Click to jump to signature section
Source: https://forms.office.com/Pages/ShareFormPage.aspx?id=z5Knz2h3QUOIV4F1TCr6H8l1dBxA_RZAr7lBOGCmz8VURUlLQURGTlFGTEQ0QzdESlFMT1lGUlpRWi4u&sharetoken=rKEHIuU7H8od3T6m0C0Z | SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'., The URL 'login.mlcloosoofttonliiiiine.com' contains misspellings and extra characters that resemble 'Microsoft', which is a common phishing tactic., The domain does not match the legitimate domain for Microsoft and includes suspicious elements such as unusual spelling and extra characters., The presence of input fields for 'Email, phone, or Skype' is typical for Microsoft services, but given the suspicious URL, it is likely a phishing attempt. DOM: 3.7.pages.csv |
Source: Yara match | File source: 0.18.id.script.csv, type: HTML |
Source: Yara match | File source: 0.30.i.script.csv, type: HTML |
Source: Yara match | File source: 2.3.pages.csv, type: HTML |
Source: Yara match | File source: 3.4.pages.csv, type: HTML |
Source: Yara match | File source: 3.6.pages.csv, type: HTML |
Source: Yara match | File source: 3.5.pages.csv, type: HTML |
Source: Yara match | File source: 3.7.pages.csv, type: HTML |
Source: 0.32.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://login.mlcloosoofttonliiiiine.com/common/oa... This script demonstrates several high-risk behaviors, including redirecting the user to an unknown domain and potentially collecting sensitive information (session ID) without transparency. The use of obfuscated code and the attempt to prevent the script from running in an iframe context further raise suspicions about the script's intent. While the script may have a legitimate purpose, the overall behavior and lack of transparency suggest a medium to high risk level that warrants further investigation. |
Source: 0.18.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://login.mlcloosoofttonliiiiine.com/common/oa... This script contains several high-risk indicators, including data exfiltration, redirects to suspicious domains, and obfuscated code/URLs. While some of the behavior may be legitimate (e.g., analytics, desktop SSO), the overall risk is elevated due to the presence of these concerning activities. |
Source: 0.25.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://login.mlcloosoofttonliiiiine.com/common/oa... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated URLs and the interaction with untrusted domains like 'live.mlcloosoofttonliiiiine.com' further increase the risk. Overall, this script demonstrates a clear intent to engage in malicious activities and should be considered a high-risk threat. |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Number of links: 0 |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Number of links: 0 |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Base64 decoded: 208ab303-ba2d-4904-a01c-092fa43c4458a84d64c5-23ff-4eed-b174-ebbf01157923 |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: Title: Redirecting does not match URL |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: Iframe src: https://live.mlcloosoofttonliiiiine.com/Me.htm?v=3 |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: <input type="password" .../> found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No favicon |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No <meta name="author".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="author".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /organizations/oauth2/v2.0/authorize/clientid4765445b32c649b083e61d93765276/638613561683610042OTY1ZWMzY HTTP/1.1Host: secure.office-auth.mlcloosoofttonliiiiine.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://forms.office.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://forms.office.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf |
Source: global traffic | HTTP traffic detected: GET /login HTTP/1.1Host: www.mlcloosoofttonliiiiine.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://forms.office.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf |
Source: global traffic | HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://forms.office.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf; fpc=Ar_2Q2S2Pg5Gl9SFWpOOLfI; esctx=PAQABBwEAAADW6jl31mB3T7ugrWTT8pFen-W7_ZtqoxQkuHooQOxSJ2xDWqENx3DtGYVn6pLf6qJAkWHT0qy-VYkwlk9_m2fKjjJ8ntc1N_rUjOnk9cOrn9ytPi4TlNb5wfQn0GcpXDlx6JhX66ThesWusT_uD7Xxwlm68HLnYA6fNmMQo-qabql-s2lKgHvBeZ5hei-beLwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd |
Source: global traffic | HTTP traffic detected: GET /s/554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf/817bdc1cc7873e1ecd7dbb25559005fb3aa0653d449d0d1955bebf482eecc584.js HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf; fpc=Ar_2Q2S2Pg5Gl9SFWpOOLfI; esctx=PAQABBwEAAADW6jl31mB3T7ugrWTT8pFen-W7_ZtqoxQkuHooQOxSJ2xDWqENx3DtGYVn6pLf6qJAkWHT0qy-VYkwlk9_m2fKjjJ8ntc1N_rUjOnk9cOrn9ytPi4TlNb5wfQn0GcpXDlx6JhX66ThesWusT_uD7Xxwlm68HLnYA6fNmMQo-qabql-s2lKgHvBeZ5hei-beLwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; esctx-sIA8wgLYHLU=AQABCQEAAADW6jl31mB3T7ugrWTT8pFe_z5kx8N7JMlmtKjxH8FwvMYgu1fsZ3FEBn44cgBJKIVUPWehAhy_KXFfSMLpmjjSttB48V23zco_SyytRnWI3qYSSfPgSa7QfxoS8A1PdLee7qVydyhQx_xi61IuF5igAXegAlHapL6f3RFRNTyR7iAA |
Source: global traffic | HTTP traffic detected: GET /s/554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf.js HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf; fpc=Ar_2Q2S2Pg5Gl9SFWpOOLfI; esctx=PAQABBwEAAADW6jl31mB3T7ugrWTT8pFen-W7_ZtqoxQkuHooQOxSJ2xDWqENx3DtGYVn6pLf6qJAkWHT0qy-VYkwlk9_m2fKjjJ8ntc1N_rUjOnk9cOrn9ytPi4TlNb5wfQn0GcpXDlx6JhX66ThesWusT_uD7Xxwlm68HLnYA6fNmMQo-qabql-s2lKgHvBeZ5hei-beLwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; esctx-sIA8wgLYHLU=AQABCQEAAADW6jl31mB3T7ugrWTT8pFe_z5kx8N7JMlmtKjxH8FwvMYgu1fsZ3FEBn44cgBJKIVUPWehAhy_KXFfSMLpmjjSttB48V23zco_SyytRnWI3qYSSfPgSa7QfxoS8A1PdLee7qVydyhQx_xi61IuF5igAXegAlHapL6f3RFRNTyR7iAA |
Source: global traffic | HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.mlcloosoofttonliiiiine.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.mlcloosoofttonliiiiine.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /s/554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf/817bdc1cc7873e1ecd7dbb25559005fb3aa0653d449d0d1955bebf482eecc584.js HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf; fpc=Ar_2Q2S2Pg5Gl9SFWpOOLfI; esctx=PAQABBwEAAADW6jl31mB3T7ugrWTT8pFen-W7_ZtqoxQkuHooQOxSJ2xDWqENx3DtGYVn6pLf6qJAkWHT0qy-VYkwlk9_m2fKjjJ8ntc1N_rUjOnk9cOrn9ytPi4TlNb5wfQn0GcpXDlx6JhX66ThesWusT_uD7Xxwlm68HLnYA6fNmMQo-qabql-s2lKgHvBeZ5hei-beLwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; esctx-sIA8wgLYHLU=AQABCQEAAADW6jl31mB3T7ugrWTT8pFe_z5kx8N7JMlmtKjxH8FwvMYgu1fsZ3FEBn44cgBJKIVUPWehAhy_KXFfSMLpmjjSttB48V23zco_SyytRnWI3qYSSfPgSa7QfxoS8A1PdLee7qVydyhQx_xi61IuF5igAXegAlHapL6f3RFRNTyR7iAA |
Source: global traffic | HTTP traffic detected: GET /s/554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf.js HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf; fpc=Ar_2Q2S2Pg5Gl9SFWpOOLfI; esctx=PAQABBwEAAADW6jl31mB3T7ugrWTT8pFen-W7_ZtqoxQkuHooQOxSJ2xDWqENx3DtGYVn6pLf6qJAkWHT0qy-VYkwlk9_m2fKjjJ8ntc1N_rUjOnk9cOrn9ytPi4TlNb5wfQn0GcpXDlx6JhX66ThesWusT_uD7Xxwlm68HLnYA6fNmMQo-qabql-s2lKgHvBeZ5hei-beLwgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; esctx-sIA8wgLYHLU=AQABCQEAAADW6jl31mB3T7ugrWTT8pFe_z5kx8N7JMlmtKjxH8FwvMYgu1fsZ3FEBn44cgBJKIVUPWehAhy_KXFfSMLpmjjSttB48V23zco_SyytRnWI3qYSSfPgSa7QfxoS8A1PdLee7qVydyhQx_xi61IuF5igAXegAlHapL6f3RFRNTyR7iAA |
Source: global traffic | HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true HTTP/1.1Host: login.mlcloosoofttonliiiiine.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://login.mlcloosoofttonliiiiine.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638700745458973596.MjA4YWIzMDMtYmEyZC00OTA0LWEwMWMtMDkyZmE0M2M0NDU4YTg0ZDY0YzUtMjNmZi00ZWVkLWIxNzQtZWJiZjAxMTU3OTIz&ui_locales=en-US&mkt=en-US&client-request-id=596e2536-c746-4553-92f3-8a624f7a08ef&state=Q0FnHn53wo5sL6uTjOI-7Ksju3iDdf8Iaiy8bv3QTtHod8eFPCpqcHoKQZVE5pB3FTi3pJ4LfwVz1cvuqfF2euem_Yfem20lCa0o5B4qdUGzXRy2dPyxfrX8HPtmIw2-gHKK2b-rexgYLhnRMJELAtX6Bi7Z8WPVhaGrczsCu3GQd1EsIqQPJXbqs_j1OT-Eg6g71aO7dN20ymZdzfDrFI7sUntLYkIXojJ1wGmY9Oihb4b6SFepIlVzOPNMJUUl6LEkpLlA1aTV9FBD8MPrBg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: 5fe5-5419=554d6b57dfef8303ab631738893fa37eb93d634d8241daea2573ae6097d4dcaf; fpc=Ar_2Q2S2Pg5Gl9SFWpOOLfI; esctx=PAQABBwEAAADW6jl31mB3T7ugrWTT8pFen-W7_ZtqoxQkuHooQOxSJ2xDWqENx3DtGYVn |