Windows Analysis Report


General Information

Sample URL:
Analysis ID: 1541695


Score: 20
Range: 0 - 100
Whitelisted: false
Confidence: 80%


AI detected landing page (webpage, office document or email)
Drops files with a non-matching file extension (content does not match file extension)


Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: global traffic HTTP traffic detected: GET /:f:/g/personal/dmiller_retinatulsa_com/ElBi9GQATzFLspsGNnE3XgEB-vtfzVVycqutPd6xXmtipQ?e=lATAVo HTTP/1.1Host: tulsaretina-my.sharepoint.com
Source: global traffic HTTP traffic detected: GET /personal/dmiller_retinatulsa_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fdmiller%5Fretinatulsa%5Fcom%2FDocuments%2FAlliance%20Technical%20Group&ga=1 HTTP/1.1Host: tulsaretina-my.sharepoint.com
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host:
Source: global traffic HTTP traffic detected: GET /personal/dmiller_retinatulsa_com/_api/v2.1/graphql HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=1cHwVDBHAk1kLhC&MD=R6MXt3om HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host:
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /personal/dmiller_retinatulsa_com/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fdmiller%5Fretinatulsa%5Fcom%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /personal/dmiller_retinatulsa_com/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fdmiller%5Fretinatulsa%5Fcom%2FDocuments%27&RootFolder=%2Fpersonal%2Fdmiller%5Fretinatulsa%5Fcom%2FDocuments%2FAlliance%20Technical%20Group&TryNewExperienceSingle=TRUE HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /personal/dmiller_retinatulsa_com/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fdmiller%5Fretinatulsa%5Fcom%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&navigationPreloadHeaderValue=%7B%22supportsFeatures%22%3A%5B1855%2C61313%5D%7D&dataHost=Nucleus&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%2C%7B%22id%22%3A%22SPStart%22%7D%2C%7B%22id%22%3A%22Agreements%22%7D%5D&list=v2&prefetchListData=true&defaultBrotli=true&authenticateFast=true&inlineAuth=v2&wwData=true&enableTheming=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099905,3]&spStartApplicationWebBundle=true&enableIntegrities=true&streamViewServerLoad=true&streamInlineScript=true HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveCache-Control: max-age=0Accept: */*Service-Worker: scriptSec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: serviceworkerReferer: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /_vti_bin/afdcache.ashx/_userprofile/userphoto.jpg?_oat_=1729894253_994b437c72ac238a29cf6298df49691bfddb3d28855bc3ab7ba7c2aadb09432e&P1=1729820047&P2=-149452251&P3=1&P4=SERj8f6czRe23%2FyK8y1WtVcK%2BxgQJqTJN9uPFaiIiwuvXrZ05ht6YFq%2Bq9ntUGNN5Y0yJmsova7UHt%2FbzaTPGQsk%2FZR%2BZZjhI6zm%2FImQzOvCDIZBFs%2BOtBweRss7W09XPSKspJ38EJSksFeP9%2FBZILOeHLNZX7onIF4h6ZoPVHfQYvp0VOPG6z9v9tFOybN3tHHNJ9U8wR%2BcgTgBFmK1QjE0hIEDFoGmiPEdefSHs0T1YGkrgB6JNboF9rf92qJ%2FbPST54HQrX8xX%2BNuc75JPxcR74rr%2Fm6TZsGKGtaG6pwAML9tLVoHyjLccYy3ZSJPyzRN6bYFPeJevgaahOCKTA%3D%3D&size=M& HTTP/1.1Host: tulsaretina.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_vti_bin/afdcache.ashx/_userprofile/userphoto.jpg?_oat_=1729894253_994b437c72ac238a29cf6298df49691bfddb3d28855bc3ab7ba7c2aadb09432e&P1=1729820047&P2=-149452251&P3=1&P4=SERj8f6czRe23%2FyK8y1WtVcK%2BxgQJqTJN9uPFaiIiwuvXrZ05ht6YFq%2Bq9ntUGNN5Y0yJmsova7UHt%2FbzaTPGQsk%2FZR%2BZZjhI6zm%2FImQzOvCDIZBFs%2BOtBweRss7W09XPSKspJ38EJSksFeP9%2FBZILOeHLNZX7onIF4h6ZoPVHfQYvp0VOPG6z9v9tFOybN3tHHNJ9U8wR%2BcgTgBFmK1QjE0hIEDFoGmiPEdefSHs0T1YGkrgB6JNboF9rf92qJ%2FbPST54HQrX8xX%2BNuc75JPxcR74rr%2Fm6TZsGKGtaG6pwAML9tLVoHyjLccYy3ZSJPyzRN6bYFPeJevgaahOCKTA%3D%3D&size=M& HTTP/1.1Host: tulsaretina.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_layouts/15/SPComponentRegistry.ashx?projects=[%22STS%22]&languages=%5B%5D HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveAccept: application/jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Content-Type: application/jsonSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer:[-83099905,3]&spStartApplicationWebBundle=true&enableIntegrities=true&streamViewServerLoad=true&streamInlineScript=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /_layouts/15/SPComponentRegistry.ashx?projects=[%22spfx%22]&languages=%5B%5D HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveAccept: application/jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Content-Type: application/jsonSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer:[-83099905,3]&spStartApplicationWebBundle=true&enableIntegrities=true&streamViewServerLoad=true&streamInlineScript=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /transform/passthrough?provider=spo&inputFormat=pdf&cs=fFNQTw&!h4j4iUDNXEuFPMK0-0z9aCHPmB2P-4dGnR9RE0Al3DBYvuPEXpqZQZTK034LdXeL%2Fitems%2F01KCJQRXVEQLHFGCGZ6NAJ6K6VDCUS7CXI%3Fversion%3DPublished&access_token=v1.eyJzaXRlaWQiOiI4OWY4ODg4Ny1jZDQwLTRiNWMtODUzYy1jMmI0ZmI0Y2ZkNjgiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvdHVsc2FyZXRpbmEtbXkuc2hhcmVwb2ludC5jb21AYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkIiwiZXhwIjoiMTcyOTgzNjAwMCJ9.CiMKCXNoYXJpbmdpZBIWdkg1Y2hwb0IxRTIzZC90M29mc2krZwoICgNzdHASAXQKCgoEc25pZBICMzMSBAjquAIaDjE3My4yNTQuMjUwLjgxIhRtaWNyb3NvZnQuc2hhcmVwb2ludCosZm15ZnJmK3VNUVg0eXF3andyUGRnR0FTbjNvSk5TVDRLRXBZS21mK3NFQT0weTgBShBoYXNoZWRwcm9vZnRva2VuYgR0cnVlcmEwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNhNzRhYTVjZGU2NDIwYjU2ODFhYTVjOTc3OTk2MWY5MGUzOTU1NGM5MTc0MjFkNjE4OGUxZTAyNjI1MGI2YTNiegEwwgFhMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYg.CTzoPGt6i07hxshHxV5IyW5X1CpF1dmbvBKGOwdRxV0&cTag=%22c%3A%7B53CE82A4-D908-40F3-9F2B-D518A92F8AE8%7D%2C1%22 HTTP/1.1Host: eastus1-mediap.svc.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://tulsaretina-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/passthrough?provider=spo&inputFormat=pdf&cs=fFNQTw&!h4j4iUDNXEuFPMK0-0z9aCHPmB2P-4dGnR9RE0Al3DBYvuPEXpqZQZTK034LdXeL%2Fitems%2F01KCJQRXVEQLHFGCGZ6NAJ6K6VDCUS7CXI%3Fversion%3DPublished&access_token=v1.eyJzaXRlaWQiOiI4OWY4ODg4Ny1jZDQwLTRiNWMtODUzYy1jMmI0ZmI0Y2ZkNjgiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvdHVsc2FyZXRpbmEtbXkuc2hhcmVwb2ludC5jb21AYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkIiwiZXhwIjoiMTcyOTgzNjAwMCJ9.CiMKCXNoYXJpbmdpZBIWdkg1Y2hwb0IxRTIzZC90M29mc2krZwoICgNzdHASAXQKCgoEc25pZBICMzMSBAjquAIaDjE3My4yNTQuMjUwLjgxIhRtaWNyb3NvZnQuc2hhcmVwb2ludCosZm15ZnJmK3VNUVg0eXF3andyUGRnR0FTbjNvSk5TVDRLRXBZS21mK3NFQT0weTgBShBoYXNoZWRwcm9vZnRva2VuYgR0cnVlcmEwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNhNzRhYTVjZGU2NDIwYjU2ODFhYTVjOTc3OTk2MWY5MGUzOTU1NGM5MTc0MjFkNjE4OGUxZTAyNjI1MGI2YTNiegEwwgFhMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYg.CTzoPGt6i07hxshHxV5IyW5X1CpF1dmbvBKGOwdRxV0&cTag=%22c%3A%7B53CE82A4-D908-40F3-9F2B-D518A92F8AE8%7D%2C1%22 HTTP/1.1Host: eastus1-mediap.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/thumbnail?provider=spo&inputFormat=pdf&cs=fFNQTw&!h4j4iUDNXEuFPMK0-0z9aCHPmB2P-4dGnR9RE0Al3DBYvuPEXpqZQZTK034LdXeL%2Fitems%2F01KCJQRXVEQLHFGCGZ6NAJ6K6VDCUS7CXI%3Fversion%3DPublished&access_token=v1.eyJzaXRlaWQiOiI4OWY4ODg4Ny1jZDQwLTRiNWMtODUzYy1jMmI0ZmI0Y2ZkNjgiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvdHVsc2FyZXRpbmEtbXkuc2hhcmVwb2ludC5jb21AYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkIiwiZXhwIjoiMTcyOTgzNjAwMCJ9.CiMKCXNoYXJpbmdpZBIWdkg1Y2hwb0IxRTIzZC90M29mc2krZwoICgNzdHASAXQKCgoEc25pZBICMzMSBAjquAIaDjE3My4yNTQuMjUwLjgxIhRtaWNyb3NvZnQuc2hhcmVwb2ludCosZm15ZnJmK3VNUVg0eXF3andyUGRnR0FTbjNvSk5TVDRLRXBZS21mK3NFQT0weTgBShBoYXNoZWRwcm9vZnRva2VuYgR0cnVlcmEwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNhNzRhYTVjZGU2NDIwYjU2ODFhYTVjOTc3OTk2MWY5MGUzOTU1NGM5MTc0MjFkNjE4OGUxZTAyNjI1MGI2YTNiegEwwgFhMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYg.CTzoPGt6i07hxshHxV5IyW5X1CpF1dmbvBKGOwdRxV0&cTag=%22c%3A%7B53CE82A4-D908-40F3-9F2B-D518A92F8AE8%7D%2C1%22&encodeFailures=1&width=1024&height=1024&srcWidth=&srcHeight= HTTP/1.1Host: eastus1-mediap.svc.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://tulsaretina-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/thumbnail?provider=spo&inputFormat=pdf&cs=fFNQTw&!h4j4iUDNXEuFPMK0-0z9aCHPmB2P-4dGnR9RE0Al3DBYvuPEXpqZQZTK034LdXeL%2Fitems%2F01KCJQRXVEQLHFGCGZ6NAJ6K6VDCUS7CXI%3Fversion%3DPublished&access_token=v1.eyJzaXRlaWQiOiI4OWY4ODg4Ny1jZDQwLTRiNWMtODUzYy1jMmI0ZmI0Y2ZkNjgiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvdHVsc2FyZXRpbmEtbXkuc2hhcmVwb2ludC5jb21AYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkIiwiZXhwIjoiMTcyOTgzNjAwMCJ9.CiMKCXNoYXJpbmdpZBIWdkg1Y2hwb0IxRTIzZC90M29mc2krZwoICgNzdHASAXQKCgoEc25pZBICMzMSBAjquAIaDjE3My4yNTQuMjUwLjgxIhRtaWNyb3NvZnQuc2hhcmVwb2ludCosZm15ZnJmK3VNUVg0eXF3andyUGRnR0FTbjNvSk5TVDRLRXBZS21mK3NFQT0weTgBShBoYXNoZWRwcm9vZnRva2VuYgR0cnVlcmEwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNhNzRhYTVjZGU2NDIwYjU2ODFhYTVjOTc3OTk2MWY5MGUzOTU1NGM5MTc0MjFkNjE4OGUxZTAyNjI1MGI2YTNiegEwwgFhMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYg.CTzoPGt6i07hxshHxV5IyW5X1CpF1dmbvBKGOwdRxV0&cTag=%22c%3A%7B53CE82A4-D908-40F3-9F2B-D518A92F8AE8%7D%2C1%22&encodeFailures=1&width=1024&height=1024&srcWidth=&srcHeight= HTTP/1.1Host: eastus1-mediap.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: unknown HTTP traffic detected: POST /personal/dmiller_retinatulsa_com/_api/v2.1/graphql HTTP/1.1Host: tulsaretina-my.sharepoint.comConnection: keep-aliveContent-Length: 507sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"accept: application/json;odata=verboseContent-Type: application/json;odata=verboseX-ServiceWorker-Strategy: CacheFirstsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Origin: https://tulsaretina-my.sharepoint.comSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2E3NGFhNWNkZTY0MjBiNTY4MWFhNWM5Nzc5OTYxZjkwZTM5NTU0YzkxNzQyMWQ2MTg4ZTFlMDI2MjUwYjZhM2IsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYTc0YWE1Y2RlNjQyMGI1NjgxYWE1Yzk3Nzk5NjFmOTBlMzk1NTRjOTE3NDIxZDYxODhlMWUwMjYyNTBiNmEzYiwxMzM3NDI5MTI1MDAwMDAwMDAsMCwxMzM3NDM3NzM1MDQ1MDczNjUsMC4wLjAuMCwyNTgsYTA1YmQ5MTQtZTczMy00OTk2LWFmOTMtY2Q1ZGI1NWIwZmNkLCwsMmUzNTVkYTEtNzA4Ni02MDAwLWNhNjktNDQzYjE0N2NjYWUzLDJlMzU1ZGExLTcwODYtNjAwMC1jYTY5LTQ0M2IxNDdjY2FlMyx2SDVjaHBvQjFFMjNkL3Qzb2ZzaStnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTI1OTAsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLFAwTXJDV0tqSU1yZEh0VGZZeHI3a0ZKL2x4cEp0WWIrSVFJWU1kbEN4R3ZTY2Fad3Q5Ky81Vkd4YnZhU2llV2N4UitEU1VURWh0RDVUUElUZ0UzVXF0Y1g4ZUZqVlNRenJiT2tMTWVLSXA1eE91OWV3WW5KNGtYU1crMUdIeW9YYUV2NHp3NFRTa3hEZm5aMTEyck9WZXRiNXJUU2wzWkVjc1J5RWZiWm11dHpYSmdFcHhGMVRxVENhaXBFVEhOVUFLY2NmYXNQaEx0SHVSNzl3d0pGWlNmSUJSYjZZQmNzeldwbmdqalpQZUJrOXBqREtwc1YrbHhmMlV4V2k1TlEzenVvSlF4akNrMTlkakJrbzdCZ2pzSVRwQWlQWUlHUXk3eEloaG9nOVIxVkRnY3hRTjA2RG5VU2pza3BjalRjNVJYVWdmM0w3OWcwVVREWnVJcnZ3Zz09PC9TUD4=
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 25 Oct 2024 00:50:00 GMTContent-Type: text/htmlContent-Length: 27150Connection: closeServer: cloudflareCF-RAY: 8d7e35c30edf6b39-DFW
Source: chromecache_713.2.dr, chromecache_729.2.dr, chromecache_435.2.dr, chromecache_673.2.dr, chromecache_714.2.dr, chromecache_449.2.dr String found in binary or memory:
Source: chromecache_411.2.dr, chromecache_658.2.dr String found in binary or memory:
Source: chromecache_466.2.dr String found in binary or memory:
Source: chromecache_663.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_577.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_500.2.dr String found in binary or memory:
Source: chromecache_730.2.dr, chromecache_465.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_472.2.dr, chromecache_598.2.dr String found in binary or memory:
Source: chromecache_572.2.dr, chromecache_485.2.dr, chromecache_488.2.dr, chromecache_533.2.dr, chromecache_456.2.dr, chromecache_455.2.dr String found in binary or memory:
Source: chromecache_472.2.dr, chromecache_598.2.dr String found in binary or memory:
Source: chromecache_572.2.dr, chromecache_533.2.dr, chromecache_493.2.dr, chromecache_687.2.dr String found in binary or memory:
Source: chromecache_572.2.dr, chromecache_485.2.dr, chromecache_488.2.dr, chromecache_533.2.dr, chromecache_456.2.dr, chromecache_455.2.dr String found in binary or memory:
Source: chromecache_721.2.dr, chromecache_636.2.dr String found in binary or memory:
Source: chromecache_721.2.dr, chromecache_636.2.dr String found in binary or memory:
Source: chromecache_551.2.dr, chromecache_569.2.dr String found in binary or memory:
Source: chromecache_472.2.dr, chromecache_598.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_692.2.dr, chromecache_720.2.dr String found in binary or memory:
Source: chromecache_449.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_551.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_551.2.dr, chromecache_477.2.dr String found in binary or memory:
Source: chromecache_477.2.dr String found in binary or memory:
Source: chromecache_410.2.dr, chromecache_564.2.dr, chromecache_477.2.dr String found in binary or memory:
Source: chromecache_477.2.dr String found in binary or memory:
Source: chromecache_410.2.dr, chromecache_564.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_551.2.dr, chromecache_477.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_577.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_576.2.dr String found in binary or memory:
Source: chromecache_485.2.dr, chromecache_456.2.dr String found in binary or memory:
Source: chromecache_487.2.dr, chromecache_696.2.dr, chromecache_716.2.dr, chromecache_565.2.dr String found in binary or memory:
Source: chromecache_500.2.dr String found in binary or memory:
Source: chromecache_569.2.dr String found in binary or memory:$
Source: chromecache_551.2.dr String found in binary or memory:
Source: chromecache_569.2.dr String found in binary or memory:$
Source: chromecache_551.2.dr String found in binary or memory:
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: classification engine Classification label:
Source: chromecache_720.2.dr Initial sample:
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2044,i,2214216025922011460,6580258473650715008,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" ""
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2044,i,2214216025922011460,6580258473650715008,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected

Persistence and Installation Behavior

Source: LLM: Page contains button: 'VIEW DOCUMENT' Source: '3.5.pages.csv'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 692 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 720
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 720 Jump to dropped file
Source: chromecache_422.2.dr, chromecache_516.2.dr, chromecache_527.2.dr Binary or memory string: ",ConnectVirtualMachine:"
Source: chromecache_422.2.dr, chromecache_516.2.dr, chromecache_527.2.dr Binary or memory string: ",DisconnectVirtualMachine:"
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs