URL: https://bitvavo.debak.nl Model: Joe Sandbox AI | {
"typosquatting": true,
"unusual_query_string": false,
"suspicious_tld": false,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": false,
"encoded_characters": false,
"redirection": false,
"contains_email_address": false,
"known_domain": false,
"brand_spoofing_attempt": true,
"third_party_hosting": true
} |
URL: https://bitvavo.debak.nl |
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-827... Model: Joe Sandbox AI | {
"risk_score": 7,
"reasoning": "This script demonstrates several high-risk behaviors, including redirecting the user to an unknown domain and potentially collecting sensitive information (session ID) without transparency. While the script may have a legitimate purpose, such as preventing unauthorized framing, the lack of context and the use of obfuscated code raise significant security concerns."
} |
//<![CDATA[
!function(){var e=window,s=e.document,i=e.$Config||{};if(e.self===e.top){s&&s.body&&(s.body.style.display="block")}else if(!i.allowFrame){var o,t,r,f,n,d;if(i.fAddTryCatchForIFrameRedirects){try{o=e.self.location.href,t=o.indexOf("#"),r=-1!==t,f=o.indexOf("?"),n=r?t:o.length,d=-1===f||r&&f>t?"?":"&",o=o.substr(0,n)+d+"iframe-request-id="+i.sessionId+o.substr(n),e.top.location=o}catch(e){}}else{o=e.self.location.href,t=o.indexOf("#"),r=-1!==t,f=o.indexOf("?"),n=r?t:o.length,d=-1===f||r&&f>t?"?":"&",
o=o.substr(0,n)+d+"iframe-request-id="+i.sessionId+o.substr(n),e.top.location=o}}}();
//
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-827... Model: Joe Sandbox AI | {
"risk_score": 6,
"reasoning": "The script appears to be handling authentication and authorization flows, which is a common and legitimate use case. However, it contains several indicators that require further review, such as the use of obfuscated URLs, the presence of fallback domains, and the transmission of user data to external servers. While the script may have a legitimate purpose, the lack of transparency and the potential for data exfiltration warrant a medium-risk score."
} |
//<![CDATA[
$Config={"iMaxStackForKnockoutAsyncComponents":10000,"fShowButtons":true,"urlCdn":"https://aadcdn.msauth.net/shared/1.0/","urlDefaultFavicon":"https://aadcdn.msauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico","urlPost":"/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04\u0026redirect_uri=https%3a%2f%2fbitvavo.debak.nl%2fsignin-oidc\u0026response_type=id_token\u0026scope=openid+profile\u0026response_mode=form_post\u0026nonce=638724075848211305.NjVhNDQ5NzktZGIxZC00N2MxLTliOTQtOTIwYjc4NTE4ZGNmYjIxM2QzNmYtNTc0MS00MDBmLTk5MDMtYjdlNDhlMjFmNTNm\u0026client_info=1\u0026x-client-brkrver=IDWeb.3.5.0.0\u0026state=CfDJ8NFo9WFn7g1OgcL5rhnSPxmWeUKHI5OS-B7l_lOlACRg1csUcE6qXMhzZ7dxJGFGghGStiXISuOCD_g47BFrkW8dc7BWNqoWOfLvSLyWzBQsSGkJBxhPlSolqDwKyFcgm-J8GaWHpzHzFzLniltLauFVPMp-zC-OAcHl1nolZaj2aEnuipHlqUwnK7zYPSTntT32_pXPvdcia1VErZAfWD1cFKL56cs5ENLg1Al_Prbb2LAS72XzHouYiuJPr8WJ-R489gDaWhC9l8jTMXtF_AE2PSsl2aQbGbA6pSPfCSgx\u0026x-client-SKU=ID_NET9_0\u0026x-client-ver=8.3.0.0\u0026client-request-id=858b4196-c6a6-42e5-857d-7aff1f1ac023\u0026sso_reload=True","iPawnIcon":0,"sPOST_
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-827... Model: Joe Sandbox AI | {
"risk_score": 3,
"reasoning": "The provided JavaScript snippet appears to be a utility library for managing asynchronous script loading and execution. It does not contain any high-risk indicators such as dynamic code execution, data exfiltration, or redirects to malicious domains. The script primarily focuses on handling document ready and load events, as well as providing a simple API for registering and executing scripts. While it uses some legacy practices like `XDomainRequest`, these pose minor risks and are not inherently malicious. Overall, this script seems to be a benign utility with no clear signs of malicious intent."
} |
//<![CDATA[
!function(){var e=window,r=e.$Debug=e.$Debug||{},t=e.$Config||{};if(!r.appendLog){var n=[],o=0;r.appendLog=function(e){var r=t.maxDebugLog||25,i=(new Date).toUTCString()+":"+e;n.push(o+":"+i),n.length>r&&n.shift(),o++},r.getLogs=function(){return n}}}(),function(){function e(e,r){function t(i){var a=e[i];if(i<n-1){return void(o.r[a]?t(i+1):o.when(a,function(){t(i+1)}))}r(a)}var n=e.length;t(0)}function r(e,r,i){function a(){var e=!!s.method,o=e?s.method:i[0],a=s.extraArgs||[],u=n.$WebWatson;try{
var c=t(i,!e);if(a&&a.length>0){for(var d=a.length,l=0;l<d;l++){c.push(a[l])}}o.apply(r,c)}catch(e){return void(u&&u.submitFromException&&u.submitFromException(e))}}var s=o.r&&o.r[e];return r=r||this,s&&(s.skipTimeout?a():n.setTimeout(a,0)),s}function t(e,r){return Array.prototype.slice.call(e,r?1:0)}var n=window;n.$Do||(n.$Do={"q":[],"r":[],"removeItems":[],"lock":0,"o":[]});var o=n.$Do;o.when=function(t,n){function i(e){r(e,a,s)||o.q.push({"id":e,"c":a,"a":s})}var a=0,s=[],u=1;"function"==typeof n||(a=n,
u=2);for(var c=u;c<arguments.length;c++){s.push(arguments[c])}t instanceof Array?e(t,i):i(t)},o.register=function(e,t,n){if(!o.r[e]){o.o.push(e);var i={};if(t&&(i.method=t),n&&(i.skipTimeout=n),arguments&&arguments.length>3){i.extraArgs=[];for(var a=3;a<arguments.length;a++){i.extraArgs.push(arguments[a])}}o.r[e]=i,o.lock++;try{for(var s=0;s<o.q.length;s++){var u=o.q[s];u.id==e&&r(e,u.c,u.a)&&o.removeItems.push(u)}}catch(e){throw e}finally{if(0===--o.lock){for(var c=0;c<o.removeItems.length;c++){
for(var d=o.removeItems[c],l=0;l<o.q.length;l++){if(o.q[l]===d){o.q.splice(l,1);break}}}o.removeItems=[]}}}},o.unregister=function(e){o.r[e]&&delete o.r[e]}}(),function(e,r){function t(){if(!a){if(!r.body){return void setTimeout(t)}a=!0,e.$Do.register("doc.ready",0,!0)}}function n(){if(!s){if(!r.body){return void setTimeout(n)}t(),s=!0,e.$Do.register("doc.load",0,!0),i()}}function o(e){(r.addEventListener||"load"===e.type||"complete"===r.readyState)&&t()}function i(){
r.addEventListener?(r.removeEventListener("DOMContentLoaded",o,!1),e.removeEventListener("load",n,!1)):r.attachEvent&&(r.detachEvent("onreadystatechange",o),e.detachEvent("onload",n))}var a=!1,s=!1;if("complete"===r.readyState){return void setTimeout(n)}!function(){r.addEventListener?(r.addEventListener("DOMContentLoaded",o,!1),e.addEventListener("load",n,!1)):r.attachEvent&&(r.attachEvent("onreadystatechange",o),e.attachEvent("onload",n))}()}(window,document),function(){function e(){
return f.$Config||f.ServerData||{}}function r(e,r){var t=f.$Debug;t&&t.appendLog&&(r&&(e+=" '"+(r.src||r.href||"")+"'",e+=", id:"+(r.id||""),e+=", async:"+(r.async||""),e+=", defer:"+(r.defer||"")),t.appendLog(e))}function t(){var e=f.$B;if(void 0===d){if(e){d=e.IE}else{var r=f.navigator.userAgent;d=-1!==r.indexOf("MSIE ")||-1!==r.indexOf("Trident/")}}return d}function n(){var e=f.$B;if(void 0===l){if(e){l=e.RE_Edge}else{var r=f.navigator.userAgent;l=-1!==r.indexOf("Edge")}}return l}function o(e){
var r=e.indexOf("?"),t=r>-1?r:e.length,n=e.lastIndexOf(".",t);return e.substring(n,n+v.length).toLowerCase()===v}function i(){var r=e();return(r.loader||{}).slReportFailure||r.slReportFailure||!1}function a(){return(e().loader||{}).redirectToErrorPageOnLoadFailure||!1}function s(){return(e().loader||{}).logByThrowing||!1}function u(e){if(!t()&&!n()){return!1}var r=e.src||e.href||"";if(!r){return!0}if(o(r)){var i,a,s;try{i=e.sheet,a=i&&i.cssRules,s=!1}catch(e){s=!0}if(i&&!a&&s){return!0}
if(i&&a&&0===a.length){return!0}}return!1}function c(){function t(e){g.getElementsByTagName("head")[0].appendChild(e)}function n(e,r,t,n){var u=null;return u=o(e)?i(e):"script"===n.toLowerCase()?a(e):s(e,n),r&&(u.id=r),"function"==typeof u.setAttribute&&(u.setAttribute("crossorigin","anonymous"),t&&"string"==typeof t&&u.setAttribute("integrity",t)),u}function i(e){var r=g.createElement("link");return r.rel="stylesheet",r.type="text/css",r.href=e,r}function a(e){
var r=g.createElement("script"),t=g.querySelector("s |
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-827... Model: Joe Sandbox AI | {
"risk_score": 2,
"reasoning": "The provided JavaScript snippet appears to be a configuration object for a login/authentication system. It contains URLs for Microsoft Account (MSA) sign-up and logout, as well as options related to persistent cookies and federated identity providers like GitHub. While the snippet includes some external URLs, it does not exhibit any high-risk behaviors like dynamic code execution, data exfiltration, or suspicious redirects. The overall behavior seems to be related to standard authentication and account management functionality, which is considered a low-risk context."
} |
//<![CDATA[
$Config={"fShowPersistentCookiesWarning":false,"urlMsaSignUp":"https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access\u0026response_type=code\u0026client_id=51483342-085c-4d86-bf88-cf50c7252078\u0026response_mode=form_post\u0026redirect_uri=https%3a%2f%2fdebak.ciamlogin.com%2fcommon%2ffederation%2foauth2msa\u0026state=rQQIARAAjdLLi9x0AAfwyc52urtoO6hIvVXYg6iZzfux0EJmMsk88ppNZjMzl5B3MvObJJtkHpu74El6EUq99aL04uIDixet3haEehKEQo9SREQvPbr9D7x8-X5P38vn4DrTwltIC3m_jrWQ40MnIFgGt1kYRXEKJhiHgVkcIWCEcAiUYmnUR4j8jYPmv799_t2zvBDvv_Nk_u4XX959AO1bIF77LTddPoIOo7LMiuOjIycu1_Y6bXm-Yy9aCTgq4jCJEziNPfcxBD2FoD8g6NFOQeEMjREITTIEg11dI2RLmZ9GCj8ilWpRzsT-dtZBEAWTt5IBYtUYlarR30znLqEYXWImKsvpvL-VsVF11UrFcBFZRxCZby8lY0HKvFxO5x5Q-AjIc2GpGMry952bKrcqI-xVpHlc-f_s7AdpvrSytCgf1C92OgE_YBQhZU0hoUNUDV2JzKNE17ZL0x8Pe31S1eE2DSygAq5zEqJuMXa71NlEjqoZ7W0HoiCGkaiX8aSvr9QOb4UE3Rbyhcl4Lt02lbPUVANprUvnZtUeFbq4GLS3kQb0FJzxm-G54IZLeMCIttnLql4lVFISg1KyV8KpJmdw1YFVzu0BNEnBzJ5jdjdZxVkPnI03yZCupppuJKWBY1Y20daeG9voaTefcYHJo64wlEjKLciuIoUoBywtdxxM4nQam1S9dDWNVwMtZ8wBfEIwbMjbZtRhATM35EkpWFwX0_QCYPbIER2OynQt6Ojh9qv6oUN4OEMFV3xY34MJiiJhBqMJmCLwgPIRlvAp77J-I838JPZuZ3kaxMB_ugu92H17b69Zv1W7XXvvLaR-vLd30Ky9Wi93oYfXrrx98-un9W8_Ae0f_vzg55_q9drltaMCzUxSSJHxAgz9zTzApISqyhE6wkDmb1Rax1UOxcn0XCbuUMfovUbjXuPNy8Z-n7eUrsFayN8N6OPrte_3_5fW-wfQxWvQj6_XXt548vjrh5999MtfvRc3P5zMNFdZAyrvnZOKo1EV5ZvaJFYMMTypuJUUjcU0jU8RqcPduWjWnjdr_wE1\u0026estsfed=1\u0026uaid=b7a7d7f372dd47739819c16a21a8af3e\u0026signup=1\u0026lw=1\u0026fl=easi2\u0026fci=bf4983a9-1136-48b8-9304-04b416971e04","urlMsaLogout":"https://login.live.com/logout.srf?iframed_by=https%3a%2f%2fdebak.ciamlogin.com","urlOtherIdpForget":"https://login.live.com/forgetme.srf?iframed_by=https%3a%2f%2fdebak.ciamlogin.com","showCantAccessAccountLink":true,"urlGitHubFed":"https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access\u0026response_type=code\u0026client_id=51483342-085c-4d86-bf88-cf50c7252078\u0026response_mode=form_post\u0026redirect_uri=https%3a%2f%2fdebak.ciamlogin.com%2fcommon%2ffederation%2foauth2msa\u0026state=rQQIARAAjdLLi9x0AAfwyc52urtoO6hIvVXYg6iZzfux0EJmMsk88ppNZjMzl5B3MvObJJtkHpu74El6EUq99aL04uIDixet3haEehKEQo9SREQvPbr9D7x8-X5P38vn4DrTwltIC3m_jrWQ40MnIFgGt1kYRXEKJhiHgVkcIWCEcAiUYmnUR4j8jYPmv799_t2zvBDvv_Nk_u4XX959AO1bIF77LTddPoIOo7LMiuOjIycu1_Y6bXm-Yy9aCTgq4jCJEziNPfcxBD2FoD8g6NFOQeEMjREITTIEg11dI2RLmZ9GCj8ilWpRzsT-dtZBEAWTt5IBYtUYlarR30znLqEYXWImKsvpvL-VsVF11UrFcBFZRxCZby8lY0HKvFxO5x5Q-AjIc2GpGMry952bKrcqI-xVpHlc-f_s7AdpvrSytCgf1C92OgE_YBQhZU0hoUNUDV2JzKNE17ZL0x8Pe31S1eE2DSygAq5zEqJuMXa71NlEjqoZ7W0HoiCGkaiX8aSvr9QOb4UE3Rbyhcl4Lt02lbPUVANprUvnZtUeFbq4GLS3kQb0FJzxm-G54IZLeMCIttnLql4lVFISg1KyV8KpJmdw1YFVzu0BNEnBzJ5jdjdZxVkPnI03yZCupppuJKWBY1Y20daeG9voaTefcYHJo64wlEjKLciuIoUoBywtdxxM4nQam1S9dDWNVwMtZ8wBfEIwbMjbZtRhATM35EkpWFwX0_QCYPbIER2OynQt6Ojh9qv6oUN4OEMFV3xY34MJiiJhBqMJmCLwgPIRlvAp77J-I838JPZuZ3kaxMB_ugu92H17b69Zv1W7XXvvLaR-vLd30Ky9Wi93oYfXrrx98-un9W8_Ae0f_vzg55_q9drltaMCzUxSSJHxAgz9zTzApISqyhE6wkDmb1Rax1UOxcn0XCbuUMfovUbjXuPNy8Z-n7eUrsFayN8N6OPrte_3_5fW-wfQxWvQj6_XXt548vjrh5999MtfvRc3P5zMNFdZAyrvnZOKo1EV5ZvaJFYMMTypuJUUjcU0jU8RqcPduWjWnjdr_wE1\u0026estsfed=1\u0026uaid=b7a7d7f372dd47739819c16a21a8af3e\u0026fci=bf4983a9-1136-48b8-9304-04b416971e04\u0026idp_hint=github.com","arrExternalTrustedRealmFederatedIdps":[],"fShowSignInWithGitHubOnlyOnCredPicker":true,"fEnableShowResendCode":true,"iShowResendCodeDelay":90000,"sSMSCtryPhoneData":"AF~Afghanistan~93!!!AX~land Islands~358!!!AL~Albania~355!!!DZ~Algeria~213!!!AS~American Samoa~1!!!AD~Andorra~376!!!AO~Angola~244!!!AI~Anguilla~1!!!AG~Antigua and Barbuda~1!!!AR~Argentina~54!!!AM~Armenia~374!!!AW~Aruba~297!!!AC~Ascension Island~247!!!AU~Australia~61!!!AT~Austria~43!!!AZ~Azerbaijan~994!!!BS~Bahamas~1!!!BH~Bahrain~973!!!BD~Bangladesh~880!!!BB~Barbados~1!!!BY~Belarus~375!!!BE~Belgium~32!!!BZ~Belize~501!!!BJ~Benin~229!!!BM~Bermuda~1!!!BT~Bhutan~975!!!BO~Bolivia~591!!!BQ~Bonaire~599!!!BA~Bosnia and Herzegovina~387!!!BW~Botsw |
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-827... Model: Joe Sandbox AI | {
"risk_score": 4,
"reasoning": "The provided JavaScript snippet appears to be a configuration object for a web application, with various settings and parameters. While it does not contain any obvious high-risk indicators, there are some moderate-risk behaviors that warrant further review:
1. External Data Transmission (+2 points): The script sends user data to external domains like 'debak.ciamlogin.com' and 'aadcdn.msauth.net' without clear transparency.
2. Fallback Domains (+2 points): The script uses multiple fallback domains, some of which may be of unknown or dubious reputation.
Additionally, the script contains some legacy practices, such as the use of the `XDomainRequest` API, which pose minor risks but are not inherently malicious.
Overall, the script appears to be part of a larger web application and may be performing legitimate functionality, such as authentication and telemetry. However, the lack of clear transparency around data transmission and the use of multiple fallback domains raise some concerns that require further investigation to determine the true intent and potential risks."
} |
//<![CDATA[
$Config={"iMaxStackForKnockoutAsyncComponents":10000,"fShowButtons":true,"urlCdn":"https://aadcdn.msauth.net/shared/1.0/","urlDefaultFavicon":"https://aadcdn.msauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico","urlPost":"/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04\u0026redirect_uri=https%3a%2f%2fbitvavo.debak.nl%2fsignin-oidc\u0026response_type=id_token\u0026scope=openid+profile\u0026response_mode=form_post\u0026nonce=638724075848211305.NjVhNDQ5NzktZGIxZC00N2MxLTliOTQtOTIwYjc4NTE4ZGNmYjIxM2QzNmYtNTc0MS00MDBmLTk5MDMtYjdlNDhlMjFmNTNm\u0026client_info=1\u0026x-client-brkrver=IDWeb.3.5.0.0\u0026state=CfDJ8NFo9WFn7g1OgcL5rhnSPxmWeUKHI5OS-B7l_lOlACRg1csUcE6qXMhzZ7dxJGFGghGStiXISuOCD_g47BFrkW8dc7BWNqoWOfLvSLyWzBQsSGkJBxhPlSolqDwKyFcgm-J8GaWHpzHzFzLniltLauFVPMp-zC-OAcHl1nolZaj2aEnuipHlqUwnK7zYPSTntT32_pXPvdcia1VErZAfWD1cFKL56cs5ENLg1Al_Prbb2LAS72XzHouYiuJPr8WJ-R489gDaWhC9l8jTMXtF_AE2PSsl2aQbGbA6pSPfCSgx\u0026x-client-SKU=ID_NET9_0\u0026x-client-ver=8.3.0.0\u0026client-request-id=858b4196-c6a6-42e5-857d-7aff1f1ac023\u0026sso_reload=True","iPawnIcon":0,"sPOST_Username":"","sFTName":"flowToken","fEnableOneDSClientTelemetry":true,"urlReportPageLoad":"https://debak.ciamlogin.com/common/instrumentation/reportpageload?mkt=en-US","dynamicTenantBranding":null,"staticTenantBranding":null,"oAppCobranding":{},"iBackgroundImage":2,"fApplicationInsightsEnabled":false,"iApplicationInsightsEnabledPercentage":0,"urlSetDebugMode":"https://debak.ciamlogin.com/common/debugmode","fEnableCssAnimation":true,"fAllowGrayOutLightBox":true,"fUseMsaSessionState":true,"fIsRemoteNGCSupported":true,"desktopSsoConfig":{"isEdgeAnaheimAllowed":true,"iwaEndpointUrlFormat":"https://autologon.microsoftazuread-sso.com/{0}/winauth/sso?client-request-id=858b4196-c6a6-42e5-857d-7aff1f1ac023","iwaSsoProbeUrlFormat":"https://autologon.microsoftazuread-sso.com/{0}/winauth/ssoprobe?client-request-id=858b4196-c6a6-42e5-857d-7aff1f1ac023","iwaIFrameUrlFormat":"https://autologon.microsoftazuread-sso.com/{0}/winauth/iframe?client-request-id=858b4196-c6a6-42e5-857d-7aff1f1ac023\u0026isAdalRequest=False","iwaRequestTimeoutInMs":10000,"startDesktopSsoOnPageLoad":false,"progressAnimationTimeout":10000,"isEdgeAllowed":false,"minDssoEdgeVersion":"17","isSafariAllowed":true,"redirectUri":"","isIEAllowedForSsoProbe":true,"edgeRedirectUri":"https://autologon.microsoftazuread-sso.com/common/winauth/sso/edgeredirect?client-request-id=858b4196-c6a6-42e5-857d-7aff1f1ac023\u0026origin=debak.ciamlogin.com\u0026is_redirected=1","isFlowTokenPassedInEdge":true},"iSessionPullType":2,"fUseSameSite":true,"isGlobalTenant":true,"uiflavor":1001,"fOfflineAccountVisible":false,"fEnableUserStateFix":true,"fShowAccessPassPeek":true,"fUpdateSessionPollingLogic":true,"fEnableShowPickerCredObservable":true,"fFetchSessionsSkipDsso":true,"fIsCiamUserFlowUxNewLogicEnabled":true,"fUseNonMicrosoftDefaultBrandingForCiam":true,"fRemoveCustomCss":true,"fFixUICrashForApiRequestHandler":true,"fShowUpdatedKoreanPrivacyFooter":true,"fUsePostCssHotfix":true,"fUseHighContrastDetectionMode":true,"fFixUserFlowBranding":true,"fEnablePasskeyNullFix":true,"fEnableRefreshCookiesFix":true,"urlAcmaServerPath":"https://debak.ciamlogin.com","sTenantId":"00000000-0000-0000-0000-000000000000","scid":1013,"hpgact":1800,"hpgid":6,"apiCanary":"PAQABDgEAAABVrSpeuWamRam2jAF1XRQEzXxEuo7Hh51tzjTbfvahxPNaQLeDNPLGsmBvyhA3h5020O9bfbsvWiBMUehEm0wJK37axGvGxJGRgfboSecyIw7FSvrnWTn_dQ4Fv2yP0FLwz8yx5loCTmlu1tOmk4_GbRVy-7J-qnj3GTn284v4pSQNEnsR3fmHc5B1zr3GqrOIADV0p91KweTjStpu6INOdIsSMREsywxD5MSsPZwAOiAA","canary":"s1pW5Fo0UklKewjf2Ln6ztQ1Q2lpewO7S3OA135oyM4=0:1:CANARY:Zd/nluXeCRA4iw1fPKdwbzt1czwQvqjy7sxvUtePQ2o=","sCanaryTokenName":"canary","fSkipRenderingNewCanaryToken":false,"fEnableNewCsrfProtection":true,"correlationId":"858b4196-c6a6-42e5-857d-7aff1f1ac023","sessionId":"817e1550-c9b1-49b7-923d-89a720ae0200","locale":{"mkt":"en-US","lcid":1033},"slMaxRetry":2 |
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | {
"contains_trigger_text": true,
"trigger_text": "Sign in",
"prominent_button_name": "Next",
"text_input_field_labels": [
"h04abb@toop.org"
],
"pdf_icon_visible": false,
"has_visible_captcha": false,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | {
"brands": [
"Microsoft"
]
} |
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | {
"contains_trigger_text": false,
"trigger_text": "unknown",
"prominent_button_name": "Next",
"text_input_field_labels": [
"h04abb@toop.org"
],
"pdf_icon_visible": false,
"has_visible_captcha": false,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | ```json{ "legit_domain": "microsoft.com", "classification": "wellknown", "reasons": [ "The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'.", "The URL 'debak.ciamlogin.com' does not match the legitimate domain 'microsoft.com'.", "The domain 'ciamlogin.com' is not commonly associated with Microsoft and could be a third-party service.", "The presence of a subdomain 'debak' and the main domain 'ciamlogin.com' suggests a potential phishing attempt, as it does not directly relate to Microsoft.", "The email domain 'toop.org' in the input fields is unrelated to Microsoft, which raises further suspicion." ], "riskscore": 8}
Google indexed: False |
URL: debak.ciamlogin.com
Brands: Microsoft
Input Fields: h04abb@toop.org |
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | {
"brands": [
"Microsoft"
]
} |
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | ```json{ "legit_domain": "microsoft.com", "classification": "wellknown", "reasons": [ "The brand 'Microsoft' is a well-known brand with a legitimate domain of 'microsoft.com'.", "The URL 'debak.ciamlogin.com' does not match the legitimate domain of Microsoft.", "The domain 'ciamlogin.com' is not associated with Microsoft and could be a third-party service.", "The subdomain 'debak' and the domain 'ciamlogin.com' are suspicious as they do not relate to Microsoft's known domains.", "The presence of a subdomain and a domain that do not match Microsoft's legitimate domain increases the likelihood of phishing." ], "riskscore": 8}
Google indexed: False |
URL: debak.ciamlogin.com
Brands: Microsoft
Input Fields: h04abb@toop.org |
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | {
"contains_trigger_text": true,
"trigger_text": "This username may be incorrect. Make sure you typed it correctly. Otherwise, contact your admin.",
"prominent_button_name": "Next",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": false,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://debak.ciamlogin.com/b4d386f9-19ed-4665-8274-643f6e094e6d/oauth2/v2.0/authorize?client_id=bf4983a9-1136-48b8-9304-04b416971e04&redirect_uri=https%3A%2F%2Fbitvavo.debak.nl%2Fsignin-oidc&response_type=id_token&scope=openid%20profile&response_mode=for Model: Joe Sandbox AI | {
"brands": [
"Microsoft"
]
} |
|