Click to jump to signature section
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The URL 'wfs.satsgroup.co' does not match the legitimate domain 'microsoft.com'., The domain 'satsgroup.co' does not have any known association with Microsoft., The presence of a subdomain 'wfs' and the main domain 'satsgroup.co' suggests a potential phishing attempt as it does not align with Microsoft's typical domain structure., The email domain 'ssyjwqx.net' in the input fields is unusual and not associated with Microsoft, which raises suspicion. DOM: 1.0.pages.csv |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: nferdinando@wfs.aero |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: Number of links: 0 |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: Invalid link: Forgot password? |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: Has password / email / username input fields |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: Form action: Awarenesslogin.php |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: <input type="password" .../> found |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: No favicon |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: No <meta name="author".. found |
Source: http://wfs.satsgroup.co/login.php?id=bmZlcmRpbmFuZG9Ad2ZzLmFlcm8= | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown | TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown | TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown | TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /s/jiGQCnr5DH7GvmPu9fVSJcV9l?domain=wfs.satsgroup.co HTTP/1.1Host: url.uk.m.mimecastprotect.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /r/l46Z77kEPQ0B4k1MwoMHIq3Ghcz8sA3RKdqFlOqNT0RqcpeBoPLAds4py8P25Hnpqm2F98ayEaBm0KRhFCsFt0Ds_l364DuWmn0lFgQxs5fMhhQTuEjO4BqoOokEpHLjKI2BhvaotczMTnWOpDhLbUvOcFe-A0YhNsp6Zvw4T5yAY4rPSC1TwIY51eZnAAymqMXtNcUmx39kc15G2xg6BG_e3apSkhPuQJZF3I-0DnHnRKebwWaHCrRc1WcPbP00tZxmqRyiQfXEhd2HuwhY_yXr_YTmTxQT0Z-O3Bpbi0vwexGli1Ln2DqfheqUaEXSjQybLTQh-9r1gfFGf9FqNWqyCy5veMMNDd0S6tDlj7ykDQGdWhLjYV2zbD_wrxKTeVAVvem9TiCR2jfVmXoHXFioxoS3UfIREwHfMLs3PRRxpYrv1DOPsKvmyj5LorQ7Lal3gxDHI07jg8QD8HViUUVdxWt5TSKU9dDbxogFrVBVXqaLGqzjMEQZXhSKv-oSt9sL1OW2vEWDhfLFC-03PCajPa0XB-wOiEi_B0VKz8b__W4YhkHdIbMtJvvqz8tWqyTUAScKFrHrFDL24lYBg6HG4PdVzFu0eLN57ogpnridZSq6-dHOa765jO4G2aVKThrouWF01ooVZwJmakHTJlC9jKob3DhnkrlEqVX_QScU8jQJfMU-RDBcbNUO9TwZGxNgV7B7Pvb4bdSx5S1MMv-T_Kb9J7ehqAaglHKekrWgeByDhxJsgwd4UO3p_v-4EjIma7osysuoUDioWYzsQeRQLNwPNfIzKFNvwUPDA1d1DBi1pLwiHRHHKjnHMku0uq1SyBElANKb-12I01UEuOIuPVqrAYbqrd-rKyzc5qx7lmRZ8T2eYRiWIuD9bOpOhQorCZ19nuephIKvA05Un9VscXecx2g9YEbFDzpAdJ5QpGJQyLBfiqwAxneIemZnl4ft7WBf9M46sTZmkND8Ln8dRtpxOQYDG8REg6rdrOY0TzMIW7Mzo_A2h1fLzK3AcHCF69R91_dF-5N8MftnYQDgws9fwkD3ni8ZIpl4EaL9XD9McT0bI08189lp1AH9G3lahZWLUCKkXtEqVjxmXCoFWjVjpfbcfJKAKJc5x8k8Me69KHoXLYXPCsaiMGCJcQdf60TltHN3WOn-Sm-ffhHA7sGho4Eu0B8PcHbd-OQePUpHbsKppeAv40mC7qWh46cIk32vpZPB4vWl20K3R_AsmCLs7n_5Drvp7jkMlQEnIQ8JH-tMm9r3fAO8DRBxWHhid_SWRPugKxOyG1ws6159UVVHQ0VBWvBr85J1VD2OT8vebwUBNvjbOBkXKbZPk34U42LV4P_wjEmdlnT9khfqvsHV1rxW6pHGV9e7lGUh-I4AP7tQYFGOCBvZnbDZQTxAcbHR5LuEE8-4Ms9tGJ7ChlWGP7ET2rkUNqDkpeTh8l3Q7TO22iKDmzI6TCAcMUhp5gDyaMQryHHt6dy_kyqk07-VDRg4fgpa5KROOMig1COqYxQdJ-ffRzbxs82PjyiS_s2SeEzu62MWt1vVCEiH3ix8_6XGHM2l8JjpR95KSyqZDgxDoaFfY90i-AguaRLowzmUiC1c0zyliMUxjhfxNtcMgtK_SJIisZY3EvjASpEuSr5x_FoIztxcxsGXd6X2fVj_bIekRP_YY6p5FV7cmqxKFJS3FpntKIn8km0CxDRfHe2jxMlhLauhQL4okW4P5IKrjQklz3c3Q9HvG7j552TG7hWAR76ExOS208bgzUPcZLSUXFRtEZI4mdWhfnp-BI03JT57wDhejIeF3chvnVZGQUhXeNlsrrMT4gLNdpBFsv2BJuurIf0MhoMSsBB6k4s6JG7iqoXvLpadpk-ba4xYG5tGtWlCh_-NvqElyhRYYYkBs40h3_ogyfvs15_-YHK9ZULwk3tPb5bB4JUIhuga4pgi8Nl1eOaIDDSgtS0KK_BTknadD0arPZ3wzmaXDNwKclGY2-J1Der3cRLYPJLG7dIgxqJjdH1rL7jdCPnA9UFu5eOYulaGyCyr HTTP/1.1Host: url.uk.m.mimecastprotect.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Us |