Click to jump to signature section
Source: https://www.rfp-documents.com/ | SlashNext: Label: Credential Stealing type: Phishing & Social Engineering |
Source: https://www.rfp-documents.com | Avira URL Cloud: Label: malware |
Source: 0.18.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://r5k.ljxfrbcb.ru/dqhqST/... High-risk script with multiple red flags: uses atob() for obfuscation, contains an encoded suspicious URL (*.ru domain), implements anti-debugging measures, uses document.write() for DOM manipulation, and contains heavily encoded/obfuscated content. The script also attempts to block defensive measures like dev tools and includes event listeners to prevent inspection. |
Source: 0.29.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://r5k.ljxfrbcb.ru/dqhqST/... High-risk script showing multiple suspicious behaviors: 1) Makes requests to a suspicious Russian domain (.ru) with an unusually long, seemingly random hostname, 2) Contains form data exfiltration via FormData POST, 3) Uses redirects to excel.office.com as a possible legitimate-looking fallback, 4) Implements Cloudflare Turnstile but appears to be using it maliciously, 5) Uses obfuscated/random-looking variable names and paths. The pattern suggests a sophisticated phishing or data theft attempt masquerading as legitimate Microsoft service. |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC9jbCQI5lTowYn3v1S20QLkCvJrX0ouzkju34ic51R8pswGDPibwTDBzQxQPX0VQ2f66IzW7DuOhoxr4LIW7TfC98G67QYOZ8QPPBI1fpTc1tyAA&jshs=2&jsh=&jshp=&username=fake.fake%40fake.com&login_hint=fake.fake%40fake.com | HTTP Parser: fake.fake@fake.com |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Number of links: 0 |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Number of links: 0 |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC... | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: https://www.rfp-documents.com/ | HTTP Parser: Base64 decoded: AIzaSyCBTROq6LuvF_IE1r46-T4AeTSV-0d7my8 |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Title: Redirecting does not match URL |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC... | HTTP Parser: Title: Sign in to your Microsoft account does not match URL |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC... | HTTP Parser: Iframe src: https://fpt.live.com?session_id=b82ae0266de847a38912a18a3642a987&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SI |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: <input type="password" .../> found |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC... | HTTP Parser: <input type="password" .../> found |
Source: https://r5k.ljxfrbcb.ru/dqhqST/ | HTTP Parser: No favicon |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No favicon |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&ui_locales=en-US&mkt=en-US&client-request-id=b82ae026-6de8-47a3-8912-a18a3642a987&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.live.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.office.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.microsoft365.com%2flandingv2&response_type=code+id_token&state=iZWu6ChVaD7vmWA1k75lVI0DUoAKH5BZgeUQUG35ssyHYPndkIHjsnxJPZ4jwJQO2uVJMrFcYQwn0tx713caSlpvjzjVQFFcfDKxFQ8v621lQt9Fxcyh0FFAs_hRl4EMBWdajv0EqsMwPuooU-JeT_KleHNnE1AhiJqRMHcO5HT6UIDsfWgUW8lPURxZhfCkA7ZJsGcFUNrPQ53stG5MniWqbvgw5XDyBeGecKyjj3zAdRZD2TpsQPukICYaCh-Tw1SK1rlwNO_z7YH2cxktVsNEo-Gvb88din_A_ZnIBWe8W60p-xTfjngXl4BUgc6wuEqR3XhH0rN5k8dPuAWO_A&response_mode=form_post&nonce=638691055113888370.MTNlZDAyZGEtNWQ4OS00NjU4LTk0MTEtOGZiNjNhY2Y2ZGFiY2VkZDIyMTktZDVlYy00MjNhLWFmODgtYTQ0OWQ0YjYzZjBh&x-client-SKU=ID_NET8_0&x-client-Ver=7.5.1.0&uaid=b82ae0266de847a38912a18a3642a987&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAADW6jl31mB3T7ugrWTT8pFe1308fuOLqptfzg23nf6OY37D8C77hBXsXRMPjo9m5cEJYH79pUghHFhnj_OQ75cH6v3Xs1t9IUuyXnzVDyJX3GsUphevuSc49Mdu6UAZC... | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 20.190.181.23:443 -> 192.168.2.17:49692 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49694 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 2.16.158.186:443 -> 192.168.2.17:49705 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.17:49708 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 2.16.229.162:443 -> 192.168.2.17:49716 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 2.16.229.162:443 -> 192.168.2.17:49717 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.17:49792 version: TLS 1.2 |
Source: global traffic | HTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br |
Source: Joe Sandbox View | IP Address: 13.107.246.63 13.107.246.63 |
Source: Joe Sandbox View | IP Address: 104.18.94.41 104.18.94.41 |
Source: Joe Sandbox View | IP Address: 151.101.0.237 151.101.0.237 |
Source: Joe Sandbox View | JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4 |
Source: Joe Sandbox View | JA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3 |
Source: Joe Sandbox View | JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.107.5.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.181.23 |
Source: global traffic | HTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br |
Source: global traffic | HTTP traffic detected: GET /client/config?cc=CH&setlang=en-CH HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-UserAgeClass: UnknownX-BM-Market: CHX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: -300X-DeviceID: 01000A41090080B6X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Search-TimeZone: Bias=300; StandardBias=0; TimeZoneKeyName=Eastern Standard TimeX-BM-Theme: 000000;0078d7X-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAbwmgMpeMqyLcwi4%2BaXgrM4o12F3Iyrn6wfmpBovFTS%2BqG%2BJK1x82uA46M5S1Zo9mnUewu/ldDV%2B3Q4uMDhR5WIk%2BSBOzPtxv38vxAGZuU7gBQ4GbS4NXVmPA0zFBRmpsuAwASMI528EKAslipNxhpWLojH7NAZrn8NndAXk9H6KnA6rX6DPsptdoUOefPENWp3aVfXsfAL1N2u9NL6vX7lDAm5sPEOQHY8SxFrg0ppXA0YG6p6XYV3FtQiJ8a1WrNWOfLpUNo6Pl/NJIUEFN7AfGRzRLamXHBKZaSG15bdah465WyGVbCBiihL5dfWGunN1R93kCkJ9hy6Pc/HjgBsQZgAAEDJ3k7wPtDm/wMxpP/4NwhawAY80RL6OIC3m42P6ivM4Q7swz1Fp9xIPUAYsGNozHSAd24wd8QO2i%2BBybaeKkfZKG6wMp42drGNT1FHfHEm0Po0IcxxoDy9P2gWYCnWblsXO5Kqb4Bfnkqm6YsrLUPVZcpyHE1N9Wm%2BXy5ybnlU8kYKwbsxlEe1MrVJMN%2BRsX3XLKtxJk1tU%2BxlwpxxZr0XW1bwGEZpaJf3ktzqHU/7P4xUAE0IC/E%2Bsj0o9T3r/g%2BB%2BlLMgQjbS046HrL7SAlB1keymrK%2BU/nUNCsNDicDXT2A8p4fxJSPEjS5pTF4UcVkf6uX83b9b0bvJM8kK/eLKZql3%2BSJ7NRBX0s2dK2KHB1U2xBMqsu1Lh7KwWBGgx9aV7QZ2ZwTKS3Hej6Z5TUX/1oS7LcFT6pFz4Y/NJ2kNbsrRabVC2/9bv0oFYU9wn30xnmMLhC9JfJxMUU8PqtbwRM92q/6fw1rE6H226Dpio9tvld8zBpJYtAFVlwfa7yMOBtYf34G6HtSJouPuZ0vYwMuvfiT7DkHrV9WQrS7%2Bpcf3ZSiCoy5hZ%2B6Yz5L1uU97InlmEGbCgQr4SDZEo/Bkv9gB%26p%3DX-Agent-DeviceId: 01000A41090080B6X-BM-CBT: 1733508630User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045X-Device-isOptin: falseAccept-language: en-GB, en, en-USX-Device-Touch: falseX-Device-ClientSession: 7EA1F92E2F2941C7B6D05AC70053D1CBX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; MUID=4590362BB |