOXilXC9QuI9zPE+46Y18we3gkbhsVkuDBs0GF9cyJlc9K1piBhe33CZlfz7sS8a6Fv+6aqsnnqpbW8f2eui72szqtNVNzktHgfMW9xfJTNHTQrCnm9eIl0A/GuAt7pbdifUnx5P2+vg4VpWf9u7vcd9BjE48nBLkefx9hCk1P9vHOcUOqacrnEEXktLEFvKwq5vlu2hA0v6W34yJi3u4Jnwga/ezCtPeHFGeXVYYMoyqauqkdwUlXj4EYhjr69bMrdd017MLuoju/CHOLxI3T2nPvW4/287xkeXq6AOY89OMVk/XqN1nWIImby78g3cO1pT3gDFcmT2Xjm++ItXVJdYaIc6/qCkqGm8M1c1heaKtXjPC0Qmt7FTi93UwUDPVkLjTpvlKk9r39d476jKqPU7qBT7b5a/Lx2Wf/BmuNjhiyGYGH/iMm/Lc2KpOdtghqbVMomKs8L7IvXa73Y/YgV0XqfKSKpnMIIIa3UpF0mxonGeZeI6keG0291K1m1F2UVO7xZLgnlSrlUN7vzgKvYnoPxz/Vd8VYif9FqUr+sq6y3lsOZC3V6vbEI15qCGZgcDxuWsZhmzr+Wx+mUrbSH08ZByMZ+dyDeyllcq91xb6KsHFPp/ic5iyEKufy3TFveSJR+R6CIaYFQN/uxW3k46yIp3eVNkVZ2pFu7OwpaCSf2VDs72mpl26R+reftXLc6Vd104RVXIianR9hmP1u5cySLZD+Z9XE3YcTaQh12K1tDesWuR4tNDF0HRBpHvNJMK2iNeJtlVSmdPYpAQCZPXUzsVtKVb8LNdoNW9qXr7ChoJdhzK9OHm29S//y9hK0JgthExlUcfHuVGTbslBkbGTvidU3CWDwM35vIIhPhjmI1x8vfXrWy3WslK0twPpjtdrVz1uFmm7wobDAZWbQ0p1/Kcnq9iHrE5EnxbqdsIp2upcSbF/OWbQb74i3lrnhF1ebS/Jw8yCojScjfc3sprxDvYEbY1NDpcTbrEtpDbxZ46peQIWLypHhzUjYR7Serf67xvHXCfci0eGOzmYXtNGXKS607ik8sL6WzVliu5y12drRbT1rlHm6WyasStqX6xl4Op3ef3jV5VryF+/dWqS5Hdyrw0553O2RwV+YKxLtG00tiOK+zqjdF6DR9k/h9TL2FbxppJZnfhvdeK7XrefMON8fkdb0Nhn6qvdG1Y1ZNmTYxS5v6JifFu8aR1XoC9gLTwB3YDcrw9Fu9De12b4OowvMtZSBhX7zSXiTcfKjMIsHzprC1u/Zc2CbSXWrcmNSRo/RMYq1EB8d2dxS0UnvizTrczL/oRdceXi8o3FkXFu6Wie+dvXZOYPKs581P2YrDb056XlGfiAiFdN1y/DtW7Hxzb8wl2QydUpFNPOYtkjsKWml2Y97cVt4S81pf/r0dH6zXZ1VBZBGYHF9ceulVaXQk69Qxb4+y1dZ0TdOPWi89NJuLSy8NR7rK6la6JsG80MhovXDqOGVb+h1H9kTF0Wl6U0Ujj72nvAGHYuNd7uPISHpyR8Fjs+fqyOEmTV7SVTYsF7Ey9Y7KL4hUKZOnPW/G/KetdO1Zz7ux5Jms6vEKQk1dbXaV2essV21kPMp8Bit3KeblQGuzg2C15rCfrQ5M6qksYVqn8f/cXYmS2zgOdU3xrN0tcsurZP7/SzdtSyRukrLs6cSdTidumJBsEMTxALTUmWZkEVePciYkUc2wKc2lZ0jeJLwdtPu3PA3ob9Kh94o4b8XCS463YAeLKhLxxAOKopEsJikc+gCOVRIACsR95GPVhReZf+DZCLcHJoF4gjZTEpHIDQMPEuzSxT3pLCBsqeMPkQyPW+MkO+fQH4QkiA8aYcC/ze+ARO7e2A6L/PnMB++uW3fTDpKfIsmc8EYMicRHMZl4oLhsQULmZbMMKJkLS5MWhCSXD7LZwF8LutbuZkMsYw4xF3vSgx/W93+l7wo9p4R5fxOc2fH0jcuAfkBgzo+ff/eS4UdOgsx8l0hOlAHt43uaNvO7mbQ7qrLL5iBJe3dyhcl1ZvP2OUGC5s3gWnYSJcgaVJu3dGMZvtalp+ZNmKRWkUPEtvnXwoE5CsUsgXShsHd6nfPXnyCE2wCJJbx9lY/VsP1syJsfP3rT8//B+G7vmMNJXpgGlKGW2NEcX0IUtZdyktRe+fjBsQ1g0hUR3ljQZCJiG9AzOHNgDuy5zsaYumPDFYS3TxpsASAEHvfi4Ra0GDUhk7Y6uMisc8ZfTogV13ElRR0wi39d8mhBnEsecVF4gUOa6aGzf0BedNcgSYLaUz9RA/Z8nXTSARIDVei8bTbI4enETIZRiUm7okRAMoudhVLHDdmcYyLNsxgmGqxSzb4NJwYS/1aPJMczXcUIaRVfUmlEIp2ONrCU7vxokMoH4zg7PmLq3RZRQyDZqKwyNXzmKO2rK5zl6TZI85ax5v1zxy7hhFhGz1czjxsQnB/71D1pwGzeAvG5TgqTNZLpNzzWSThNtpFmNgoha+xmhHeFMwMVZQsRNNfu6bcX3qg4bNItoslUksvmGRD4Vc0bTo+5Yjav9tpAyPLYl20+ZD+fyVCjqSM5HKvMvCaZd+PrNTbvH6J5JV0XcKA0ylLPPbqM60+Spq6ZK+JwTcvKdEwuvF6Nj8Ave3tEIrz9JgsvSxhZDQULbxjYGORC48vC+2favGK0oTleRcmP7qnO4zsRR6doHXNatOH5l5NiO2W5105s0bUyin0WmKLNU85sCzh5BJIZ+YaMM0zd+pGexnfkSZz3cGiL2ausgFX+ZJtXALvYllXWjv+M0SBmhg196qGsW5LICMW1dNrZDc2hAQuPyhOAhqVTaMbT60NfpSCEm2n1VtFiRZc1aDrSVpEnC14Y3Loo8PbXmuaFXnomYl1lObsBkBN1eFOpFPUs+oeVQCIpMmyl4QNz2OIEFmPMQh3/klen1i1zrobquMphi/+95PGffbX747H9+mqPbf/Gz1sk278u0bwPM61a49u7zZtvtxWbt0g2r39hiCG1eYNueC45WgEGm8C4Ts9H3gY/CJRVCDWY5nx8CaGyMrZ5i52kuEZ4/w2Ed9u/7lA+sdjCL4HkIuGl53jUXxb1eMJ0tIFoiqXJ3XGupTvdH0NTNSsKXRyZaInvq5zRu3FZZ/RrhXfbfsnj85s/7sePeyO7iyTrwnsACvCnnhvA4NmEjzrPz2/aQDoXZN5JeN5uzTluv+zXsjShLVac8/Vm0qmpo+H+8LWi0gSH3FzE8gF/UAvlM1zFKIpHWTS4vGOat46jDfAiP615lYesd8FjTXh17FEsCAMeeCJXcrbTSVRZGaKg7GgDjFU4/V7BPY33h9OQZa4I6HijTUmaAoLhbYPuyMC0TaDKyieEd6NmQ/vP/o+Nmw2c5CqzgfwOiEQ0zq2T1cPxlbndHc/7PAyi5fI3U32uiSA4RsBFJdxFCQQSROshIJI6y7lfrqehiG71mnHedpEfMRsEQ4E+dd+6ASGRXKV5qeLJyt73tws0b6zDTt5jzTtAyoRV5R7V40BCHjdVyLXv8rES9Zqn6/C815sNLz/Wbd5ahXJyEhuo0C8LKKgahURAU0ii5m0kjiEJap10aajNewCtSlFNSkgylzHtMAw6fdpVGFMBkGix0xghmdo26I6I8JbFzuj1A5oX2AX7n+1hP2y62SCQLGre4y0VhLf34H6QeCxoe/YmWYHjmuSkMhNeDxmtTiUGDpshvLGeE96e2M08YHWshjxBKiuRkEwcKwXfUX4tPfwRm3fjJu3WZXaThJeTrArvgQ3nGNMIUOWgY2SGeHFeDWEleUMp0BNxNOfZriW+YjYoZLNQXnbcF0ljOlahCyIEWPlGQuKnOYtmA2A0wPMW62bfZjZsE+aB9ovLbF5mODnhjQ22Yz1r8/qpgbovCa9lRxr6D2Ax8CtiwhGBiqIzMGUcCYmfMRsMmxczGqAp9GlA79a8u4vW/LS7ZDgQkvPCy/an6LI5XENoy3syfSZVeMu30ryauPtiTG4G0ntq26jX+l0dNmLWtsgZzAmzDBslWTYbRp1hSEFFQk2xjDkBdSHD5ssQ/T4TKjt6lSnhJ9jCYNpt6uh5pr5iLoQE5IADiwNW2gZn+o4890TKKFSGSt/9R8wGOT18H6eHz0cb+i1mI6/ZEj063gnFeatSSVHF0DFhtC68sB+4EW2AffenhLd3/JLnQeWCSGDLiYzdr04ys23wHXn6mdRRI0Q8RvoTcd6mXxHYBpu5XbY3mWRVeEE7tix7vajvm0cVvk5aEHhsUiyiNhJHYUDtWlbjvKgTuIV2qYO6YQHJ0xwtuS4uBxgmg3ljB/csIJnm3C7Xff9owx2pVI67kaMNlOSyDJuQMKOvCKMXnM2w5XXNO2xJnuY6l+t4Gs0Q92HQXzeszmb0VwNzPiu8IOULgY/bmOTCaANzex15wo/S+NMZNuKhrAJzWpW+4bAl2Bdipuo3kx5/hqZMJHBWQO9BPGhxyh3Nxh3hqe9lPPW9fCbaoGpeRXRFkks1LyPwA110tjN6uBASeZtSRmP8RCLzKcxrSEZrVDI6bWzRp98HjC6EyratJdl2qd2UDBsjOSm8SqWTJ23Sk+ySLEQb5JhCIu0Nz4DR7WjDs1sH6J4wNE2AdzdB7xIZH9Xv3oNVZjhHPFYNv8/rNu/n8LzMJngEcQ9NLJsNiGQ5Pdx9/Ky5OQdJxXVdTtnxVpfI2rt0VwJGr2Y3clPzVjgwz5Tx0vypkWnielJ3LjGWuze6MyJZisMrneCM7sjTPVg7I9VsQNfyjwBzNlxGIUXQKMm1ZoPWMlc7sc5WUtAeHzVebjawGk8/lsW1K/Jaa5GwVkphcv7+ZgPJqRlmAyNZd9iKlXSKBZEUkOj02o7vJHKG7SBxIo5A7NA1FSqz47zPggZQoJBmorzN75nxIUm3hCakCXhP05zf3HTkM5DIjSQphOe309iGMrBhKYnQa1zAjfVJOlJYuVRBASXa0dtdrnmZYnQrajSfuBJ3CWd/+x00L6+koGaCYPMSku1is0EfQJIn3rT5OWx+bgifbcw+v00PrIwrb5+LBux8zdkxoaIKCEcTzXWFcxE7zK432pPLRt5TScGqKw/jgFgUrOriTKhsAjGiVQ3E8YIrndEZm7QgvDPAHIZWMSEypFfr5NVoyKN0HedTwJzwT5kN766kGJ2MfmU86fkJmHl6curjPPDrZkNrNDrhsxkHfTTGaWs36MoVnBfMhnF28I0OWzMbsPErmg33V7ANFURUsgHHqjDmqReYJ0gi1FmgVZwQ3ISMsuEZ5ROalytATYYQ1Jy09Y9VH6et9p0OdJyUPni52kqTEGjCOywKfF8ZEI4uHEFcOUlBSFbNhjKEuPIxH0UVkVxR1baJ5y2sMzr57KvSBYzPpChzwuvYjcj3zJG6Du+VFHXJE9sFuFpJObu8bxDuSRxn4zEEPqh3ClcR+ql9R7PhfrnZILtseSqxuTKHTWxEw4/o+MTBGHPYhveLhpPxXgsxYRLSPCU+n9Fmzxa5H3nic6r4DohJG2UlGgSG6xcrGZaN1nHvMBtAxuxQrN1aIPHdrnsxyRmHbTAnIfARlBq4ZFBJUaxRVl6adYmGpD2GlRkTMEeaVxgoxVqFOGmeVBT8w0AnUbmAB3aizck4P8TX5iyh/YlBoMYt2PDQvlVcSu9PD7fQw6B6GJOsl74XpXoYxsUL6vCkO9+pk4iaF63ibuqv8SrZf3XT9DkZEzC7qT1II8A41F4ADDiEWjmJp9nonSTkJsDR4/mJLK2RayXx8scq4N5q4SRec8XqYMRjoox+fWZfrHwO+/jW3z/aAJHjuntf0IQpq4gwd5Kq9SprJI4du5Uxwi5cz1Ll9QwbcFFRrq2yzuqEJJkJvZBSCtIqWcxmWozYKll2xcYZNqGVJWD0JuElZUC0xekm1bDdX6lhmwo+sgBpmFuwLE3ApPXk+AxuBfqs+1YEPcfLSHhjQE3dgbjgVQBJEHBAkATtqr4K9ZHamB+VEVslGVJpjTC89THdIqO3ad6N43dxJcWAZL0MqB2R2cJtoeRwnsSUSNOAqpEk9UWaAC2M0qZmQ5lz2G6kEJPMKxZ/MiGsMil9ygmcTUZsFTHYMlfDdkPgVfrzPTbv4KF3QH1DrzIrQBonCRc1r11Orl3rfJzXUO9677FoJ/QmLvAqzgsZNiEsSD6Wd5cB3bFavStmAyZZTlKUiQ5IvvfHstG2ufXsl+BTAa0ixuk9Juk9lWCjmFc0b7McKinqpfW/Wqg5VkIiriK+RS7ojNgqaiwZMQr2ZyszenO04Y6SFHc92sBIro/z8rynn1hQrB6ewFY5xAoMIkYSfNphe4ZTAeamoiKHOp5TxSdnCaskbd/ofhReRdUkHjMKtn0kM3qz5qUOm9hyRCRZ1by90s8S3gwMfgsTNepVhn7tdNFibgz8T6k8w9b7u5eJ+86g892h3AtepValGulw2ApwhOgqVmJbZERXsbAP6HKDmU9UGL1DeFGpxMZ+4JIK1rdhe0slhZT+yrMLlhOa96bXkpeLNO9xgFe+LNJQ8sEtal68ih9zFjVvx0FHG+1bp8CVvnxO8/IkBbYeZLOBkpwQ3joB40pzM9KyWYAZJiHZMRcKga/6+JJpVBndIYKHDzee001mUi5K2gTFIWdpU/Z/JmdLJKQOtm8qM3pXtAEFFO6wiBj9GtQJEZL3aF74PqTbmzXv7dmIRtO9dHBUrCgxV2Zv3qdKMOJgn1gC5FIhFjhYJcVpzlVaBefDTXU6LuaMMqO3JSmYkcArKUh/vRcybDnl1P/4OVJTLyRrxYx/a3/MTpbfxLA68ddS+4qPH/O3H3OSe934kQT+urh66oV9c9aTnBN6E/OQXJi6FW/vLsCk+nXbVPADJFkS3m/+iF9ggx5ACsm7eDUL98Wizyf5AgDMvvL/7d1ta+owFABgGJflw+i+hP7/v3oFq2vS9NXWVH0eYYPt2Ioc42mal+tgi64VvDxz3Yu7nbm7SFtx5tVv4vdtgEPvRR45nje/lVZeMacQ8k7J270x4V+4OPYUV8985j7PX3Wa5C8HDYksdpXFubENW3ob+FgHtry3aUDt7D5seYjkpUbyPrwfxeqbFEje/W5SDHbAjHE4kCFbqywNkbxUSN7B7OG/UjebL1Goee8hkpc6yTu6K2s6MHIqRPJSueW9TsL8a1ZjeSurQojkpdIF22A3oP7SIiProqchkpeKvQ0TW1nF2MY4uZWV5KVeyxvz3oZ2sNxTzHsbNi8ujeTdfUOVNl/itB1d1j8PkbzU6m2YnWE5FyJ5qVbzPnWtMiTvYTMp0mphepVIYxuonrxtdxFWqBPyZfZKIZKXir0NE6Nv2mSG5vKZFOuHi4ZNIVsGxO5yFM5wwdZvWkduDMd8wsX2FXOQvFVa3rjDHDYk755DIrN6oI35Ig1tPv0yDZG81Cwbku2pelthZuVCLIZIXqq0vGlZmy7cXx7POwyRvNRoeUujyuL0DpgP1rxh2cX9fFjY5US6GV64bIj52IZ8+M1Yy9sLOUnLG050FJ5S847uljIyGL0Q8nN0tkhLybtg3YZ7esbpljcJUfNyhpq3HXTojm/f2urn5QxdZe6wcXzyNk3z+9tcHkVN97Ppft4f/WdcDnFbXu1nF1/KTN7mE7Yhgx+6bAu7HCj41AEAAAAAAAAA8NpC8msqZMlhHjuRMTgAAAAAAAAAAAAAAAAAAAAAAAAwL5z+9GcKAQDf+0/5zlUhAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACcTa29oexsBQAAAAAAAAAAAMBbCIsCwsKYcERIGP4zf1FnCgHgbF9lyAMAAAAAAODDWe8LzvAB8TGTY88KCa8RAqBlVz0AAKDOVQoD8IH+A2neTmsS6R8NAAAAAElFTkSuQmCC" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 4980 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4460 --field-trial-handle=2328,i,10368134677555096853,1180295129127408783,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 5024 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6280 --field-trial-handle=2328,i,10368134677555096853,1180295129127408783,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 5344 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=6600 --field-trial-handle=2328,i,10368134677555096853,1180295129127408783,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 5380 | "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1 | C:\Windows\System32\BackgroundTransferHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Download/Upload Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6872 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=3784 --field-trial-handle=2328,i,10368134677555096853,1180295129127408783,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: B1C57C2EB48F2F00 | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: C1D2852EB48F2F00 | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197228 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {A8D8DDAE-CBD1-49E2-94A9-BB57F4C124A8} | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197228 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {560D7993-C884-4098-9278-2543384909ED} | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197228 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {2EC4966B-3022-4613-A953-9D8ACDC3EEF0} | |||
| (PID) Process: | (4380) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\197228 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {A0B687C3-0488-450D-AA32-4B42795204AA} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10b652.TMP | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10b652.TMP | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10b652.TMP | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10b661.TMP | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10b6a0.TMP | — | |
MD5:— | SHA256:— | |||
| 4380 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.159:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
856 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
8168 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
8904 | BackgroundTransferHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
856 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.48.23.159:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7304 | msedge.exe | 172.67.189.116:443 | powerpoint.probuildsllc.org | — | — | unknown |
4380 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
7304 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7304 | msedge.exe | 150.171.27.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
powerpoint.probuildsllc.org |
| unknown |
edge-mobile-static.azureedge.net |
| whitelisted |
business.bing.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7304 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
7304 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge |
7304 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspicious redirect to Wikipedia (hrefwiki) |
7304 | msedge.exe | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Suspicious redirect to Wikipedia (hrefwiki) |