Click to jump to signature section
Source: file:///C:/Users/user/Desktop/securedoc_20241104T081116.html | LLM: Score: 10 Reasons: HTML file with login form DOM: 1.0.pages.csv |
Source: securedoc_20241104T081116.html | HTTP Parser: document.write |
Source: securedoc_20241104T081116.html | HTTP Parser: location.href |
Source: securedoc_20241104T081116.html | HTTP Parser: .location |
Source: securedoc_20241104T081116.html | HTTP Parser: .location |
Source: securedoc_20241104T081116.html | HTTP Parser: Subrogation <subrogation_svc@optum.com> |
Source: securedoc_20241104T081116.html | HTTP Parser: Secure Message from subrogation_svc@optum.com |
Source: file:///C:/Users/user/Desktop/securedoc_20241104T081116.html | HTTP Parser: {'name':null,'msgID':'|1__a74d4cff00000192f784015a956f8f48082d051c@mail10688.corpmailsvcs.com','keysize':24,'flags':3073,'rid':'ImxmcmFuY29AaGFpZ3JvdXAuY29tIiA8bGZyYW5jb0BoYWlncm91cC5jb20+','algnames':{'encryption':{'data':'AES'}},'algparams':{'encryption':{'data':{'IV':'KcAt6m7ewViKVN03X+bJAA=='}}},'keyserverhost':'res.cisco.com:443','securereplyhost':'res.cisco.com:443','openerhost':'res.cisco.com:443','toc':[['Body-1730729476447.txt',1,'','',13,[0,16417],'Body-1730729476447.txt','ISO-8859-1'],['attachment2024-11-04-09.11.10.pdf',2,'','attachment2024-11-04-09.11.10.pdf',5,[16417,66199],'attachment2024-11-04-09.11.10.pdf','ISO-8859-1'],['MessageBar.html',4,'','',1,[82616,33405],'MessageBar.html','ISO-8859-1']],'salt':'DTJqJGnNKxiWH++/QjzuDWHX1jc=','data':['','','']} |
Source: file:///C:/Users/user/Desktop/securedoc_20241104T081116.html | HTTP Parser: lfranco@haigroup.com |
Source: securedoc_20241104T081116.html | HTTP Parser: Base64 decoded: Zeppelin rules! |
Source: securedoc_20241104T081116.html | HTTP Parser: Title: Secure Registered Envelope:Secure Message from subrogation_svc@optum.com does not match URL |
Source: securedoc_20241104T081116.html | HTTP Parser: <input type="password" .../> found |
Source: securedoc_20241104T081116.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241104T081116.html | HTTP Parser: No favicon |
Source: securedoc_20241104T081116.html | HTTP Parser: No <meta name="author".. found |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49738 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49739 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49740 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49743 version: TLS 1.2 |
Source: global traffic | HTTP traffic detected: GET /envelopeopener/pf/ZGJAVG9rZW4zMzcxOjEzNTk2/gCVdrxCug0HP4HxHokZCk3cF0JvafI.XzHUADwopgIGs.rSMguUhFI8U9JQHbcRNYKMGS0RsPlbanESfOqNAyHGm0htzLfhZ9Q!!/?p=0&d=%7B%27name%27%3Anull,%0D%0A%27msgID%27%3A%27%7C1__a74d4cff00000192f784015a956f8f48082d051c%40mail10688%2Ecorpmailsvcs%2Ecom%27,%0D%0A%27keysize%27%3A24,%0D%0A%27flags%27%3A3073,%0D%0A%27rid%27%3A%27ImxmcmFuY29AaGFpZ3JvdXAuY29tIiA8bGZyYW5jb0BoYWlncm91cC5jb20%2B%27,%0D%0A%27algnames%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%27AES%27%7D%7D,%0D%0A%27algparams%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%7B%27IV%27%3A%27KcAt6m7ewViKVN03X%2BbJAA%3D%3D%27%7D%7D%7D,%0D%0A%27keyserverhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27securereplyhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27openerhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27toc%27%3A%5B%0D%0A%5B%27Body-1730729476447%2Etxt%27,1,%0D%0A%27%27,%0D%0A%27%27,%0D%0A13,%5B0,16417%5D,%27Body-1730729476447%2Etxt%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27attachment2024-11-04-09%2E11%2E10%2Epdf%27,2,%0D%0A%27%27,%0D%0A%27attachment2024-11-04-09%2E11%2E10%2Epdf%27,%0D%0A5,%5B16417,66199%5D,%27attachment2024-11-04-09%2E11%2E10%2Epdf%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27MessageBar%2Ehtml%27,4,%0D%0A%27%27,%0D%0A%27%27,%0D%0A1,%5B82616,33405%5D,%27MessageBar%2Ehtml%27,%0D%0A%27ISO-8859-1%27%5D%0D%0A%5D,%0D%0A%27salt%27%3A%27DTJqJGnNKxiWH%2B%2B%2FQjzuDWHX1jc%3D%27,%0D%0A%27data%27%3A%5B%0D%0A%27%27,%27VsMhLQ3SnIOj%2Fpx%2BZJ3qeBitZQoXHLamiificjDMUghbKKAIkTDpRGYGKiaH9JDOcnGKsFQJTdMTEV06z7ULIfw1ZTDFy9NtNP7c3Nw8iMDOUAM9c4HP9CeOU0Q5p16lrobXZ43pKCw1qTSYQexaurynIO3jxfcvePYMa5B0KCGCn%2Be%2FaFslddl2Qeur3om9XsJzuQoo5t9YMP9YFeAgWrbjjfGbUDXkd7YYDf1DCuKxCSTo61vnmBjvB8%2F0W38LNHqqCGOorHiZhaYh%2Bhg03NYEk%2FXivNWhNzfK6VHN0n8wbjlkwNkHKKec2x7itDFXv7gV33OAVneRYndOjb6u0F2Jnn%2BT7tXs72u%2F%2FItXHi5CXmTEBxHoulj1KNzgm%2FwBkz9zlrikxEXAWf4ZaT65xXF1s99ZUqO0PQfMAAL%2FDlNZ0%2BvY0qGZ%2B8OuX4WBTphxc2belL4DMNILerAtjtUE%2FvFpA7arFsH0HcCVZ83Fps42UcKw8pxGl8YYVMqoeM0Xdg%2BPojRowpxgeZlk%2FO71jeY1CGJ5c8137yquwyVfhI4H6qRJQIM1OJJf5hIoIoX7yrCb%2BqwVr3bReXEW3DUesfetxeHF5gfBlrPmW4K2pI7rzwiTfc9pKC%2FW0fGMVVaEoOJNVjcHsptmnShfjNHCcIn6MDWFsmALx%2FEhpUKSEhdGkTfUT8KsiktfxnMUKDlJ7KAaxe4phLdlhmLa%2Begk8xPRt3okwf2cfFotr0MoRouW3WRcRplYzCVAaeqIEhj7WSsORhctvH2j%2B8SQ08EWbGHtuuIqsJ5LK8e43JcRLX6Z5JOqF3EhbUgqIqsWNMEf4hsAaaPm8WnLVumOm3jAsId8RewE99TxiZLZ%2BfoOxpgYcig5T1nTfKgMo%2Bi%2FgpBywEWCfPeAK0XYXpSGik2aXyJGMJql3GqCnURc2ReowuD3fhIs%2B8THxsqv4awiGMIc5cigZN8qBjSMyb8WJQsLwNvZHaUmzzS |