Click to jump to signature section
Source: https://1drv.ms/w/c/17cc1e7b64547fa0/ER4uyAUCto9GkfZ_Sw-4_NAB9TeJj_jWV9oRzb3kdQINFQ?e=4%3aaVtPRh&sharingv2=true&fromShare=true&at=9 | SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering |
Source: https://ivfqcze9jpywgexhiy1ev9zzqhigpjadjigpjmdm1kbev6ftctv6ybfkt5ej.lpliwptf.ru/choqmnpnjiwpotfzqbXzTLDBQdlXDXJCVGMCWEVKGVHWSZRTWLDCYXMIYUFOVGKDVIOKEBBWGGQBNPKDXI | Avira URL Cloud: Label: malware |
Source: 0.73.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://uoqp.foadinexer.ru/Kkw5r3/... This script demonstrates several high-risk behaviors, including detecting the presence of web automation tools, disabling common browser debugging and developer tools, and redirecting the user to an external domain. The combination of these behaviors suggests a malicious intent to prevent analysis and potentially compromise the user's system. |
Source: 0.70.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://uoqp.foadinexer.ru/Kkw5r3/... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated code and the presence of anti-debugging techniques further increase the risk. Overall, this script demonstrates a high likelihood of malicious intent and should be treated with caution. |
Source: 0.74.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://uoqp.foadinexer.ru/Kkw5r3/... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated URLs and the interaction with untrusted domains further increase the risk. While the script may have some legitimate functionality, the overall behavior is highly suspicious and indicative of potential malicious intent. |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Number of links: 0 |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Number of links: 0 |
Source: https://onedrive.live.com/personal/17cc1e7b64547fa0/_layouts/15/Doc.aspx?sourcedoc=%7B05c82e1e-b602-468f-91f6-7f4b0fb8fcd0%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_ZT00OmFWdFBSaCZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=24886ea1-70e2-7000-1508-6a946bae7d0b&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_cnRpbWU9S29nS2F0b2UzVWc&CID=dffede72-4382-4548-a4e8-d3b7d7a6a9d1&_SRM=0:G:33 | HTTP Parser: Base64 decoded: {"siteid":"99f0858d-7028-49f5-89ab-c8bf3e3a1e91","aud":"00000003-0000-0ff1-ce00-000000000000/onedrive.live.com@9188040d-6c67-4c5b-b112-36a304b66dad","exp":"1734896160"} |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Title: Redirecting does not match URL |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Iframe src: https://login.live.com/Me.htm?v=3 |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: <input type="password" .../> found |
Source: https://onedrive.live.com/personal/17cc1e7b64547fa0/_layouts/15/Doc.aspx?sourcedoc=%7B05c82e1e-b602-468f-91f6-7f4b0fb8fcd0%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_ZT00OmFWdFBSaCZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=24886ea1-70e2-7000-1508-6a946bae7d0b&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_cnRpbWU9S29nS2F0b2UzVWc&CID=dffede72-4382-4548-a4e8-d3b7d7a6a9d1&_SRM=0:G:33 | HTTP Parser: No favicon |
Source: https://uoqp.foadinexer.ru/Kkw5r3/ | HTTP Parser: No favicon |
Source: https://uoqp.foadinexer.ru/Kkw5r3/ | HTTP Parser: No favicon |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No favicon |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700646460581042.ZTRiNjdjOTgtYzRlZS00OGE3LThmNGEtNWI0NDEyNDY3YmM3ZjUxNjQ4MTQtY2JmYy00YjI2LWFmZmYtOGQ2OWVkOGM0NWFl&ui_locales=en-US&mkt=en-US&client-request-id=00253917-800b-45d0-91a3-4783e85958c2&state=eOzX7pIimQpGF6NtB_7dvTcUR03XxmAmKBnUvBgSu8kTbyD-ZZmfFHmqZlCByo43kq1cn40pJlea0jqQVTxjVLI_inMw83TYNbfXC22kFXFV3-eB17gX3mMX4NvI87OYOWX3y8qqjCAGq7viy2e0mro7Qnen15FlVvqe494Hbol74ELBuCzhgWi-GwoxZOq7uYUJ0if9Lmr_I3OL8iyNyna54STnJ6g8M2vPeQHl5jWWqpnHIAG5thk2xCODxj9UPJHAsEAIvbCosXXw-nmCoF25PKyIo5hSBbMiU2EDi_AHSE0vPaIuJz8iGgNg6jAcLsEOarrsfnLzCd1DSf_nrQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /w/c/17cc1e7b64547fa0/ER4uyAUCto9GkfZ_Sw-4_NAB9TeJj_jWV9oRzb3kdQINFQ?e=4%3aaVtPRh&sharingv2=true&fromShare=true&at=9 HTTP/1.1Host: 1drv.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /:w:/g/personal/17CC1E7B64547FA0/ER4uyAUCto9GkfZ_Sw-4_NAB9TeJj_jWV9oRzb3kdQINFQ?resid=17CC1E7B64547FA0!s05c82e1eb602468f91f67f4b0fb8fcd0&ithint=file%2cdocx&e=4%3aaVtPRh&sharingv2=true&fromShare=true&at=9&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_ZT00OmFWdFBSaCZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05 HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /personal/17cc1e7b64547fa0/_layouts/15/Doc.aspx?sourcedoc=%7B05c82e1e-b602-468f-91f6-7f4b0fb8fcd0%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_ZT00OmFWdFBSaCZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=24886ea1-70e2-7000-1508-6a946bae7d0b&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_cnRpbWU9S29nS2F0b2UzVWc&CID=dffede72-4382-4548-a4e8-d3b7d7a6a9d1&_SRM=0:G:33 HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2FkYzI3MDQ5YjllYmJiMjY4NjY5NTgwYjNlM2I1NzlmMWFlNDQ1YTBhZjM3ZjlmMzViYjMyODVjODgyMjQzYjQsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYWRjMjcwNDliOWViYmIyNjg2Njk1ODBiM2UzYjU3OWYxYWU0NDVhMGFmMzdmOWYzNWJiMzI4NWM4ODIyNDNiNCwxMzM3ODk0MTY1ODAwMDAwMDAsMCwxMzM3OTAyNzc1ODY5NDQ4MTksMC4wLjAuMCwyNTgsOTE4ODA0MGQtNmM2Ny00YzViLWIxMTItMzZhMzA0YjY2ZGFkLCwsYzU0MDdmYjAtMTI1MS00ZjAyLWJjMmItODk2ZWMxOWUzMGY3LGM1NDA3ZmIwLTEyNTEtNGYwMi1iYzJiLTg5NmVjMTllMzBmNyxnK0pYTHF2U2hrYWxxdEVwSnpGdnVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTQwOTQsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLEMyU0dleTBPdzlib1VqK1I5QTFVM1F1NVpiNmgvTVdGOXQwbkZTeVRlcml3QjFlVFZNYnQ4cXM1N25vTExkNjhGNFFtQ2tldVcxaGY1d0dHYjcxcStNZ0ZIajh0djR1TENNeDVPUGlienh5dXhjM1NPNk1WMmpKYmlNR3RwSkZCKzYydWhrRnNGd0NWeHNGM3BQZlNObnRRak5LYkN1bDBGUHV5ZFM2ZEVpZUZoQUxRMFVydDY3aGh2TWs1a1ZpRjVRVnBxaVBoS0tQelVuZEIxU0RWTmo4cUlGbm5mdmNkN3BLRUxyZXI2Um1xR2toWEducm5iZFk2SUxCVzdOd0ttbWxVeU1vdG1WZk9zZTRrc1p2ZHhwUy9qRm9SaUhZc3ROT0hmNzZ0TmdRajNZYmpmQWFDajFPcEp2MlE3MmViUWJZaER6YW80K1g5SFBoLzc2U0w5Zz09PC9TUD4= |
Source: global traffic | HTTP traffic detected: GET /personal/17cc1e7b64547fa0/_api/v2.1/drives/b!jYXwmShw9UmJq8i_PjoekfvN232NuhNAvOZijfCiH_SuXF6pgvCvT56vRvtsTJbX/items/01CDPN6UI6F3EAKAVWR5DJD5T7JMH3R7GQ/streams/content_preview_Op1.img/streamContent?tempauth=v1e.eyJzaXRlaWQiOiI5OWYwODU4ZC03MDI4LTQ5ZjUtODlhYi1jOGJmM2UzYTFlOTEiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvb25lZHJpdmUubGl2ZS5jb21AOTE4ODA0MGQtNmM2Ny00YzViLWIxMTItMzZhMzA0YjY2ZGFkIiwiZXhwIjoiMTczNDg5NjE2MCJ9.-HPRGMgdEbPfX1gb4pvrWYijdsAkVX_ZA5-OnQQYSUUfetmSHrh70J9dY7OseRMAZVeancIfkQk_NnscPaGDrA7KXn3q0lkLHkbGw23I3aVIqxuMY42DeOiFqJyF5Axyy1Lqh-FU5KlsJ6EMTcQree_8phJ0l9wIoONDC3QlJPg7hlAKEmV80OCggqUuUxM-RHJjm5vuoitYJCFs7I6zRYvWVyjaiGJYRJqPzC6Y26J-1DZBkMtdYS4XQXohFC5oQrb6YPsTmXPMJ9Cjf11A7Fe4U5yYtt0SUUgUvOhMgZY7wknBIDQE5NJ-eGL4izKnyZ2NdsZLmN3npWLLXZUsMpOTyqwzImW8A0JIYNTXLIkAGeRErXUzVpv00QLqxrp1WOBS11jXLvYOeT7AogyOgu69-7Imdf4ugDAXnN5LfGN6KHeQPGkeI3xxhIcJ94mAf0XH2nsLhifyPGHOeiAXqnV9xXP2Ww3YsV2tkVxyb9JKfceKO1Wjgc2RaictKmPMM5e_mZ_9lGeLpnQlr02YVdO0TeQXIlswvIlkI8toK_s.4wHNydaHButF87W0IMnCoR2V83avYpAi7N1DE3BOuvY&usecachedssr=1&prefetchSSRCorrelationId=28886ea1-00ac-7000-62cb-bb8bcc0c0658 HTTP/1.1Host: onedrive.live.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://onedrive.live.com/personal/17cc1e7b64547fa0/_layouts/15/Doc.aspx?sourcedoc=%7B05c82e1e-b602-468f-91f6-7f4b0fb8fcd0%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_ZT00OmFWdFBSaCZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=24886ea1-70e2-7000-1508-6a946bae7d0b&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL3cvYy8xN2NjMWU3YjY0NTQ3ZmEwL0VSNHV5QVVDdG85R2tmWl9Tdy00X05BQjlUZUpqX2pXVjlvUnpiM2tkUUlORlE_cnRpbWU9S29nS2F0b2UzVWc&CID=dffede72-4382-4548-a4e8-d3b7d7a6a9d1&_SRM=0:G:33Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2FkYzI3MDQ5YjllYmJiMjY4NjY5NTgwYjNlM2I1NzlmMWFlNDQ1YTBhZjM3ZjlmMzViYjMyODVjODgyMjQzYjQsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24j |