File name:

phish_email.eml

Full analysis: https://app.any.run/tasks/a21570d4-4269-4267-b380-6575597c4536
Verdict: Malicious activity
Analysis date: May 27, 2025, 10:12:14
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
rust
Indicators:
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with very long lines (335)
MD5:

C1EF707E68CC27FD299CCF8455C2FDB6

SHA1:

6CC18D8E6EEEFDB30ECA80B37FCC166D9956949F

SHA256:

DD3CE4DFB69563DBE838846645BB3A35F40C8B8F075FC64DAFBC2B36D1A3BD7C

SSDEEP:

768:YouXn51RcyZZO2W7LdEAH8gEV23gmhoepqie21DMc:nuDRcyZZOxxEA8gE03gmhoelHZd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 4348)
    • Application launched itself

      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 4348)
      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 2152)
    • Executes application which crashes

      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 800)
    • Connects to unusual port

      • svchost.exe (PID: 5360)
  • INFO

    • Reads the computer name

      • identity_helper.exe (PID: 8128)
    • Application launched itself

      • msedge.exe (PID: 7420)
      • Acrobat.exe (PID: 680)
      • AcroCEF.exe (PID: 7676)
      • msedge.exe (PID: 8528)
      • chrome.exe (PID: 5360)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7868)
      • msedge.exe (PID: 1284)
    • Manual execution by a user

      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 4348)
      • WinRAR.exe (PID: 7868)
      • svchost.exe (PID: 5360)
      • svchost.exe (PID: 800)
      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 2152)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 1284)
      • WinRAR.exe (PID: 7868)
    • Checks supported languages

      • identity_helper.exe (PID: 8128)
    • Reads the software policy settings

      • slui.exe (PID: 7696)
      • slui.exe (PID: 2852)
    • Launch of the file from Downloads directory

      • msedge.exe (PID: 8180)
    • Application based on Rust

      • หลักฐานการละเมิดสิทธิ์.pdf .exe (PID: 4348)
    • Reads Environment values

      • identity_helper.exe (PID: 8128)
    • Checks proxy server information

      • slui.exe (PID: 2852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
249
Monitored processes
105
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe sppextcomobj.exe no specs slui.exe ai.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe no specs winrar.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs openwith.exe no specs msedge.exe no specs หลักฐานการละเมิดสิทธิ์.pdf                                               .exe no specs msedge.exe no specs openwith.exe no specs acrobat.exe acrobat.exe no specs msedge.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs หลักฐานการละเมิดสิทธิ์.pdf                                               .exe svchost.exe werfault.exe no specs หลักฐานการละเมิดสิทธิ์.pdf                                               .exe msedge.exe no specs svchost.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs หลักฐานการละเมิดสิทธิ์.pdf                                               .exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=5836 --field-trial-handle=2856,i,11426580134095394210,8669734103201517153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
680"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\admin\Downloads\หลักฐานการละเมิดสิทธิ์\1"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
OpenWith.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
704"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=7156 --field-trial-handle=2856,i,11426580134095394210,8669734103201517153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
800"C:\Users\admin\Downloads\หลักฐานการละเมิดสิทธิ์\หลักฐานการละเมิดสิทธิ์.pdf .exe"C:\Users\admin\Downloads\หลักฐานการละเมิดสิทธิ์\หลักฐานการละเมิดสิทธิ์.pdf .exe
หลักฐานการละเมิดสิทธิ์.pdf .exe
User:
admin
Company:
Haihaisoft Limited
Integrity Level:
MEDIUM
Description:
Haihaisoft PDF Reader
Exit code:
3221225477
Version:
1.5.7.0
Modules
Images
c:\users\admin\downloads\หลักฐานการละเมิดสิทธิ์\หลักฐานการละเมิดสิทธิ์.pdf .exe
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
c:\windows\syswow64\gdi32.dll
800"C:\Windows\System32\svchost.exe"C:\Windows\System32\svchost.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
980"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3180 --field-trial-handle=2404,i,17203992084298909686,7916111357573775004,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4332 --field-trial-handle=2856,i,11426580134095394210,8669734103201517153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1120"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --mojo-platform-channel-handle=6180 --field-trial-handle=2856,i,11426580134095394210,8669734103201517153,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1184"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2936 --field-trial-handle=2856,i,11426580134095394210,8669734103201517153,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1284"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5456 --field-trial-handle=2856,i,11426580134095394210,8669734103201517153,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
38 225
Read events
37 597
Write events
547
Delete events
81

Modification events

(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Licensing
Operation:delete valueName:EligibleForExtendedGrace
Value:
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\outlook
Operation:writeName:BuildNumber
Value:
16.0.16026
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:writeName:Expires
Value:
int64_t|0
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:delete valueName:ConfigIds
Value:
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook
Operation:delete valueName:ETag
Value:
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1
Value:
4D736F3A3A436865636B73756D52656769737472793A3A446174617C75696E7436345F747C333737353933303235313133383638343636303B456373436F6E666967526573706F6E7365446174617C7B202256657222203A2022696E7433325F747C30222C2022436F6E6649647322203A20227374643A3A77737472696E677C502D522D313039383135382D312D352C502D522D37363735372D312D322C502D522D32363134362D352D31372C502D442D32393633352D312D312C502D442D32373038372D312D392C502D522D37393638382D312D332C502D582D313035363139362D322D332C502D522D313037353533392D342D362C502D522D313036353130332D342D352C502D522D313034303537342D342D382C502D522D313032313439312D342D342C502D522D313032303733302D322D31302C502D522D313031393539312D342D342C502D522D313030343536312D342D342C64686965643636303A3434383338312C502D582D39383531382D362D392C502D582D313036313437302D322D332C502D582D313032313936352D312D372C502D582D313032313936382D322D332C502D582D37333633392D312D352C502D522D313037383237352D342D372C502D522D313037363531382D342D362C502D522D313036393531352D342D362C502D522D313032353434342D342D352C502D522D33333737342D36342D3235302C626C6F636B6564677261706869637361646170746572353A3437353839392C66653635313636373A3336313635382C37326838623835393A3238343430302C38306562633336353A3236353636392C61696764693533333A3338303138352C502D522D35383634302D312D332C502D582D37343731382D312D392C502D522D313037343034382D362D372C502D522D33353039392D322D342C6175656E613732343A3537373735332C502D522D313038313433312D382D362C502D522D313035333437382D382D352C502D522D33343834332D342D362C502D582D37313237342D312D372C502D522D33333832322D31342D36362C502D522D34353438332D31362D35332C502D522D35303731372D31382D36302C502D522D38373538372D342D342C502D522D37353036392D312D332C502D522D37353030312D312D332C502D522D36383135322D31382D32312C502D522D35323331362D31382D33372C502D522D34393136322D31382D31332C502D522D34393136312D31382D31332C502D522D34303235332D362D31392C502D522D34303235342D362D31382C502D522D33353430312D362D372C502D522D33323130372D32322D32322C636C70726F3130353A3436363736322C502D582D3130393138392D312D352C502D582D313030333535362D312D352C502D522D35383236362D34382D33392C502D522D32343938302D382D34382C502D522D31383237392D322D36352C63753637333A3332353936392C63756973663436343A3434363635342C502D582D313033363930382D312D332C502D522D3131333931352D382D372C502D522D35323938322D31382D33342C502D522D35313134352D322D372C67356234623530373A3238363035352C502D582D313031323533332D312D352C502D522D313036393430352D342D382C502D522D313035303139342D33322D32312C502D522D34313034362D32322D38312C64696173793933323A3237333238302C502D582D313037373139382D322D352C502D582D313034383430382D322D352C502D582D38353335392D312D31332C502D582D38393031322D312D31312C502D522D313036313635312D382D362C502D522D313034323432302D342D332C502D522D313033363136342D342D372C502D522D3131333530382D382D362C502D522D39353631362D382D352C502D522D37393631362D312D332C502D522D37373632312D312D332C502D522D37373230342D312D332C502D522D37363130372D312D332C502D522D37343333342D312D332C502D522D37343433392D312D332C502D522D37333634322D312D332C502D522D36383933382D312D362C502D522D36323837352D322D342C502D522D36303537392D322D322C502D522D36303333332D312D332C502D522D35383130372D322D322C502D522D35353734332D312D332C502D522D35313935382D312D352C502D522D33383038352D31322D392C502D522D33353338392D31382D33382C75736570726570726F63743A3337333738382C7573657632656E64706F696E7474726561746D656E743A3333333939332C6E617469766577696E333272646C3A3138363734342C646F6373686F6D6570616765736561726368656E61626C65616767726567617465646D7275736561726368736F757263653A3137353733392C502D522D313033343136392D31302D372C502D582D313037383537362D322D332C502D582D313035393131312D312D332C502D582D38303734322D312D31312C502D582D39333738372D332D31312C502D582D313035363137372D322D332C502D582D37393936312D312D372C502D582D313033333335362D322D332C502D582D39393034342D312D332C502D582D39363134312D312D332C502D452D32383637372D322D332C502D522D35353132322D382D382C502D522D35303235352D31302D392C502D522D34353331342D31302D31362C37393332313738393A3335353439302C336A6768393438383A3337353232372C6578706F773334343A3337353535352C65787069766F746E6F6E64657374727563746976656175746F67726F75703A3338373137392C69393268333737303A3333363131342C657861766F3833333A3234393839332C736D617274726563616C632D74726561746D656E743A3433313131322C6D6F6465726E62726F777365726F617574686469616C6F673A3230383934332C65786973723434383A3230383933342C502D582D313234303832332D312D332C502D452D33383233312D43312D342C502D522D313234353636322D31352D342C502D522D3130383334322D31342D31372C502D522D39353232352D31342D31372C502D522D39343636312D31342D31332C502D522D39343536302D31342D31322C502D522D39343138392D31342D31332C502D522D39333838322D31342D32362C502D522D36313134372D4331372D322C502D522D35343732382D31362D32332C502D522D35343639382D31362D31362C502D522D35343635382D31382D31392C502D522D34303034392D322D32392C502D522D33383330362D4331372D332C502D522D33343031392D342D332C77696E333264657669636563616E6172793A3534313438332C77696E333264657669636563616E6172793A3534313438332C502D582D313035313539312D312D352C502D582D313030373237342D332D31372C502D582D313030373237352D31332D34352C502D582D38353839362D312D31392C502D582D39313739302D312D352C502D582D313031343433312D312D372C502D582D3131363131352D312D392C502D582D3130373539352D312D352C502D582D36313130322D332D31312C502D582D35313236322D312D31312C502D582D35323539312D312D31312C502D582D39383636352D312D392C502D582D39383635352D312D352C502D582D38343436342D312D352C502D582D35343335382D312D372C502D582D35333937352D332D392C502D582D36393138392D312D372C502D582D35363237342D312D392C502D582D36333133342D312D372C502D582D35383637382D312D352C502D582D35353833322D312D362C502D582D35363134372D312D352C502D582D35363135342D312D352C502D582D35343231322D312D352C502D522D313535343133302D342D352C502D522D313535343132372D342D352C502D522D313535343132322D342D362C502D522D313037343833392D382D352C502D522D313037343430372D382D352C502D522D313037343033302D382D342C502D522D313037323332362D382D362C502D522D313036323835322D382D392C502D522D313035333236392D382D352C502D522D39353038322D382D352C502D522D39333937302D382D342C502D522D36393036352D312D332C502D522D35393139332D312D332C502D522D34353630392D31342D362C502D522D34353139372D322D362C502D522D34303938302D31382D31362C502D522D33393032392D352D31382C502D522D33353136352D322D372C502D522D32393830392D312D372C502D522D32363936382D332D392C502D522D31383432352D382D36322C502D522D31383432362D352D33302C502D522D31383432342D342D33342C502D442D313130393930372D342D31322C686E6C6162656C3A3630333036372C686E656469746F72733A3531383233342C356D696E31306D696E5F31306D696E6772616365706572696F643A3531373738392C66696C69733436363A3733363730322C66696D6F633234383A3139333439312C62657474657262726561646372756D62733A3439303833362C6669616C6C3139383A3439383838372C66696261633936373A3630383537312C66697465733231373A3136313436382C66697265663334363A33343532352C66696D6F633538393A32383937392C6772617068617069666F726F64656E61626C6564726F6C6C6F75743A3339343135362C6F6E656472697665636F6E76657267656E6365656E6C69676874656E6564726F6C6C6F75743A3135393033382C66696F6D693239333A3131383038312C6669656E613934373A33303633352C66697374613430373A36313032372C6669656E613930333A36353934342C66696461763236353A35353033352C66696361633834313A34393636342C6669656E613431353A33383738302C6669656E613439303A33343138312C72656D6F74656D6F76656465766963653A34323530302C6669656E613237363A34313030342C6669656E613338313A34393939372C502D582D313032303335332D312D372C502D522D313233363533302D382D322C502D522D313037383537312D31382D382C502D522D313034363334302D31382D31352C502D522D313033343131382D31382D32302C502D522D313032363335342D31382D32312C502D522D36313730372D33362D32382C502D522D35333534352D342D352C502D522D34393733362D362D32322C502D522D33303038352D312D392C502D522D32353135372D382D31342C502D522D32343336332D362D31332C502D522D31393831342D312D36322C502D522D31393031322D312D35372C666C656E613231343A3532363832342C666C656E613231343A3532363832342C502D582D313032343434382D312D332C30356269353338323A3430333333312C502D582D313035363435362D322D31312C502D582D313031383536342D332D392C502D582D313032303539372D312D372C502D582D313030393332392D312D372C502D582D313031313434322D312D31312C502D582D313031393633322D312D332C502D582D313031353535342D312D352C502D582D313031303331342D312D352C502D582D3130383336342D312D332C502D582D37373734322D312D352C502D582D38363339352D312D352C502D582D38343332312D312D352C502D582D35303232302D312D332C502D582D34393733302D312D332C502D522D313034333838352D362D362C502D522D313031343435322D382D382C502D522D36343834312D32322D31352C502D522D36333130302D32382D31302C502D522D35323033382D32382D31382C502D522D34303939302D31322D31352C502D522D33323734342D31342D31352C502D522D33323734312D33322D31362C502D522D32383735312D322D32302C69693435373531323A3434393137382C6272616B696E67736B703A3338383633312C6772616C743139333A3431313231352C6772616C743232323A3334353534372C67726766783930363A3432333930352C67723233343A3433343331362C6772736B693435353A3537383535332C67723331323A3631333334312C67723337303A3538333038372C677264656C3334373A3132373632382C67727376673936303A3435323639302C67727573653434343A3132343039312C67727573653438383A3537303335382C677269636F3430363A31393737372C502D582D3130353838392D312D352C32346139333336353A3134373734372C502D522D35303432392D31382D382C502D522D33363533392D31302D352C502D522D32343038342D312D31362C502D582D313535393535332D312D332C502D582D313034393232352D312D332C502D582D313033333336302D312D352C502D582D313033333335352D312D332C502D582D313031313137332D312D352C502D522D313537363838342D31332D31342C502D522D313434353932342D382D362C502D522D313130313038312D382D352C502D522D313037373631302D382D352C502D522D313032363534322D382D342C502D522D313032313732352D31382D35302C502D522D35333432312D32382D31342C502D522D34303437352D32382D32382C502D522D33353938352D31342D32332C502D522D33323030342D322D352C37613961633834303A3736333637322C39373935633332303A3335393832302C32646262623537393A3238363232352C69383364613438393A3338383033382C69643539323A3238383731342C502D582D38383033352D312D352C6C616C616E3233313A3134303738312C502D582D313237363530392D312D352C502D582D313033393636392D312D392C502D582D313035363637392D312D362C502D582D313031323534332D342D32352C502D582D3130333738362D312D332C502D522D313238303432352D31332D31372C502D522D36313234382D31382D372C502D522D35313939352D31382D32382C502D522D33323433382D31352D35352C69306437363937303A3539383638392C31343530373439353A3430363034302C6C6F6F705F6761726F6C6C6F75743A3431303034392C65663635393538383A3430343732312C6C656973753732343A3631303738342C502D582D313034343531342D322D372C502D582D313036313732332D322D352C502D582D313037363235322D312D362C502D582D313034393634392D322D352C502D582D313034373731352D322D372C502D582D313031343139352D342D31392C502D582D313032363133312D322D352C502D582D313032373931332D312D31312C502D582D313031373734352D382D31342C502D582D3130383634332D322D372C502D582D39353630352D322D332C502D522D313035383637352D382D342C502D522D313033363537362D342D342C502D522D39383131302D342D352C502D522D37393936332D312D322C502D522D36303831362D31302D31392C502D522D35313736342D312D342C502D522D34323339322D322D342C502D522D33393037332D312D352C70697063687962726964743A3333363236352C326766396A3631383A3336323439302C396A6734633839333A3335373434342C34676839653230353A3438333737382C363135316A3631333A3434373631392C67643868383735353A3331373939302C6A6A3035303832373A3234353136322C61306537323236393A3332323039342C37673633363833323A3236383639382C37366534673937353A3332343937392C67306864303232313A3435303335352C502D522D313132333337362D31302D31342C502D522D313030393835352D31322D31342C502D522D39383835362D31382D34382C502D522D313036313233392D382D362C502D522D34333438392D33302D31352C502D522D33383431302D31322D32332C502D582D313239313234362D322D332C502D582D313236343332372D312D392C502D582D313032313731342D322D352C502D582D313032373135362D312D372C502D582D313031323836352D312D352C502D582D313036313138302D322D372C502D582D313037313733392D312D332C502D582D313036363534362D312D31332C502D582D38393837382D312D352C502D582D313035303032352D312D31312C502D582D313035303636352D332D372C502D582D313034313735362D322D352C502D582D313032313432332D322D352C502D582D313031393538312D312D332C502D582D313030363137342D312D352C502D582D3131383230392D312D332C502D582D35313735392D312D332C502D522D313536353432382D322D332C502D522D313533343538302D382D322C502D522D313532363931352D382D332C502D522D313234393337302D342D352C502D522D313039343131352D342D342C502D522D313038393139322D362D352C502D522D313031373036362D342D352C502D522D3131373934312D342D342C502D522D35393533342D312D332C502D522D35343535372D312D332C63683337313137393A3630303339362C33326535613931333A3538333337322C64633031373739383A3533373631302C31323568373933353A3335313834372C6361726574706F736974696F6E6368616E6765643A3339343139362C38376A61613633343A3336383734362C3866316A663234323A3638313635382C62656C6F776F70656E646976696465723A3534323535372C6F6575696C3832303A3332363132342C726573706563746C6F6F707374796C653A3639313535392C6F65656E61626C656F73666964656E746974796D616E616765723A3434393931392C67623038643735323A3239323132322C65333931323438393A3338393436372C6F656D69633633393A3339373735332C6F65616C6C3834333A3337353838372C6F65666C753433343A3332313933392C6F656D61633335383A32303530322C726573706563746C6F6F707374796C653A3639313535392C502D522D37313336302D31382D31392C502D582D37363535352D312D332C6F6E6D61703336363A38313734302C502D442D313437363534302D312D332C502D442D313234383335302D332D332C502D442D313232303436342D392D352C502D442D313033303630312D332D332C502D442D313135373731372D312D332C502D442D313134393433362D312D332C502D442D313133313332392D362D372C502D442D313131303935362D342D332C502D442D313038343536352D332D332C502D442D313037333031342D352D332C502D442D313035393333322D322D342C502D442D313034323830332D322D342C502D442D313033373534312D372D362C502D442D313033333339312D322D342C502D442D313033313531322D312D332C502D442D313033313531302D312D332C502D442D313033313530392D312D332C502D442D313033313530382D312D332C502D442D313033313436302D312D332C502D442D313033313435362D322D342C502D442D313033313435352D312D332C502D442D313033313435342D312D332C502D442D313033313435332D312D332C502D442D313033313435322D312D332C502D442D313033313435312D312D332C502D442D313033313435302D312D332C502D442D313033313434392D312D332C502D442D313033313434382D312D332C502D442D313033313434372D312D332C502D442D313033313434362D312D332C502D442D313033313337332D312D332C502D442D313033313035302D342D332C502D442D313033313032322D312D332C502D442D313033313031382D312D332C502D442D313033313031322D312D332C502D442D313033303936342D312D332C502D442D313033303936332D312D332C502D442D313033303932362D312D332C502D442D313033303932332D322D332C502D442D313033303932322D322D332C502D442D31303330393230
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|1
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.2
Value:
6F636B646F776E3A3439363034382C73656175743232323A3130353133372C7573656C65737370726976696C65676564617070636F6E7461696E65723A3738303238352C502D582D37383534352D312D352C502D582D313033363639312D322D31332C502D582D3131363238362D312D332C502D582D3131363038352D312D332C502D582D3131363037382D312D352C502D582D3131363036352D312D332C502D582D37343233342D312D31312C502D582D37333731382D312D332C502D452D32393636322D322D332C502D522D36313335382D4331372D32322C502D522D313034393532362D322D382C502D522D313034393533352D322D382C502D522D32393330332D322D32302C502D522D32393033312D322D32302C502D522D33363331362D362D32302C502D522D33303239302D362D32332C502D522D32383938322D332D31382C502D522D36333934372D31382D322C502D522D36333335372D31382D31392C502D522D36313336312D31382D32362C502D522D36313336302D31382D32312C502D522D35393530312D4331372D352C502D522D34383633342D322D31352C502D522D34373234322D31382D31312C502D522D34353537392D31382D382C502D522D34323531322D312D332C502D522D34303532312D322D31332C502D522D33383730342D342D362C502D522D33383231322D322D31312C502D522D33353834362D382D342C502D522D33353430372D342D332C502D522D33333133342D322D31372C502D522D33303239322D342D392C502D522D32383634342D312D342C502D522D32343033372D312D372C502D522D32333434352D332D372C502D522D32333337302D322D392C502D522D32333433342D332D372C502D522D31383531332D312D33302C502D442D33343630392D312D332C502D442D33343235302D312D332C73686175743539363A3639383734352C776F72646D61696C737461746566756C6175676C6F6F706F6E3A3430343730362C73686772613439383A3232373730372C73686772613630313A3138343038302C73686772613335353A3230383034392C73686772613530323A3138393932342C73686772613734373A38363637372C73686963723331373A39343532312C502D582D313130373037302D322D332C502D582D313038333432372D322D352C502D582D313034313336382D332D31302C502D582D313034323339332D332D372C502D582D313032343737362D322D372C502D582D313030303332322D312D372C502D522D36353031312D312D332C502D522D35303534312D322D372C66366562623730383A3433343833322C6A683861623434373A3338303633332C65386A69683932303A3434323139352C6C697374656E696E676F6E6465766963653A3332343439342C61686938323431313A3434323135392C73683335303A3332393432382C502D582D37313536382D312D352C502D522D36393233322D33382D31322C502D522D32363434322D312D382C502D522D32333638312D322D372C502D442D33323530322D322D332C502D442D33323530312D322D332C502D442D33323431352D322D332C7461656E613537363A39303236352C502D582D313033383432302D322D352C502D582D3130393636322D312D31372C502D582D3130373131392D312D332C502D582D38303033382D312D352C502D522D36343531332D31382D31312C502D522D35313931362D38342D33312C502D442D313136303234302D312D362C502D442D313136303134312D312D342C38686262343533383A3338363637302C74656172693335323A3233333737342C74657072693632383A3433393731302C74656576653835303A3132303534302C502D522D313538353838372D342D362C502D522D313036373736362D372D31352C502D522D313535313135332D312D332C502D522D313233363935332D382D31322C502D522D313534373631372D312D332C502D522D313532363837352D31352D332C502D522D313532363837342D31352D332C502D522D313532363837332D31352D332C502D522D313532363837322D31352D332C502D522D313532363837302D31352D332C502D522D313532363836392D31352D332C502D522D313532363836382D31352D332C502D522D313532363836372D31352D332C502D522D313532363836362D31352D332C502D522D313532363836322D31352D332C502D522D313437393637342D332D352C502D522D33383234382D32322D32382C502D522D313431353138332D33322D342C502D522D313431353138322D33322D342C502D522D313431353138312D33322D342C502D522D313431353138302D33322D342C502D522D313431353137392D33322D342C502D522D313238303138362D312D332C502D522D313236373038342D322D362C502D522D313236313931382D322D342C502D522D313235393532392D312D332C502D522D313234353830342D34382D352C502D522D313234353239362D342D362C502D522D313138333633392D36322D362C502D522D313138333633312D36322D362C502D522D313138333632382D36322D362C502D522D313135373537302D322D342C502D522D313134303939382D37352D372C502D522D313134303939372D37352D372C502D522D313134303939362D37352D372C502D522D313134303939352D37352D372C502D522D313134303939342D37352D372C502D522D313134303939332D37352D372C502D522D313134303939322D37352D372C502D522D313134303939312D37352D372C502D522D313134303939302D37352D372C502D522D313134303938392D37352D372C502D522D313133323832312D322D342C502D522D313132333331362D312D332C502D522D313131393031332D312D332C502D522D313130363736382D38362D382C502D522D313130363736372D38362D382C502D522D313130363736362D38362D382C502D522D313130363736352D38362D382C502D522D313130363736342D38362D382C502D522D313130363736332D38362D382C502D522D313130363736322D38362D382C502D522D313039383739362D312D332C502D522D313039343434352D312D332C502D522D313035383634332D352D392C502D522D313038303431322D312D332C502D522D313038303130312D39362D392C502D522D313038303130302D39362D392C502D522D313038303039392D39362D392C502D522D313038303039372D39362D392C502D522D313038303039362D39362D392C502D522D313038303039352D39362D392C502D522D313038303039342D39362D392C502D522D313038303039332D39362D392C502D522D313038303039322D39362D392C502D522D313038303039312D39362D392C502D522D313038303039302D39362D392C502D522D313038303038392D39362D392C502D522D313038303038382D3131332D31302C502D522D313037313736312D312D332C502D522D313036393736392D322D342C502D522D313036383131352D312D332C502D522D313032343037362D342D382C502D522D313032343037342D342D382C502D522D313035393332392D3130342D31302C502D522D313035393332382D3132312D31312C502D522D313035393332362D3130342D31302C502D522D313035393332352D3130342D31302C502D522D313035393332342D3130342D31302C502D522D313035393332332D3132312D31312C502D522D313035393332322D3132312D31312C502D522D313035393332312D38372D392C502D522D313035393332302D3130342D31302C502D522D313035393331392D3130342D31302C502D522D313035393331382D3130342D31302C502D522D313035393331372D3130342D31302C502D522D313035393331362D3130342D31302C502D522D313035393331352D3130342D31302C502D522D313035393331342D3130342D31302C502D522D313035393331322D3130342D31302C502D522D313035393331312D3130342D31302C502D522D313035393331302D3130342D31302C502D522D313035393330392D3130342D31302C502D522D313035393330382D3130342D31302C502D522D313035393330372D3130342D31302C502D522D313035393330362D3130342D31302C502D522D313035393330352D3130342D31302C502D522D313035393330342D3130342D31302C502D522D313035393330332D3132312D31312C502D522D313035393330322D3130342D31302C502D522D313035393330312D3132312D31312C502D522D313035393330302D3130342D31302C502D522D313035393239392D3132312D31312C502D522D313035393239382D3130342D31302C502D522D313035393239372D3132312D31312C502D522D313035393239362D3130342D31302C502D522D313035393239352D3130342D31302C502D522D313035393239342D3130342D31302C502D522D313035393239332D3130342D31302C502D522D313035393239322D37312D382C502D522D313035393239312D3132312D31312C502D522D313035393239302D3130342D31302C502D522D313035393238392D3130342D31302C502D522D313035393238382D3130342D31302C502D522D313035393238372D3130342D31302C502D522D313035393238362D3130342D31302C502D522D313035393238352D3130342D31302C502D522D313035393238342D3130342D31302C502D522D313035393238332D3130342D31302C502D522D313035393238322D3130342D31302C502D522D313035393238312D3130342D31302C502D522D313035393238302D3130342D31302C502D522D313035393237392D3130342D31302C502D522D313035393237382D3130342D31302C502D522D313035393237372D3130342D31302C502D522D313035393237362D3130342D31302C502D522D313035393237352D3130342D31302C502D522D313035393237342D3130342D31302C502D522D313035393237332D3130342D31302C502D522D313035393237322D3130342D31302C502D522D313035393237312D3130342D31302C502D522D313035393237302D3130342D31302C502D522D313035393236392D3130342D31302C502D522D313035393236382D3130342D31302C502D522D313035393236372D3130342D31302C502D522D313035393236362D3130342D31302C502D522D313035393236352D3130342D31302C502D522D313035393236342D3130342D31302C502D522D313035393236332D3130342D31302C502D522D313035393236322D3130342D31302C502D522D313035393236312D3130342D31302C502D522D313035393236302D3130342D31302C502D522D313035393235392D3130342D31302C502D522D313035393235382D3130342D31302C502D522D313035393235372D3130342D31302C502D522D313035393235362D3130342D31302C502D522D313035393235352D3130342D31302C502D522D313035393235342D3130342D31302C502D522D313035393235332D3130342D31302C502D522D313035393235322D3130342D31302C502D522D313035393235312D3130342D31302C502D522D313035393235302D3130342D31302C502D522D313035393234392D3130342D31302C502D522D313035393234382D3130342D31302C502D522D313035393234372D3130342D31302C502D522D313035393234352D3130342D31302C502D522D313035393234342D3132312D31312C502D522D313035393234332D3130342D31302C502D522D313035393234322D3130342D31302C502D522D313035393234312D3130342D31302C502D522D313035393134362D3132302D31322C502D522D313035393035332D3131322D31312C502D522D313035383938382D3132302D31322C502D522D313035383938372D3131322D31312C502D522D313035383938362D3131322D31312C502D522D313035383938352D3132382D31332C502D522D313035383938342D3132382D31332C502D522D313035383938332D3133362D31342C502D522D313035383938322D3133372D31332C502D522D313035383938312D3131322D31312C502D522D313035383938302D3131322D31312C502D522D313035383937392D3132382D31332C502D522D313035383937382D3132382D31332C502D522D313035383937372D3134342D31352C502D522D313035383937362D3133372D31332C502D522D313035383937352D3133372D31332C502D522D313035383937342D3133372D31332C502D522D313035383937332D3133372D31332C502D522D313035383937322D3133372D31332C502D522D313035383937312D3133372D31332C502D522D313035383936392D3133372D31332C502D522D313035383936382D3133372D31332C502D522D313035383936372D3133362D31342C502D522D313035383936362D3133362D31342C502D522D313035383936352D3131322D31312C502D522D313035383936342D3131322D31312C502D522D313035383936332D3131322D31312C502D522D313035383936322D3131322D31312C502D522D313035383936312D3131322D31312C502D522D313035383936302D3131322D31312C502D522D313035383935392D3131322D31312C502D522D313035383935382D3132302D31322C502D522D313035383935372D3131322D31312C502D522D313035383935362D3132392D31322C502D522D313035383935352D3132392D31322C502D522D313035383935342D3132392D31322C502D522D313035383935332D3132392D31322C502D522D313035383935322D3132392D31322C502D522D313035383935312D3132392D31322C502D522D313035383935302D3132392D31322C502D522D313035383934392D3132392D31322C502D522D313035383934382D3132392D31322C502D522D313035383934372D3132392D31322C502D522D313035383934362D3132392D31322C502D522D313035383934352D3132392D31322C502D522D313035383934342D3132302D31322C502D522D313035383934332D3132302D31322C502D522D313035383934322D3133362D31342C502D522D313035383934312D3132302D31322C502D522D313035383934302D3132302D31322C502D522D313035383933392D3132302D31322C502D522D313035383933382D3132302D31322C502D522D313035383933372D3132302D31322C502D522D313035383933362D3132302D31322C502D522D313035383933352D3132302D31322C502D522D313034393137352D312D332C502D522D313034353131382D322D342C502D522D313034343430382D312D332C502D522D313033373838372D312D332C502D522D313033373837392D312D332C502D522D313033363839342D312D332C502D522D313033363239332D312D332C502D522D313033363239322D312D332C502D522D313033363238392D322D342C502D522D313033363238382D312D332C502D522D313033363036382D322D342C502D522D313033363033392D322D342C502D522D313033353933332D322D342C502D522D313033353839342D312D332C502D522D313033353134392D322D342C502D522D313033333831372D312D332C502D522D313033333632342D322D342C502D522D313032383535302D322D342C502D522D313032383136382D312D332C502D522D313032373533352D332D352C502D522D313032343638302D342D362C502D522D313032343037312D322D342C502D522D313031313233322D332D352C502D522D313031303339332D312D332C502D522D313030363839362D312D332C502D522D313030363839342D312D332C502D522D313030363630362D332D352C502D522D313030363536322D322D342C502D522D313030303036312D322D342C502D522D3131313638322D312D332C502D522D3130353733312D33362D33382C502D522D3130343433352D31332D31352C502D522D3130303239342D312D332C502D522D39393633332D312D332C502D522D39383932392D322D342C502D522D39383932362D312D332C502D522D39383235302D312D332C502D522D39343535362D322D342C502D522D39333037372D312D332C502D522D39303839352D332D352C502D522D38383330392D322D342C502D522D38363131382D312D332C502D522D38303531372D372D392C502D522D37383835322D332D352C502D522D37383131322D342D362C502D522D37363931382D322D342C502D522D37363732312D312D332C502D522D37363235332D312D332C502D522D37353434302D322D342C502D522D37353433362D312D332C502D522D37353433342D312D332C502D522D37353433332D312D332C502D522D37323434392D372D31302C502D522D36383036392D322D342C502D522D36363937352D312D332C502D522D36363132312D322D342C502D522D36353536372D312D332C502D522D36333034392D322D342C502D522D36303630322D332D352C502D522D35333330392D312D332C502D522D35323633332D312D332C502D522D35323137312D322D342C502D522D35313932312D382D31302C502D522D35313235382D382D31302C502D522D35303735322D322D342C502D522D35303638312D322D342C502D522D35303539392D342D362C502D522D35303539362D342D382C502D522D35303538352D31372D31392C502D522D35303535332D312D332C502D522D35303530322D332D352C502D522D34393539372D332D352C502D522D34393435382D322D342C502D522D34383533302D372D392C502D522D34373934382D312D342C502D522D34363538302D332D352C502D522D34363438342D31302D31322C502D522D34363132322D312D332C502D522D34353835382D322D342C502D522D34333936362D322D342C502D522D34333530322D31392D32312C502D522D34333138382D362D382C502D522D34313433302D312D332C502D522D34303735312D382D31302C502D522D34303237332D342D362C502D522D33393233382D352D372C502D522D33383837382D322D342C502D522D33383638322D332D352C502D522D33373538382D322D342C502D522D33343335352D382D31302C502D522D32363236362D342D392C502D522D32363734302D352D31302C502D522D32363833342D332D382C502D522D32343636322D31362D32322C502D522D32373437392D362D31312C502D522D32363035362D372D31352C502D522D32373030362D372D31322C502D522D33323139312D392D31312C502D522D33303333382D332D372C502D522D33303137382D37392D38312C502D522D33303035332D382D31302C502D522D32373435382D312D352C502D522D32353832322D31362D31392C502D522D32353038332D362D392C502D522D32343639302D34342D34382C502D522D32343638392D322D352C502D522D32343636362D322D352C502D522D32343636332D362D31312C502D522D32343635392D372D31302C502D522D32333736322D352D382C502D522D32333734342D372D392C502D522D32333733392D372D392C502D522D32333733362D31342D31372C502D522D32333733342D372D392C502D522D32333733302D32312D32342C502D522D32333732332D31302D31322C502D442D33323538382D312D332C502D442D33323533342D312D332C502D442D33323532342D312D332C502D442D33323531382D312D332C502D442D33323531322D312D332C502D442D33323530392D312D332C502D442D33323438352D312D342C502D442D33323438342D312D342C502D442D33323430352D312D332C502D582D313032353438352D312D352C502D582D313033363938372D322D332C502D582D313033363137332D322D332C502D582D3130
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:ChunkCount
Value:
uint64_t|2
(PID) Process:(7432) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData
Operation:writeName:1.3
Value:
33333537332D312D352C502D582D313033313539322D312D332C502D582D313033303033352D322D332C502D582D313032303536382D312D332C502D582D313030343337332D312D352C502D582D39333430372D312D352C502D582D39343332362D322D352C502D582D37383833302D342D31342C502D582D37333137392D312D372C502D582D37313939392D332D31312C502D522D313038373134312D342D372C502D522D313037353139392D362D342C502D522D313031333933302D342D352C502D522D35333038352D31382D31332C502D522D34373630312D31382D31332C502D522D34373331382D31302D32342C502D522D33333931362D312D352C502D522D33333538302D382D392C502D522D33313936362D32312D32352C34643065623633333A3237303232312C6A663463653839333A3330383937332C666A3265673632333A3238383530382C68666A67383232393A3238363439312C37623367633334313A3330383937352C6170705F73706563696669635F66696E645F6865616465725F74726561746D656E743A3330363139372C75637368613234373A3239353839322C75633430353A3233353331312C75637368613531333A3233333035312C7365617263685F696E696E73706563746F7277696E646F77735F66696E64696E646F633A3231323735362C69633468663131355F6C6F63616C3A3133383735362C656E61626C656E6F74657365617263683A3134393733342C75637368613636303A37363535382C502D582D313036343937332D312D352C502D582D313035313736332D322D372C502D582D313031303537322D312D332C502D582D313030303436352D312D332C502D582D3131373430302D312D332C502D582D38323439362D312D352C502D582D38323439372D312D352C502D582D3130353639372D312D392C502D582D39373434352D332D31352C502D582D39343937322D312D332C502D582D37313731322D312D352C502D582D37333132302D312D352C502D582D36323631302D312D352C502D522D313131313938342D342D352C502D522D313038343335342D382D372C502D522D313037393235342D382D372C502D522D313033353932312D342D342C502D522D35393832302D31382D3130352C502D522D36313432362D31382D392C502D522D35393432362D312D332C502D522D34363931332D31382D382C502D522D32353836372D312D362C39356167673335373A3334323230302C6D65636F6E74726F6C5F7765616B7074725F696E746567726174696F6E5F656E61626C65643A3731373736392C75783434363A3437303638332C7578666C753233343A3435323030332C75786D656469756D69636F6E6C756D696E616E63653A3335333435352C75786163633531363A3238323131382C75786163633131333A3238323131372C666C75656E746261636B7374616765726566726573683A3234363431322C6D696361666C696768743A3337373531342C7578656E613130313A3238383831382C636865636B6F75746465766963656F6E7061696E743A3132323131302C757873686F3634353A3139303337382C75786D6F643330313A35333336322C502D522D31393236322D322D31322C502D582D313234393939372D312D332C502D582D313132303036332D322D332C502D582D37363539392D312D31312C502D582D313035333231312D372D32312C502D582D313037323233302D312D332C502D582D313037323232382D312D332C502D582D313036353636392D322D332C502D582D313032393936332D332D31312C502D582D313035383638362D312D372C502D582D313036313330382D312D352C502D582D313036313333302D312D332C502D582D313036303638382D312D332C502D582D313035393439332D312D332C502D582D313035393036312D322D332C502D582D39363533312D312D352C502D582D313035343934382D312D352C502D582D313035363735312D322D332C502D582D313035353037372D322D332C502D582D313035343332302D312D332C502D582D313033303238302D322D352C502D582D313034383833362D312D332C502D582D313034373032322D322D332C502D582D313034363338312D312D332C502D582D313034363133352D322D332C502D582D39313034392D312D352C502D582D313030303139332D312D352C502D582D313034333930322D312D332C502D582D313034333737372D322D332C502D582D313034333734352D312D332C502D582D313034333030382D322D332C502D582D313034323237352D322D332C502D582D313034313335392D322D352C502D582D313034313031312D322D352C502D582D313033393834312D322D332C502D582D313033393433362D312D332C502D582D313033383733392D312D332C502D582D313033373733322D322D332C502D582D313033373139362D312D332C502D582D313033363636362D322D332C502D582D313033363534302D322D332C502D582D313033353634362D322D332C502D582D313033333333322D322D332C502D582D313031323530302D352D31382C502D582D313032383238342D322D352C502D582D313032383136332D312D332C502D582D313032373836312D312D332C502D582D313031363338372D312D372C502D582D313032373038312D322D352C502D582D313032343736372D322D332C502D582D313032313636352D322D352C502D582D313031393432352D312D332C502D582D3130373631392D312D352C502D582D313031363739372D312D332C502D582D313031343733382D312D332C502D582D313031323138372D312D352C502D582D313030363435302D312D352C502D582D313030363938302D312D332C502D582D3131373631312D312D372C502D582D313030353439302D312D332C502D582D38343331362D332D32312C502D582D313030343631362D312D332C502D582D313030343631352D312D332C502D582D313030333636312D312D332C502D582D313030333238392D312D332C502D582D313030303436372D312D332C502D582D3131353136372D312D332C502D582D39393839392D312D352C502D582D3130393637372D312D332C502D582D39343135372D312D352C502D582D39353233332D312D352C502D582D39333933362D312D332C502D582D39323832392D312D332C502D582D39323830372D312D352C502D582D39313533392D312D332C502D582D38393731332D312D352C502D582D38373235332D312D352C502D582D38353439372D312D352C502D582D38343836382D312D332C502D582D37383534382D312D332C502D582D37353234322D312D352C502D582D37373138342D312D332C502D582D36343230372D312D352C502D582D36373530392D312D332C502D452D32393636312D43312D332C502D522D313235303132392D31332D31352C502D522D313136383533322D382D362C502D522D313432362D31312D342C502D522D313134353333322D31312D342C502D522D313133373538332D382D332C502D522D313133313039372D382D342C502D522D313132303133322D32312D352C502D522D313132303039322D31342D31342C502D522D36343839312D31372D392C502D522D313131373034332D31332D352C502D522D313438352D31332D332C502D522D313130343836322D382D372C502D522D313039393737342D382D372C502D522D313039373436322D382D372C502D522D313039323635332D382D382C502D522D313039313638342D31322D31312C502D522D313039313636322D382D372C502D522D313039303639312D31322D352C502D522D313039303434342D31322D372C502D522D313038353934302D382D372C502D522D313037393733312D382D362C502D522D313037393031352D342D372C502D522D313037383833382D342D382C502D522D313037363131392D382D372C502D522D313037353038392D382D372C502D522D313036393434372D382D342C502D522D313036393537362D382D382C502D522D313036393139342D382D372C502D522D313036363636322D382D372C502D522D313036333832392D382D382C502D522D313036333430352D382D372C502D522D313036323331382D382D372C502D522D313036313735332D382D382C502D522D313035363437342D382D352C502D522D313035313137382D382D362C502D522D313034383233302D382D392C502D522D313034383032342D362D382C502D522D313034353430382D382D342C502D522D313034303631302D382D342C502D522D313033373838322D382D372C502D522D313033363934322D382D362C502D522D313033333834332D382D392C502D522D313032383633302D382D372C502D522D313032363135352D382D372C502D522D313032353934392D382D372C502D522D313032333533362D382D372C502D522D313031393633312D382D352C502D522D313031393631302D382D372C502D522D313031393038392D382D372C502D522D313031343536352D382D382C502D522D313031343434382D382D372C502D522D313031313539312D382D372C502D522D313030373238382D382D372C502D522D313030363736372D382D382C502D522D313030353137322D362D31312C502D522D313030343535302D362D31302C502D522D313030333934382D362D31362C502D522D3131373937372D382D372C502D522D3131373131312D382D382C502D522D3131363638392D382D372C502D522D3131363638382D382D382C502D522D3131313836362D382D372C502D522D3130303137392D382D372C502D522D39373036312D382D382C502D522D39353030372D31342D32322C502D522D37373337342D312D382C502D522D35333730302D31362D32302C502D522D34393836332D312D332C502D522D33353837332D32302D32302C502D522D33353030362D342D342C502D522D32303037302D312D392C35613736303236303A3539323137352C39353631313738363A3437373132342C776F656E613433343A3339333639332C63376936623330373A3435333535352C32363431663137383A3432383038382C3234336A333537393A3530393731332C65303333613931303A3430313937352C62666934383438392D74726561746D656E742D6661737465726E6F6E756C6C6E6F76616C69646174696F6E3A3434323034372C61393737383234373A3338333230382C6E6F69646C6575696D696E746572727570743A3636373533312C61393868343738313A3438303336342C66316935363731393A3339323030392C33393339673236363A3337383237312C63686A66613938353A3339333230352C776F636F6E3635363A3332373833302C32356638353838373A3334303332352C61393130303237393A3335393236322C65636234633430393A3339363033362C37313968693430333A3434373635332C616868626A3334363A3238313730312C31393831313234313A3333383635362C68336230353239383A3333383335322C626A6668663534313A3434383431392C69376839663434373A3430383635332C776F636C653737353A3230313535312C6E657572616C766F69636573657276696365726571756573747468726F74746C696E67656E61626C65643A3632373035302C62396436303131353A3338363537362C376A6434623137373A3732373938302C666978626164626F6F6B6D61726B3A3339313836392C69626233303434333A3239393031342C67316836623639323A3333343638322C6438336A343731383A3238383833302C6C696E6B6D6F72653A3332383238302C656E61626C656D657267656269626F7074696D697A6174696F6E3A3333323032332C353869616A3234333A3332343631382C35346739343835373A3434303232362C65306562623333303A3335343236332C34663366623834333A3239313233392C6E756C6C636865636B706974627374663A3237393030382C6738326A383837373A3239343637342C656E61626C657468656D65666F6E7475706461746574726561746D656E743A3434383333322C6E6F6F647433743A3530323939302C776F37333874726561746D656E743A3236323436352C7764736478656469746F726472696C6C696E2D743A3333373532332C776F6D74797969656C643A3434383336382C63373134693738333A3238313639362C616C6C6F776172746F6D657267653A3237363630342C38356265313539363A3435333535382C64376A63623730323A3236383539312C69673665653838373A3338393731302C776F64656C3233353A3337393536362C776F6675733934373A3435333533322C776F6669783636343A3235343634352C776F3930363A3335363638362C776F7468723639343A3335353931332C776F77696E3839353A3335373435332C776F6C61793735353A3232373335372C776F3638373A3139373237332C776F7573653138393A3436333432302C72656164616C6F75646E657572616C766F696365656E61626C65646E65773A3533303739332C776F6368653636383A3431383330342C66656E61626C65636F6E746578746D656E75656E747279706F696E743A3338303031322C776F656E613736393A3435343335332C776F6368753632303A3232383530382C776F736B693330363A3234363338312C776F3338303735343A3433363032352C776F7573653836373A3138303037382C776F656E613336333A3432343334352C776F6C61793535303A3134343334382C776F656E613639353A3139363434392C776F6C61793131313A3239353930302C776F636F6E3537383A3330333138312C776F636F763435333A3134343439362C776F3532393835333A3137363831322C776F7465733331373A3337373530342C776F7573653433383A3132343234322C776F6C61793334303A3132343232332C776F72646F64663133646576696365733A3132323233362C776F616C773830393A3132343233322C776F6272653535363A3139363035392C776F636F6C3933363A38303033312C776F6966693136333A37313830322C776F656E613238383A3234393235352C776F656E613736393A3435343335332C776F6675733934373A3435333533322C62666934383438392D74726561746D656E742D6661737465726E6F6E756C6C6E6F76616C69646174696F6E3A3434323034372C776F656E613336333A3432343334352C776F6368653636383A3431383330342C502D522D313538333836352D312D362C502D522D313536333934352D312D382C502D522D313132383633302D312D372C502D522D313039383431322D312D352C502D522D313039313236372D312D35372C502D522D38313732302D312D322C502D522D35383430362D312D352C502D442D35303639372D322D342C502D442D32393731392D312D312C502D442D32393731382D312D312C502D442D32393539332D312D36222C2022434322203A20227374643A3A77737472696E677C4445222C2022446566436F6E667322203A20227374643A3A77737472696E677C6F6673683663326231746C61316133312C6F666372756934797664756C626633312C6F6668706578336A7A6E65706F6F33312C6F6670696F796766716D756673743331222C202245787054696D6522203A2022696E7436345F747C31373438333535313435222C20224554616722203A20227374643A3A77737472696E677C5C22346A5045454B5431516655435549766B7350636E4C7A4B3974473667334772704D7274526A41754F5539633D5C22222C202246434D617022203A205B207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E4368616E6765476174655F446F6E74547275737456424156617269616E74446F75626C6556616C7565222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E4368616E6765476174655F446F6E74547275737456424156617269616E74446F75626C6556616C75654E6577222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E4368616E6765476174655F4E6577556E69636F6465496E556E697175654964656E746966696572436F6C756D6E222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E4368616E6765476174655F556E69636F6465496E556E697175654964656E746966696572436F6C756D6E222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E43757272656E6379446563696D616C506C61636573466978222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E446F6E745265696E697469616C697A654D736F34222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E46697844656C657465644272757368497373756573222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E4163636573732E4D6163726F5369676E696E67222C20225622203A2022626F6F6C7C3122207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E44756D6D79443244446576696365436F6E74657874466C75736843616C6C4F6E44656D616E6432222C20225622203A2022626F6F6C7C3122207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E4764694861726477617265416363656C65726174696F6E222C20225622203A2022626F6F6C7C3122207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E5363686564756C654173796E63436F6D6D6974416674657242696E64696E67536B697050726F6A656374222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E536574466C697054657874757265557064617465222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E536B69705A6F6F6D416E6450726F7061676174654F6E496E76697369626C655363726F6C6C696E674C61796572222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E53796E6368726F6E6F757353686F7757696E646F77496E4D6F7265436173657332222C20225622203A2022626F6F6C7C3122207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E5573654944697265637433644465766963654163636573735633222C20225622203A2022626F6F6C7C3122207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E55736550726976617465417069546F436F6D706C657465416E696D6174696F6E734F6E53637265656E4F63636C75646564222C20225622203A2022626F6F6C7C3022207D2C207B20224622203A20224D6963726F736F66742E4F66666963652E41697253706163652E55736557696E436F6D70496E57696E3332222C20225622203A2022626F6F6C7C3122207D2C207B20224622203A20224D6963726F736F66742E4F66666963
Executable files
2
Suspicious files
430
Text files
131
Unknown types
87

Dropped files

PID
Process
Filename
Type
7432OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF10f09b.TMP
MD5:
SHA256:
7432OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:56EBF6F13AA45C5BDE20103EF759465E
SHA256:3BDF114335C7BD38CF525F4E2664F5CEE9A57208E1C80045A3E59C6E2CD93D91
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database\LOG.oldtext
MD5:798EBA8558D3655BC5D2B61984B3BF12
SHA256:04EB76D36567C4FD801C5583AA34A18A081D9030BAE3034D8F81D419A797221D
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF10f09b.TMP
MD5:
SHA256:
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF10f09b.TMP
MD5:
SHA256:
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10f09b.TMP
MD5:
SHA256:
7420msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
51
TCP/UDP connections
137
DNS requests
170
Threats
21

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7640
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7432
OUTLOOK.EXE
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
7640
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7300
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3ab36512-8e78-4855-9d3c-00fc48298f23?P1=1748582336&P2=404&P3=2&P4=VTWT%2fRDrcdnJhDLDo56YIQnwI3ahc7jSlgPELnGOfjX4UBXP9Xs3K%2bMDiMioWqKBblwtfs25sSH1GM95C%2fdIXg%3d%3d
unknown
whitelisted
7300
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3ab36512-8e78-4855-9d3c-00fc48298f23?P1=1748582336&P2=404&P3=2&P4=VTWT%2fRDrcdnJhDLDo56YIQnwI3ahc7jSlgPELnGOfjX4UBXP9Xs3K%2bMDiMioWqKBblwtfs25sSH1GM95C%2fdIXg%3d%3d
unknown
whitelisted
7300
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3ab36512-8e78-4855-9d3c-00fc48298f23?P1=1748582336&P2=404&P3=2&P4=VTWT%2fRDrcdnJhDLDo56YIQnwI3ahc7jSlgPELnGOfjX4UBXP9Xs3K%2bMDiMioWqKBblwtfs25sSH1GM95C%2fdIXg%3d%3d
unknown
whitelisted
7300
svchost.exe
GET
206
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3ab36512-8e78-4855-9d3c-00fc48298f23?P1=1748582336&P2=404&P3=2&P4=VTWT%2fRDrcdnJhDLDo56YIQnwI3ahc7jSlgPELnGOfjX4UBXP9Xs3K%2bMDiMioWqKBblwtfs25sSH1GM95C%2fdIXg%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
7432
OUTLOOK.EXE
52.123.129.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7432
OUTLOOK.EXE
2.16.168.119:443
omex.cdn.office.net
Akamai International B.V.
RU
whitelisted
7432
OUTLOOK.EXE
52.111.232.11:443
messaging.lifecycle.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
JP
whitelisted
7432
OUTLOOK.EXE
52.111.243.37:443
nleditor.osi.office.net
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 2.23.246.101
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted
omex.cdn.office.net
  • 2.16.168.119
  • 2.16.168.101
whitelisted
messaging.lifecycle.office.com
  • 52.111.232.11
whitelisted
nleditor.osi.office.net
  • 52.111.243.37
  • 52.111.243.39
  • 52.111.243.43
  • 52.111.243.41
  • 52.111.243.42
  • 52.111.243.40
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.65
  • 20.190.160.4
  • 20.190.160.22
  • 20.190.160.131
  • 40.126.32.76
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted

Threats

PID
Process
Class
Message
1184
msedge.exe
Misc activity
ET INFO Observed URL Shortener Service (tr .ee) in DNS Lookup
1184
msedge.exe
Misc activity
ET INFO Observed URL Shortener Service (tr .ee) in DNS Lookup
1184
msedge.exe
Misc activity
ET INFO Observed URL Shortener Service Domain (tr .ee) in TLS SNI
1184
msedge.exe
Misc activity
ET INFO Observed URL Shortener Service Domain in DNS Lookup (goo .su)
1184
msedge.exe
Misc activity
INFO [ANY.RUN] Possible short link service (goo .su)
1184
msedge.exe
Misc activity
INFO [ANY.RUN] Possible short link service (goo .su)
1184
msedge.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
1184
msedge.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
1184
msedge.exe
Misc activity
ET INFO Observed URL Shortener Service Domain in DNS Lookup (goo .su)
1184
msedge.exe
Potentially Bad Traffic
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
No debug info