Windows Analysis Report
https://acrobat.adobe.com/id/urn:aaid:sc:EU:4ba99727-806e-403b-9057-78ef5bf9d757

Overview

General Information

Sample URL: https://acrobat.adobe.com/id/urn:aaid:sc:EU:4ba99727-806e-403b-9057-78ef5bf9d757
Analysis ID: 1543811

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Detected hidden input values containing email addresses (often used in phishing pages)
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: lasflsdkfh@microsoft.com
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25... HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: Number of links: 0
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: Number of links: 0
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25... HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25... HTTP Parser: Base64 decoded: <?xml version="1.0" encoding="UTF-8"?><svg width="38px" height="38px" viewBox="0 0 38 38" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"> <!-- Generator: Sketch 44.1 (41455) - http://www.bohemiancoding.com...
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: Title: Redirecting does not match URL
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: Title: Sign In does not match URL
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25... HTTP Parser: <input type="password" .../> found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: <input type="password" .../> found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: <input type="password" .../> found
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25... HTTP Parser: No favicon
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: No favicon
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: No favicon
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No favicon
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No favicon
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No favicon
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2 HTTP Parser: No <meta name="author".. found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No <meta name="author".. found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No <meta name="author".. found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No <meta name="author".. found
Source: https://auth.services.adobe.com/en_US/index.html?callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2Fdc-prod-virgoweb%2FAdobeID%2Ftoken%3Fredirect_uri%3Dhttps%253A%252F%252Facrobat.adobe.com%252Fid%252Furn%253Aaaid%253Asc%253AEU%253A4ba99727-806e-403b-9057-78ef5bf9d757%2523old_hash%253D%2526from_ims%253Dtrue%253Fclient_id%253Ddc-prod-virgoweb%2526api%253Dauthorize%2526scope%253DAdobeID%252Copenid%252CDCAPI%252Cadditional_info.account_type%252Cadditional_info.optionalAgreements%252Cagreement_sign%252Cagreement_send%252Csign_library_write%252Csign_user_read%252Csign_user_write%252Cagreement_read%252Cagreement_write%252Cwidget_read%252Cwidget_write%252Cworkflow_read%252Cworkflow_write%252Csign_library_read%252Csign_user_login%252Csao.ACOM_ESIGN_TRIAL%252Cee.dcweb%252Ctk_platform%252Ctk_platform_sync%252Cab.manage%252Cadditional_info.incomplete%252Cadditional_info.creation_source%252Cadditional_info.roles%252Cpps.read%252Cupdate_profile.first_name%252Cupdate_profile.last_name%26state%3D%257B%2522ac%25... HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/72f988bf-86f1-41af-91ab-2d7cd011db47/saml2?SAMLRequest=nZJPb9swDMW%2FiqG7bEt2Y0eIU2QrihXo0Cxxd9iNlqhWgC1lphzs48%2FLH7S7FNiOhN7jo%2Fjj6vbX0CdHHMkF3zCR5ixBr4Nx%2FqVhz%2B09r9ntekUw9PKgNlN89Tv8OSHFZDZ6UueXhk2jVwHIkfIwIKmo1X7z9VHJNFeHMcSgQ8%2BSDRGOcY76HDxNA457HI9O4%2FPusWGvMR5IZZlFgyNENM5wDyKls4ZSMKHDVIfhTZL9yc%2F2%2B6cMegeUlaALkUvLobY5L62sOFQ4l6LQHRbVja6QJXfz%2FM5DPP35GtuHF%2BfTwekxULAx%2BN75c1ol7bKuO8vrhRW8FGD5UkDHpam0yYUwXVmdBpEsuQ%2BjxtOeGmahpznt4a5hm923Si6xNLN10UleSlvMTSrDZZF3pV2i6YrFrKUtELkjvrmJJnzwFMHHhslcllzkXNatKFReKXGTyrr4wZLtZcmfnD%2FD%2B4hIdxaR%2BtK2W7592rcs%2BX49glnALsjVKX18z%2FrjxnAFzNb%2Fj3PACAYi%2FAPTVfZ%2B3vWl%2FPti178B&RelayState=AW-QbqPqTq5qDIM6UmIOKmXfBtK9R9wyEdg9jaZQyRfemltcqP_e-HdU-AQ-nQrJu3ngQEECOC6B&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=W5RyHMqDA%2Bwf8lFMz%2FP2Pb353OcNx9cqisWXU0CP3Ep9nf2OCGq7oiBQuFj2WweOAX7nnyoC259oFJuhCfLkqDft5BhfnYxEMia5%2ByWxCIxoWLwxPV16LCusJs5FCxoMptHY5ohszzh3iUCO9OvQ0Wkwbx2tt3poPcW%2BKVdiNjm%2... HTTP Parser: No <meta name="copyright".. found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No <meta name="copyright".. found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No <meta name="copyright".. found
Source: https://msft.sts.microsoft.com/adfs/ls/?client-request-id=3c9f6203-1e72-47b0-b3d3-57eaeb6abec1&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAAvZE_aBNRAMbfmT-todXo1EkcRJD4cn9z7y5YMUmvaZpqckmPhCzy7t57ybV3SXN3MSm4uTiKi9JFLA4iCEUHQVDUsVPBzUmdJII4djROzjo4fvDB9-P3pUDe70XRTpjneUYJDXBEiUtgH4vZkAa3XIeGWUwGNs06A_9PhQ-x7_E-jTDBEeax5-KQV7Aji4LEINaYABUmIYgRnUVRdmwqo5yDaHA2lY7Zj64E5w7KLz-2pt-33r5_xvX-naHZrP3F_AfuYqFhIkmnCmFQV20JKhKToS4iAiVZsBWmU2LL6hHHfeO4TycSzdmItBfbKLSgaQ_rw81hbrhSua5afqVW9dusGFX1hj7eNUhX38Idc7fBqO9FzrB-k8I1YsGCCftmsD6S-13TMEq1klp8EbuAJKZrms2gpjIRKiKe0YjYhhJBDhFEkdgK-hpb8nDIvJBss94133WCQThg0W8LR_GFaXxBiOXn51NpsATOg-M4t5-YyX166cn-mY3nlTu3m8n7VwE4TPBGt5NzqTZSe6avahOz6bdHExYGvIS74Xpmh-qGmlkR3N2-uazmxXvJxcMk-Jnk7s6BvTnw-uR_e-fdIjg-9erhl8cPpm9-rE1PXy62XaGYKVlGQbmBKn2nuIpo3bLcsdmur5Y7TLaqk1Zr2-PL4-WDNPicBr8A0&cbcxt=&username=lasflsdkfh%40microsoft.com&mkt=&lc=&pullStatus=0 HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknown HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49785 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49981 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49724 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: adobe.tt.omtrdc.net
Source: global traffic DNS traffic detected: DNS query: use.typekit.net
Source: global traffic DNS traffic detected: DNS query: static.adobelogin.com
Source: global traffic DNS traffic detected: DNS query: prod.adobeccstatic.com
Source: global traffic DNS traffic detected: DNS query: p.typekit.net
Source: global traffic DNS traffic detected: DNS query: widget.uservoice.com
Source: global traffic DNS traffic detected: DNS query: l.betrad.com
Source: global traffic DNS traffic detected: DNS query: ims-na1.adobelogin.com
Source: global traffic DNS traffic detected: DNS query: files-download2.acrocomcontent.com
Source: global traffic DNS traffic detected: DNS query: dc-api-v2.adobecontent.io
Source: global traffic DNS traffic detected: DNS query: dc-api.adobecontent.io
Source: global traffic DNS traffic detected: DNS query: c.evidon.com
Source: global traffic DNS traffic detected: DNS query: by2.uservoice.com
Source: global traffic DNS traffic detected: DNS query: assets.adobedtm.com
Source: global traffic DNS traffic detected: DNS query: api.echosign.com
Source: global traffic DNS traffic detected: DNS query: cdn-sharing.adobecc.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: o4505393339695104.ingest.us.sentry.io
Source: global traffic DNS traffic detected: DNS query: dpm.demdex.net
Source: global traffic DNS traffic detected: DNS query: adobe-api.arkoselabs.com
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: identity.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauthimages.net
Source: global traffic DNS traffic detected: DNS query: dc.services.visualstudio.com
Source: unknown Network traffic detected: HTTP traffic on port 49890 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49986
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49985
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49983
Source: unknown Network traffic detected: HTTP traffic on port 49970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49982
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49981
Source: unknown Network traffic detected: HTTP traffic on port 49949 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49980
Source: unknown Network traffic detected: HTTP traffic on port 49932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49878 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49912 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49961 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49978
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49977
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49976
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49975
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49974
Source: unknown Network traffic detected: HTTP traffic on port 49950 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49973
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49851
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49972
Source: unknown Network traffic detected: HTTP traffic on port 49996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49971
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 49975 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49967 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49964 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49981 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49969
Source: unknown Network traffic detected: HTTP traffic on port 49978 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49968
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49967
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49845
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49965
Source: unknown Network traffic detected: HTTP traffic on port 49924 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49964
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49961
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49960
Source: unknown Network traffic detected: HTTP traffic on port 49947 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49972 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49989 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49930 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49986 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 49992 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49959
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 49921 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49955
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49954
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49953
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49950
Source: unknown Network traffic detected: HTTP traffic on port 49927 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49969 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49994 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49822 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49983 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49955 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50023 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49949
Source: unknown Network traffic detected: HTTP traffic on port 49941 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49948
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49822
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49941
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785
Source: unknown Network traffic detected: HTTP traffic on port 49922 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49813 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49974 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49968 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49785 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49939 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49965 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49980 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49939
Source: unknown Network traffic detected: HTTP traffic on port 49845 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49977 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49868 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49813
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49932
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49931
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49930
Source: unknown Network traffic detected: HTTP traffic on port 49925 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49891
Source: unknown Network traffic detected: HTTP traffic on port 49954 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49971 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49890
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50023
Source: unknown Network traffic detected: HTTP traffic on port 49988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49879 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49911 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49960 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49851 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49929
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49928
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49927
Source: unknown Network traffic detected: HTTP traffic on port 49991 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49925
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49924
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49922
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49921
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49920
Source: unknown Network traffic detected: HTTP traffic on port 49976 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49953 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49982 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49916
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49879
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49912
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49911
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49878
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 49948 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49891 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49996
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49994
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49992
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49991
Source: unknown Network traffic detected: HTTP traffic on port 49931 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49959 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49987 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49909
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49868
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49989
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49988
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49987
Source: unknown HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49785 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49981 version: TLS 1.2
Source: classification engine Classification label: clean3.win@24/106@75/459
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1868,i,4439810736099498213,6467326509262905189,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://acrobat.adobe.com/id/urn:aaid:sc:EU:4ba99727-806e-403b-9057-78ef5bf9d757"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1868,i,4439810736099498213,6467326509262905189,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5624 --field-trial-handle=1868,i,4439810736099498213,6467326509262905189,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4068 --field-trial-handle=1868,i,4439810736099498213,6467326509262905189,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5624 --field-trial-handle=1868,i,4439810736099498213,6467326509262905189,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4068 --field-trial-handle=1868,i,4439810736099498213,6467326509262905189,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs