Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOu

Overview

General Information

Sample URL:https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext
Analysis ID:1558885
Infos:

Detection

HTMLPhisher
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Antivirus / Scanner detection for submitted sample
Suricata IDS alerts for network traffic
Yara detected HtmlPhish54
Detected suspicious crossdomain redirect
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
HTTP GET or POST without a user agent
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6896 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 7084 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1968,i,18413991459941374636,2457918619707442337,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 6644 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
1.3.id.script.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
    2.2.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
      No Sigma rule has matched
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-11-19T22:35:50.685627+010028570901Successful Credential Theft Detected209.38.247.52443192.168.2.1749705TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering

      Phishing

      barindex
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#Joe Sandbox AI: Score: 8 Reasons: The brand 'Magellan' is associated with Magellan Health, a known healthcare company., The URL '00c5488c-de5da622.kumovers.com' does not match the legitimate domain 'magellanhealth.com'., The domain 'kumovers.com' is not associated with Magellan Health., The presence of a UUID-like string '00c5488c-de5da622' in the subdomain is unusual and suspicious., The URL structure suggests a potential phishing attempt due to the mismatch with the known brand's domain. DOM: 3.5.pages.csv
      Source: Yara matchFile source: 1.3.id.script.csv, type: HTML
      Source: Yara matchFile source: 2.2.pages.csv, type: HTML
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: Number of links: 1
      Source: https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$HTTP Parser: Base64 decoded: a[href="http://www.salidzini.lv/"][style="display: block; width: 120px; height: 40px; overflow: hidden; position: relative;"]
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: Title: magellanlp - Sign In does not match URL
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: Iframe src: https://login-okta.kumovers.com/discovery/iframe.html
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: Iframe src: https://login-okta.kumovers.com/discovery/iframe.html
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: Iframe src: https://login-okta.kumovers.com/discovery/iframe.html
      Source: https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$HTTP Parser: No favicon
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No favicon
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No <meta name="author".. found
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No <meta name="author".. found
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No <meta name="author".. found
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No <meta name="copyright".. found
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No <meta name="copyright".. found
      Source: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#HTTP Parser: No <meta name="copyright".. found
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
      Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49709 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49727 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49729 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 20.190.159.68:443 -> 192.168.2.17:49742 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49743 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 2.23.209.189:443 -> 192.168.2.17:49760 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49766 version: TLS 1.2

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2857090 - Severity 1 - ETPRO PHISHING JS/PsyduckPockeball Payload Inbound : 209.38.247.52:443 -> 192.168.2.17:49705
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: www.google.ie to http://transcabrera.com/yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bwfyay5ty2tlbnppzubtywdlbgxhbmxwlmnvbq==$
      Source: global trafficHTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
      Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
      Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
      Source: global trafficHTTP traffic detected: GET /url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$? HTTP/1.1Host: www.google.ieConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIksrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /amp/transcabrera.com/yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$? HTTP/1.1Host: www.google.ieConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlaHLAQiFoM0BCNy9zQEIksrNAQi5ys0BCLbLzQEI6dLNAQiK080BCMHUzQEIz9bNAQjj1s0BCI7XzQEIp9jNAQi62M0BCPnA1BUYuL/NARj2yc0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=519=xSNbthA1mH0WR7zk949MIkHsVKyJGX4_31XlITI_zHpuj6oe5izJl5gbOHwTBWX9tVemlNwQeiZSZRCgT5lls_8BPWrzT8UyyY69XQEBrk9PxbVDpwP2lhGnwzJ3TI2EiN4kenQdufsqYy-7bAQBoxdFhda469ofJmas607PswWnS2ejEleNyuXjW3HjO8c
      Source: global trafficHTTP traffic detected: GET /yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$ HTTP/1.1Host: transcabrera.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: transcabrera.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://transcabrera.com/yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$ HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://transcabrera.com/yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XH7uDNN191FGgun&MD=ace9Pcrg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
      Source: global trafficHTTP traffic detected: GET /?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$ HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.js HTTP/1.1Host: 3c5a958a-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://djhdknfkfnkfjkfnf.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://djhdknfkfnkfjkfnf.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://djhdknfkfnkfjkfnf.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: 3qo4lcQXNS1vQQY40LeEKg==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.js HTTP/1.1Host: 3c5a958a-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$&sso_reload=true HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://djhdknfkfnkfjkfnf.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1Sec-WebSocket-Key: ad6GMhDXrPhrl/9t+TVoIA==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2 HTTP/1.1Host: 00c5488c-de5da622.kumovers.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://djhdknfkfnkfjkfnf.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
      Source: global trafficHTTP traffic detected: GET /api/internal/brand/theme/style-sheet?touch-point=SIGN_IN_PAGE&v=0c87dd7c98ddc6357b84282899638428bbdf1fc84909aed3df3b474c8f376dd3ef084354afcd8447c32e0cf7d2b6de79 HTTP/1.1Host: 00c5488c-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.css HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.css HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/js/okta-sign-in.min.js HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /fs/bcg/4/gfs1iitj6mtRHwXoE1d8 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /fs/bco/1/fs0tjdpam4AAR2CqZ696 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /fs/bco/1/fs0tjdpam4AAR2CqZ696 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /fs/bcg/4/gfs1iitj6mtRHwXoE1d8 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/js/okta-sign-in.min.js HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.js HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /fs/bco/7/fs0tlth7zFaclj5Hj696 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/loginpage/font/assets/Aeonik-Regular.c672e6fbaa411f5719f3.woff2 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://87fe9df4-de5da622.kumovers.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br
      Source: global trafficHTTP traffic detected: GET /assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.js HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /discovery/iframe.html HTTP/1.1Host: login-okta.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /fs/bco/7/fs0tlth7zFaclj5Hj696 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /lib/discoveryIframe-a869d3b07ebd94f8cfae.min.js HTTP/1.1Host: login-okta.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login-okta.kumovers.com/discovery/iframe.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/img/ui/forms/checkbox-sign-in-widget.png HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /idp/idx/introspect HTTP/1.1Host: 00c5488c-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/loginpage/font/assets/Inter-SemiBold.b5f0f109bc88052d4000.woff2 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://87fe9df4-de5da622.kumovers.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /assets/loginpage/font/assets/Inter-Regular.c8ba52b05a9ef10f4758.woff2 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://87fe9df4-de5da622.kumovers.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /lib/discoveryIframe-a869d3b07ebd94f8cfae.min.js HTTP/1.1Host: login-okta.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: iI7NvBkX4hK2juzRii6GIA==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: eRHbJXchAShGB1FE28AFEQ==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /client/config?cc=CH&setlang=en-CH HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-UserAgeClass: UnknownX-BM-Market: CHX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: -300X-DeviceID: 01000A41090080B6X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Search-TimeZone: Bias=300; StandardBias=0; TimeZoneKeyName=Eastern Standard TimeX-BM-Theme: 000000;0078d7X-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAWrIGbEKEyJ5cpVPjtjoWLysULzqm9PUxIWjWnSw/sBpKIcpy3pRN7wP09FcKZePE%2B6e1v5IcQK1CeDlwp5ee9/E1ge8wC848JQidXlthP5yURjrM3W0w1GH/ysSxgKEqMUCtVcuHddlYhNejUTrjc0md9jKWUrsv7yn38hxf%2BcOQcD93SR6zLMe0LfKG9FGZwbVmC3JVp5NswgCqQNDwcJp6LzPAwBEE2MuEIdtJva4fcd1rSf0TJFvkhDYTsaxpf7BYQ3d8S%2BeVp7dYiQKO/g6RVOsvJUxSH3jcNgBGpCDKm9ir6LfoPeteBvuM0ezCbvVXqt6cfU2Ct3JgeTO6LQQZgAAEGLE58aeSwUjYeiIdJ5qi9mwATW8TCUw9r57gSbI9g8stedhFfjv4anQU0ZdrMGFRuNDZ0YKWYW8ljiMEi7zvEp6gqi%2BEgN4czFqFJo%2Be1WdcvsBCgB0pWZjWBEWhgOw7SX/nilj2S98KglERbIsO0cwKDaw6VGM7zT/gYkRfdmZOsMhC4ifHYXi8zEQPjV20OpSXCNCHcy8iFkXTCVz5GaJjF1sfl5iU8zR%2BY8Qmyg6YpNYwwEp%2BM7eb5f730OtBNRxz83z8GQa4gXqCkdRppiFwm%2B5rNqfT%2BomO6CJbyIyxXMIdO6hf1UwEvGPgrMKUe5YyVALckxpLUTHbf226wS0wSqHgTiZRQ5YcshIsgnxS5msDJvxKZFtXSMbANFn7lzwv6jHm11kEuO/qrejoUOQEWKaqziZ8MpDrrWHtFol6otRMLM6GGqE9v9quhFt7Vd5YTVT8MQ1muvhsFLegLAURIETRjEQDVXmFohGUduvnZb%2ByTNzB/%2Bou8fN224M1juaS7e%2B9K7/u3QEyUBl2Cplb6LZ1Y8jNLTJ4NQkPrdGidbpYQEGCuUslyVtvqXn8N9pGMAfpsHYVp7IcRpfyBbBXtcB%26p%3DX-Agent-DeviceId: 01000A41090080B6X-BM-CBT: 1732052179User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045X-Device-isOptin: falseAccept-language: en-GB, en, en-USX-Device-Touch: falseX-Device-ClientSession: 07752558FB2A4FC88EDB108A5C67F8C2X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; MUID=4590362BB5CF472B95BBEDB3112D4B7B; MUIDB=4590362BB5CF472B95BBEDB3112D4B7B
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/img/ui/forms/checkbox-sign-in-widget.png HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /bc/image/fileStoreRecord?id=fs0119sohrXGdEDmE697 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://00c5488c-de5da622.kumovers.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: t9rl06kgNuioPfJ6LVvQeQ==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /bc/image/fileStoreRecord?id=fs0119sohrXGdEDmE697 HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: VvLd083D9og7G1dm9uxtmA==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=XH7uDNN191FGgun&MD=ace9Pcrg HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: hLzvNH2gOuouZx2n+qYQRw==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: F9un3gk8fUQblxUvlswtBg==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: gT/G8xp5VVWqi1DKnAPDzw==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: uudC+85UEH1juz/DciT2UQ==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: J5XDizMf96VSAqnxhiPjzg==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /auth/services/devicefingerprint HTTP/1.1Host: 00c5488c-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: iframeReferer: https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: VAujmsCZ/LIABGgKGEzMBQ==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/font/okticon.woff HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://00c5488c-de5da622.kumovers.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/img/icons/mfa/password_70x70.png HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /idp/idx/identify HTTP/1.1Host: 00c5488c-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="; ln=no@no.com
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/img/icons/identifier/user-icon.svg HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/img/icons/mfa/password_70x70.png HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /assets/js/sdk/okta-signin-widget/7.25.0/img/icons/identifier/user-icon.svg HTTP/1.1Host: 87fe9df4-de5da622.kumovers.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: +eMDNI4eaFFlEiR13arB+w==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: FZF47PyqhVZJ+20AxHUSHA==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficHTTP traffic detected: GET /de5da622bf084ff0b0c5db3b58bf1c67/ HTTP/1.1Host: login-okta.kumovers.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://login-okta.kumovers.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: iRfY7p="ZGU1ZGE2MjItYmYwOC00ZmYwLWIwYzUtZGIzYjU4YmYxYzY3OmY1MTFjNjIyLTNlMTQtNDc4YS04NWIxLWE5MDZhYmJkNTU3NA=="Sec-WebSocket-Key: lNfci6F2uZeNQicZdWHcbQ==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
      Source: global trafficDNS traffic detected: DNS query: www.google.ie
      Source: global trafficDNS traffic detected: DNS query: transcabrera.com
      Source: global trafficDNS traffic detected: DNS query: djhdknfkfnkfjkfnf.kumovers.com
      Source: global trafficDNS traffic detected: DNS query: www.google.com
      Source: global trafficDNS traffic detected: DNS query: 3c5a958a-de5da622.kumovers.com
      Source: global trafficDNS traffic detected: DNS query: 54e2ff44-de5da622.kumovers.com
      Source: global trafficDNS traffic detected: DNS query: 00c5488c-de5da622.kumovers.com
      Source: global trafficDNS traffic detected: DNS query: 87fe9df4-de5da622.kumovers.com
      Source: global trafficDNS traffic detected: DNS query: login-okta.kumovers.com
      Source: unknownHTTP traffic detected: POST /?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$ HTTP/1.1Host: djhdknfkfnkfjkfnf.kumovers.comConnection: keep-aliveContent-Length: 4996Cache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1Origin: https://djhdknfkfnkfjkfnf.kumovers.comContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 19 Nov 2024 21:36:06 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encodingcache-control: privatep3p: CP="DSP CUR OTPi IND OTRi ONL FIN"x-ms-request-id: fe049416-c3e9-4e51-8df5-e06a75204000x-ms-ests-server: 2.1.19343.4 - WEULR1 ProdSlicesreport-to: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://54e2ff44-de5da622.kumovers.com/api/report?catId=GW+estsfd+ams2"}]}nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}x-ms-srs: 1.Preferrer-policy: strict-origin-when-cross-originaccess-control-allow-origin: *access-control-allow-headers: *
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 19 Nov 2024 21:36:07 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encodingcache-control: privatep3p: CP="DSP CUR OTPi IND OTRi ONL FIN"x-ms-request-id: 7005279f-c740-4054-bf21-cc93185b1800x-ms-ests-server: 2.1.19343.4 - WEULR1 ProdSlicesreport-to: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://54e2ff44-de5da622.kumovers.com/api/report?catId=GW+estsfd+ams2"}]}nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}x-ms-srs: 1.Preferrer-policy: strict-origin-when-cross-originaccess-control-allow-origin: *access-control-allow-headers: *
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 19 Nov 2024 21:36:10 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeVary: Accept-Encodingcache-control: privatep3p: CP="DSP CUR OTPi IND OTRi ONL FIN"x-ms-request-id: d7028135-9ce1-4053-b100-94abc3201400x-ms-ests-server: 2.1.19343.4 - NEULR1 ProdSlicesreport-to: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://54e2ff44-de5da622.kumovers.com/api/report?catId=GW+estsfd+ams2"}]}nel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}x-ms-srs: 1.Preferrer-policy: strict-origin-when-cross-originaccess-control-allow-origin: *access-control-allow-headers: *
      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
      Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
      Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
      Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
      Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
      Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
      Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
      Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
      Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
      Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
      Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
      Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
      Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
      Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
      Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
      Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
      Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
      Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
      Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
      Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
      Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
      Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
      Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
      Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
      Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
      Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
      Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
      Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49709 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49727 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49729 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 20.190.159.68:443 -> 192.168.2.17:49742 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49743 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 2.23.209.189:443 -> 192.168.2.17:49760 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49766 version: TLS 1.2
      Source: classification engineClassification label: mal72.phis.win@19/61@26/7
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1968,i,18413991459941374636,2457918619707442337,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?"
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1968,i,18413991459941374636,2457918619707442337,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
      Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire Infrastructure1
      Drive-by Compromise
      Windows Management Instrumentation1
      Registry Run Keys / Startup Folder
      1
      Process Injection
      3
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      Registry Run Keys / Startup Folder
      1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
      Ingress Tool Transfer
      Traffic DuplicationData Destruction
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?0%Avira URL Cloudsafe
      https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?100%SlashNextCredential Stealing type: Phishing & Social Engineering
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA20%Avira URL Cloudsafe
      https://3c5a958a-de5da622.kumovers.com/shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.js0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.js0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/img/icons/identifier/user-icon.svg0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.css0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/js/okta-sign-in.min.js0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/loginpage/font/assets/Inter-SemiBold.b5f0f109bc88052d4000.woff20%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/fs/bcg/4/gfs1iitj6mtRHwXoE1d80%Avira URL Cloudsafe
      https://djhdknfkfnkfjkfnf.kumovers.com/favicon.ico0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/loginpage/font/assets/Inter-Regular.c8ba52b05a9ef10f4758.woff20%Avira URL Cloudsafe
      https://00c5488c-de5da622.kumovers.com/idp/idx/challenge/answer0%Avira URL Cloudsafe
      https://login-okta.kumovers.com/de5da622bf084ff0b0c5db3b58bf1c67/0%Avira URL Cloudsafe
      https://login-okta.kumovers.com/discovery/iframe.html0%Avira URL Cloudsafe
      https://transcabrera.com/favicon.ico0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/img/ui/forms/checkbox-sign-in-widget.png0%Avira URL Cloudsafe
      https://00c5488c-de5da622.kumovers.com/idp/idx/identify0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/fs/bco/1/fs0tjdpam4AAR2CqZ6960%Avira URL Cloudsafe
      https://login-okta.kumovers.com/lib/discoveryIframe-a869d3b07ebd94f8cfae.min.js0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/bc/image/fileStoreRecord?id=fs0119sohrXGdEDmE6970%Avira URL Cloudsafe
      https://00c5488c-de5da622.kumovers.com/auth/services/devicefingerprint0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/font/okticon.woff0%Avira URL Cloudsafe
      https://00c5488c-de5da622.kumovers.com/idp/idx/introspect0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.css0%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/loginpage/font/assets/Aeonik-Regular.c672e6fbaa411f5719f3.woff20%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/fs/bco/7/fs0tlth7zFaclj5Hj6960%Avira URL Cloudsafe
      https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$&sso_reload=true0%Avira URL Cloudsafe
      https://54e2ff44-de5da622.kumovers.com/api/report?catId=GW+estsfd+ams20%Avira URL Cloudsafe
      https://djhdknfkfnkfjkfnf.kumovers.com/de5da622bf084ff0b0c5db3b58bf1c67/0%Avira URL Cloudsafe
      https://00c5488c-de5da622.kumovers.com/api/internal/brand/theme/style-sheet?touch-point=SIGN_IN_PAGE&v=0c87dd7c98ddc6357b84282899638428bbdf1fc84909aed3df3b474c8f376dd3ef084354afcd8447c32e0cf7d2b6de790%Avira URL Cloudsafe
      https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/img/icons/mfa/password_70x70.png0%Avira URL Cloudsafe
      NameIPActiveMaliciousAntivirus DetectionReputation
      www.google.ie
      172.217.16.195
      truefalse
        high
        djhdknfkfnkfjkfnf.kumovers.com
        209.38.247.52
        truefalse
          high
          54e2ff44-de5da622.kumovers.com
          209.38.247.52
          truetrue
            unknown
            transcabrera.com
            207.210.229.228
            truefalse
              unknown
              www.google.com
              142.250.185.164
              truefalse
                high
                login-okta.kumovers.com
                209.38.247.52
                truefalse
                  high
                  00c5488c-de5da622.kumovers.com
                  209.38.247.52
                  truefalse
                    high
                    87fe9df4-de5da622.kumovers.com
                    209.38.247.52
                    truefalse
                      high
                      3c5a958a-de5da622.kumovers.com
                      209.38.247.52
                      truefalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        https://djhdknfkfnkfjkfnf.kumovers.com/favicon.icotrue
                        • Avira URL Cloud: safe
                        unknown
                        https://87fe9df4-de5da622.kumovers.com/assets/js/mvc/loginpage/initLoginPage.pack.58de3be0c9b511a0fdfd7ea4f69b56fc.jstrue
                        • Avira URL Cloud: safe
                        unknown
                        https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2true
                        • Avira URL Cloud: safe
                        unknown
                        https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/js/okta-sign-in.min.jstrue
                        • Avira URL Cloud: safe
                        unknown
                        https://3c5a958a-de5da622.kumovers.com/shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.jstrue
                        • Avira URL Cloud: safe
                        unknown
                        https://87fe9df4-de5da622.kumovers.com/assets/loginpage/font/assets/Inter-SemiBold.b5f0f109bc88052d4000.woff2true
                        • Avira URL Cloud: safe
                        unknown
                        https://00c5488c-de5da622.kumovers.com/app/office365/exk177x2glprLjvIp697/sso/wsfed/passive?login_hint=mark.mckenzie%40magellanlp.com&client-request-id=93b0a0fa-c150-42e3-8d5a-a6dcdac8441c&username=mark.mckenzie%40magellanlp.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAR-LdgwOeDgY6feqGV3bp1wkVnFqEzYCP0LjIwvGBknMcnkJhZl6-UmZ6fmVWWmOuQmpqfm5CTm5RSAVN1iEvQvSvdMCS92S01JLUosyczPe8SMV8sFFoFXLDwGzFYcHFwCDBIMCgw_WBgXsQLd-U_yhZRQX7DLqse98w2cnBhOsep755qlu4fpu2dmG7kZ-VpWVHkGmmQmGlqEhPlXmbkGZZT4aBtE5pckm2Tl25pbGU5gE5rAxnSKjeEDG2MHO8MsdoYDnIwHeBl-8DXf-fd60ZxD7zw2CDA8EGAAAA2#true
                          unknown
                          https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/css/okta-sign-in.min.csstrue
                          • Avira URL Cloud: safe
                          unknown
                          https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$false
                            unknown
                            https://87fe9df4-de5da622.kumovers.com/assets/loginpage/font/assets/Inter-Regular.c8ba52b05a9ef10f4758.woff2true
                            • Avira URL Cloud: safe
                            unknown
                            https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/img/icons/identifier/user-icon.svgtrue
                            • Avira URL Cloud: safe
                            unknown
                            https://87fe9df4-de5da622.kumovers.com/fs/bcg/4/gfs1iitj6mtRHwXoE1d8true
                            • Avira URL Cloud: safe
                            unknown
                            https://00c5488c-de5da622.kumovers.com/idp/idx/challenge/answertrue
                            • Avira URL Cloud: safe
                            unknown
                            https://login-okta.kumovers.com/discovery/iframe.htmltrue
                            • Avira URL Cloud: safe
                            unknown
                            https://www.google.ie/amp/transcabrera.com/yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?false
                              high
                              https://login-okta.kumovers.com/de5da622bf084ff0b0c5db3b58bf1c67/true
                              • Avira URL Cloud: safe
                              unknown
                              https://transcabrera.com/favicon.icofalse
                              • Avira URL Cloud: safe
                              unknown
                              https://87fe9df4-de5da622.kumovers.com/fs/bco/1/fs0tjdpam4AAR2CqZ696true
                              • Avira URL Cloud: safe
                              unknown
                              https://login-okta.kumovers.com/lib/discoveryIframe-a869d3b07ebd94f8cfae.min.jstrue
                              • Avira URL Cloud: safe
                              unknown
                              https://87fe9df4-de5da622.kumovers.com/bc/image/fileStoreRecord?id=fs0119sohrXGdEDmE697true
                              • Avira URL Cloud: safe
                              unknown
                              https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/img/ui/forms/checkbox-sign-in-widget.pngtrue
                              • Avira URL Cloud: safe
                              unknown
                              https://00c5488c-de5da622.kumovers.com/auth/services/devicefingerprinttrue
                              • Avira URL Cloud: safe
                              unknown
                              https://transcabrera.com/yaya/37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$false
                                unknown
                                https://00c5488c-de5da622.kumovers.com/idp/idx/identifytrue
                                • Avira URL Cloud: safe
                                unknown
                                https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/font/okticon.wofftrue
                                • Avira URL Cloud: safe
                                unknown
                                https://87fe9df4-de5da622.kumovers.com/assets/loginpage/css/loginpage-theme.c8c15f6857642c257bcd94823d968bb1.csstrue
                                • Avira URL Cloud: safe
                                unknown
                                https://00c5488c-de5da622.kumovers.com/idp/idx/introspecttrue
                                • Avira URL Cloud: safe
                                unknown
                                https://djhdknfkfnkfjkfnf.kumovers.com/?nf=bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$&sso_reload=truetrue
                                • Avira URL Cloud: safe
                                unknown
                                https://87fe9df4-de5da622.kumovers.com/assets/loginpage/font/assets/Aeonik-Regular.c672e6fbaa411f5719f3.woff2true
                                • Avira URL Cloud: safe
                                unknown
                                https://87fe9df4-de5da622.kumovers.com/fs/bco/7/fs0tlth7zFaclj5Hj696true
                                • Avira URL Cloud: safe
                                unknown
                                https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?false
                                  high
                                  https://djhdknfkfnkfjkfnf.kumovers.com/de5da622bf084ff0b0c5db3b58bf1c67/true
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://54e2ff44-de5da622.kumovers.com/api/report?catId=GW+estsfd+ams2true
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://00c5488c-de5da622.kumovers.com/api/internal/brand/theme/style-sheet?touch-point=SIGN_IN_PAGE&v=0c87dd7c98ddc6357b84282899638428bbdf1fc84909aed3df3b474c8f376dd3ef084354afcd8447c32e0cf7d2b6de79true
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://87fe9df4-de5da622.kumovers.com/assets/js/sdk/okta-signin-widget/7.25.0/img/icons/mfa/password_70x70.pngtrue
                                  • Avira URL Cloud: safe
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  209.38.247.52
                                  djhdknfkfnkfjkfnf.kumovers.comUnited States
                                  7018ATT-INTERNET4USfalse
                                  239.255.255.250
                                  unknownReserved
                                  unknownunknownfalse
                                  142.250.185.164
                                  www.google.comUnited States
                                  15169GOOGLEUSfalse
                                  207.210.229.228
                                  transcabrera.comUnited States
                                  36024AS-TIERP-36024USfalse
                                  172.217.16.195
                                  www.google.ieUnited States
                                  15169GOOGLEUSfalse
                                  IP
                                  192.168.2.17
                                  192.168.2.18
                                  Joe Sandbox version:41.0.0 Charoite
                                  Analysis ID:1558885
                                  Start date and time:2024-11-19 22:35:18 +01:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 3m 55s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                  Sample URL:https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3D&sa=t&url=amp%2ftranscabrera.com%2fyaya%2f37w6telbuncxaji5ywvxeooxd1ok88ou67nhi/bWFyay5tY2tlbnppZUBtYWdlbGxhbmxwLmNvbQ==$?
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Number of analysed new started processes analysed:20
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Detection:MAL
                                  Classification:mal72.phis.win@19/61@26/7
                                  EGA Information:Failed
                                  HCA Information:
                                  • Successful, ratio: 100%
                                  • Number of executed functions: 0
                                  • Number of non-executed functions: 0
                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, TextInputHost.exe, svchost.exe
                                  • Excluded IPs from analysis (whitelisted): 216.58.206.67, 172.217.18.14, 173.194.76.84, 34.104.35.123, 192.229.221.95, 2.22.50.144, 142.250.181.238, 172.217.18.10, 172.217.16.202, 216.58.206.74, 142.250.186.106, 142.250.184.202, 142.250.185.74, 142.250.186.74, 142.250.186.42, 142.250.181.234, 216.58.212.138, 142.250.184.234, 172.217.23.106, 142.250.186.170, 142.250.186.138, 216.58.206.42, 142.250.185.106, 172.217.18.3, 87.248.202.1, 216.58.212.142, 172.217.18.106, 172.217.16.138, 142.250.185.234, 142.250.185.202, 142.250.185.170, 142.250.185.138
                                  • Excluded domains from analysis (whitelisted): www.bing.com, clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, login.live.com, evoke-windowsservices-tas.msedge.net, update.googleapis.com, clients.l.google.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                  • VT rate limit hit for: https://www.google.ie/url?q=queryy8px(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3AREGION%2Cvalues%3AList((id%3A103644278%2Ctext%3AUnited%2520States%2CselectionType%3AINCLUDED))))%2Ckeywords%3Aremote)&sessionId=5NTcRf4wT3OOZdAOuNu6%2FQ%3D%3Dquery(spellCorrectionEnabled%3Atrue%2CrecentSearchParam%3A(id%3A3891228890%2CdoLogHistory%3Atrue)%2Cfilters%3AList((type%3ARE
                                  No simulations