Click to jump to signature section
Source: https://q2zg22.ru | Matcher: Template: microsoft matched with high similarity |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | Matcher: Template: microsoft matched with high similarity |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | Matcher: Template: microsoft matched with high similarity |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | Matcher: Template: microsoft matched with high similarity |
Source: Yara match | File source: 1.1.pages.csv, type: HTML |
Source: Yara match | File source: 2.2.pages.csv, type: HTML |
Source: Yara match | File source: 2.6.pages.csv, type: HTML |
Source: Yara match | File source: 2.7.pages.csv, type: HTML |
Source: Yara match | File source: 3.4.pages.csv, type: HTML |
Source: Yara match | File source: 6.10.pages.csv, type: HTML |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | Matcher: Found strong image similarity, brand: MICROSOFT |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHom | Matcher: Template: microsoft matched |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHom | Matcher: Template: microsoft matched |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHom | Matcher: Template: microsoft matched |
Source: https://ywnjb.q2zg22.ru/Me.htm?v=3 | Matcher: Template: microsoft matched |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state= | Matcher: Template: microsoft matched |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state= | Matcher: Template: microsoft matched |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHom | Matcher: Template: microsoft matched |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state= | Matcher: Template: microsoft matched |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNmgiDPuF7RBPuj5SL3QM3C4M1Kh06FbCzoMkifzVJpPWCAA&jshs=0&username=sales%40dudick.com&login_hint=sales%40dudick.com | HTTP Parser: sales@dudick.com |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: Iframe src: https://ywnjb.q2zg22.ru/Me.htm?v=3 |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: Iframe src: https://ywnjb.q2zg22.ru/Me.htm?v=3 |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: Number of links: 0 |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: Number of links: 0 |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: Number of links: 0 |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm... | HTTP Parser: Title: Sign in to your Microsoft account does not match URL |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu... | HTTP Parser: Title: Sign in to your Microsoft account does not match URL |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: <input type="password" .../> found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm... | HTTP Parser: <input type="password" .../> found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu... | HTTP Parser: <input type="password" .../> found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: No favicon |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: No <meta name="author".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: No <meta name="author".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: No <meta name="author".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: No <meta name="author".. found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm | HTTP Parser: No <meta name="author".. found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm | HTTP Parser: No <meta name="author".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: No <meta name="author".. found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu | HTTP Parser: No <meta name="author".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: No <meta name="copyright".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: No <meta name="copyright".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true#sales@dudick.com= | HTTP Parser: No <meta name="copyright".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&ui_locales=en-US&mkt=en-US&client-request-id=c9bbf586-3cb7-49e4-968c-855cb9b06dff&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: No <meta name="copyright".. found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm... | HTTP Parser: No <meta name="copyright".. found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=R1btjlLn0nsZ_HvybI1iQW79egJ4bfNhK6dkOmYcpbkizlXH594AztIP6k3xDmNUNdhPsej1iEMqwnjX96gynUUnHYVeqz7YpxI2QvZLJHV4r8DkHEi6Nk8gljZZv5WvGlIE5Og26go-5T2U69lQn1q5TI6o5VQMsZwWoXeA_nxn2T4NZft3rheUU5cDdv-TF9mO58xUEf_LDJcTw6zGzx-tCZqFP_odYqLyqaugqkr4-_v5VGMA8GP4vUjSWkdW82XubX6bTJ2NwLgrF94KOA&response_mode=form_post&nonce=638424982717341745.ZTA1YTc1Y2QtM2Y3NS00MGY0LWFjYTQtOGFjMWVjMmVkMGM0M2MwMjM3NDEtMDBiMy00ZTkyLWE1MjAtMDI3YTU3ZGE0Mzlj&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=c9bbf5863cb749e4968c855cb9b06dff&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-fpe1vwdUJkY82ZhiJe6dZAazdC0yzeQJJRTvFYOwRwcElNBSvxdCWYrC3SWRQx-4PgW46cqont4lIpPdTPko0yShUMTF97s6JNl2oTSn9sGpADw9tB-sITNf3ywWIMAA43EIRCDr8jwd66nEWyjcN6ukC7rHkGx2wY8Vd9SspNm... | HTTP Parser: No <meta name="copyright".. found |
Source: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&ui_locales=en-US&mkt=en-US&client-request-id=a2d3a705-3719-4180-a89a-d819ae49ee07&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0#sales@dudick.com | HTTP Parser: No <meta name="copyright".. found |
Source: https://ywnjb.q2zg22.ru/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2freact.q2zg22.ru%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2freact.q2zg22.ru%2flandingv2&response_type=code+id_token&state=cVigJ0JKTf9_p9nwrLeIejpLLL12Uyh9OPJOdewXQlGmDl6PEuqBRU12YO_Rh7PQdKwvV6i1wFIUZ9-EhwYWtkG4yTfICV5C6jSNAUoADJ6_0zI8wNMdIdaSYa8hT-NSBLEbMy_G0BYDULKKBl4E9Ea810-L67NsvlH1vUDs5gM8GHezu9jGTZv5CnUNeALJbhR-E1LnrgBBLTmgIMnzcGRIYgbDyHMzjadqPT5yQgH1vbHDx95jzBZOmijLYriIMyXBuWk5BqZIt3QU0LE--A&response_mode=form_post&nonce=638424983050563650.Y2ExYzgxZjItYzQ0OC00NGZiLTlkZmEtMTgyODk2MjEzNTZlM2IyMDBhY2MtZjlmZC00NjY1LTg2MTQtMzBiOTZjZmQzZmZk&x-client-SKU=ID_NET6_0&x-client-Ver=6.34.0.0&uaid=a2d3a70537194180a89ad819ae49ee07&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-wPnKDyEAN_-6_8G41fz1PZOuL_1y9VtFP9t7p5gKipKKkELpLDxD2Rb7BLgS6h8Soay21wXTavcrc02E4yhCuHro0M9AvwBh2rBqhWv2_UozUSmdABAVrgZtx9AirQKvOQbYZGv_tKnDBJnro-7F_HgAANox4NGPRLIGMSuESBu... | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.16:49718 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.16:49719 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49723 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49817 version: TLS 1.2 |
Source: Joe Sandbox View | IP Address: 13.107.246.41 13.107.246.41 |
Source: Joe Sandbox View | IP Address: 172.67.209.71 172.67.209.71 |
Source: Joe Sandbox View | IP Address: 162.241.124.47 162.241.124.47 |
Source: Joe Sandbox View | IP Address: 162.241.124.47 162.241.124.47 |
Source: Joe Sandbox View | IP Address: 13.107.213.41 13.107.213.41 |
Source: Joe Sandbox View | JA3 fingerprint: 1138de370e523e824bbca92d049a3777 |
Source: Joe Sandbox View | JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.29.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.12.23.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.12.23.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.12.23.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.12.23.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.12.23.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.12.23.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.1.237.25 |
Source: global traffic | HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com |
Source: global traffic | HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XN7tdkbw6C3m8Lv&MD=htgtz4Vy HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com |
Source: global traffic | HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /c3?firsttime=1&tcs=2478&chn=emailing&src=neolane&cmp=20231127_email_relance_app30_befr&cty=be&med=actu&url=//galeonconstruction.com/nin/niit HTTP/1.1Host: sushishop.commander1.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /nin/niit HTTP/1.1Host: galeonconstruction.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /nin/niit/ HTTP/1.1Host: galeonconstruction.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /mail/inbox/ HTTP/1.1Host: microsoft-d2vkbmvzwzgf.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04 |
Source: global traffic | HTTP traffic detected: GET /login HTTP/1.1Host: react.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04 |
Source: global traffic | HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0 HTTP/1.1Host: office.q2zg22.ruConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://galeonconstruction.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97 |
Source: global traffic | HTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04/521393ffd6e6e26814c2481ea580df56f06a765733586ff8dc0db635147b4d9a.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA |
Source: global traffic | HTTP traffic detected: GET /s/afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA |
Source: global traffic | HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_aoxn9LgNNeyAz3OYDcN7uA2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://office.q2zg22.rusec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://office.q2zg22.ru/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/scripts/jsd/main.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/scripts/jsd/24864818/main.js HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1SjljL2-mhgQ9VoUJK3J_wvKRz3Sjbi4oTarW6t9Zz7ed5ioicPhWSPqwo0BZiORSIVftWlg5DNCJFrIgBxKMsmna1gkBhhlzTVsbGcOi6THtwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=2E6F22D2EA936CD30EE836CBEBB26D97; esctx-sAcwFNXs9p0=AQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Xz-zY4mFOFPtOKDCtkncDgiCqiq8JSPFEneyjDU4hFCxc9yKOXR0OSKd5FYQRJM3mXeQZYPo-cw18QcWUama1nI0_hypcV18IPjbFcAN8l-2_npQ8hQ5HCn_XXMqMr00sdRCGYoSBfgWdZ8ETjE1OiAA |
Source: global traffic | HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0&sso_reload=true HTTP/1.1Host: office.q2zg22.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://office.q2zg22.ru/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638424982651072914.MTc3ZWVkZGQtYTZjNy00OTZlLTgxODctYWFiZGUzNzYwM2JlNjljY2M1YzEtZjRmNy00Njg2LTk5NzctYmUyYmY1ZDhiYjVi&ui_locales=en-US&mkt=en-US&client-request-id=27340d1a-f75c-4aed-bfd4-e7d89e08f2f5&state=Yvf-XDUrjz0oeLPkq8m6wvZNNx-4HHkagqS9BhHl9kXhuZbnWeP_boVBmzqCmf36UjRbbqyVFxS6NfMPtPrMzkYT0e3eC9jdOQOPVaXsUaKvdkKS66v9CzSs89a-xvCDlX83KjhHGwLHOIpviusPB2JbXEDMaguF9u_IRWYYWRgKHLprzYpu6YRCePlMSrde_70j5tZlDSgEnKs7NwUMbr6fRrt8o-EvCVkm0FfE3NnjacnfJhuLiNnd81beGyMvkxdpyTZsYXUvoKRGU0_4ng&x-client-SKU=ID_NET6_0&x-client-ver=6.34.0.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: ae23-8632=afc35fefb916ef4eaaf2fe859837e744a9c25a67b61248f6ee93c6a02ca7fe04; fpc=Aq_odsI7GDJHm8suSWCV-X8; esctx=PAQABAAEAAAAmoFfGtYxvRrNriQdPKIZ-Vdc2TMKN3WgRVIPG2KYMe9cKLPhl_mFvXXBfxpTirUGdlKhgqDMpWnM2_5_gD1Sjlj |