Edit tour

Windows Analysis Report
https://vardhadevelco.com/365confirmation.php

Overview

General Information

Sample URL:https://vardhadevelco.com/365confirmation.php
Analysis ID:1643219
Infos:

Detection

HTMLPhisher, Mamba2FA
Score:84
Range:0 - 100
Confidence:100%

Signatures

AI detected phishing page
Suricata IDS alerts for network traffic
Yara detected HtmlPhish10
Yara detected Mamba 2FA PaaS
AI detected landing page (webpage, office document or email)
AI detected suspicious Javascript
HTML page contains suspicious onload / onerror event
Creates files inside the system directory
Deletes files inside the Windows folder
Detected hidden input values containing email addresses (often used in phishing pages)
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML title does not match URL
Invalid 'forgot password' link found
Invalid T&C link found
No HTML title found
Suricata IDS alerts with low severity for network traffic

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 2332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,10196678198657757390,3594446482516654740,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2248 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6672 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vardhadevelco.com/365confirmation.php" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
SourceRuleDescriptionAuthorStrings
2.3.pages.csvJoeSecurity_Mamba2FAYara detected Mamba 2FA PaaSJoe Security
    2.3.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
      2.4.pages.csvJoeSecurity_Mamba2FAYara detected Mamba 2FA PaaSJoe Security
        2.4.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
          2.5.pages.csvJoeSecurity_Mamba2FAYara detected Mamba 2FA PaaSJoe Security
            Click to see the 5 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-19T16:38:54.389259+010020566432Possible Social Engineering Attempted192.168.2.1749786162.241.203.10443TCP
            2025-03-19T16:40:12.249211+010020566432Possible Social Engineering Attempted192.168.2.1750030162.241.203.10443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-19T16:38:53.215590+010020573331Successful Credential Theft Detected192.168.2.1749778162.241.203.10443TCP

            Click to jump to signature section

            Show All Signature Results

            Phishing

            barindex
            Source: https://vardhadevelco.com/365confirmation.phpJoe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The URL 'vardhadevelco.com' does not match the legitimate domain 'microsoft.com'., The URL does not contain any recognizable association with Microsoft., The domain name 'vardhadevelco.com' appears unrelated to Microsoft and could be a phishing attempt., No subdomain or URL structure indicates a legitimate Microsoft service or product. DOM: 0.0.pages.csv
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comJoe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The legitimate domain for Microsoft is 'microsoft.com'., The provided URL 'x2bm.com' does not match the legitimate domain for Microsoft., The URL 'x2bm.com' does not contain any recognizable association with Microsoft., The URL is short and lacks any clear indication of being related to Microsoft, which is suspicious., No subdomains or recognizable brand elements are present in the URL. DOM: 2.4.pages.csv
            Source: Yara matchFile source: 2.3.pages.csv, type: HTML
            Source: Yara matchFile source: 2.4.pages.csv, type: HTML
            Source: Yara matchFile source: 2.5.pages.csv, type: HTML
            Source: Yara matchFile source: 2.6.pages.csv, type: HTML
            Source: Yara matchFile source: 2.7.pages.csv, type: HTML
            Source: Yara matchFile source: 2.3.pages.csv, type: HTML
            Source: Yara matchFile source: 2.4.pages.csv, type: HTML
            Source: Yara matchFile source: 2.5.pages.csv, type: HTML
            Source: Yara matchFile source: 2.6.pages.csv, type: HTML
            Source: Yara matchFile source: 2.7.pages.csv, type: HTML
            Source: https://vardhadevelco.com/365confirmation.phpJoe Sandbox AI: Page contains button: 'Verify it's you' Source: '0.0.pages.csv'
            Source: 2.2..script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZH... The script uses the 'Function' constructor to execute dynamic code, which is a high-risk indicator of potential malicious behavior. This allows for the execution of arbitrary JavaScript, which could be used to perform harmful actions.
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: (new function(atob(this.dataset.digest)))();
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: {"screen":{"availWidth":1280,"availHeight":984,"width":1280,"height":1024,"colorDepth":24,"pixelDepth":24,"availLeft":0,"availTop":0,"orientation":"[object ScreenOrientation]","onchange":null,"isExtended":false,"addEventListener":"function addEventListener() { [native code] }","dispatchEvent":"function dispatchEvent() { [native code] }","removeEventListener":"function removeEventListener() { [native code] }","!!":[]},"window":{"window":"[object Window]","self":"[object Window]","document":"[object HTMLDocument]","name":"","location":"https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.com","customElements":"[object CustomElementRegistry]","history":"[object History]","navigation":"[object Navigation]","locationbar":"[object BarProp]","menubar":"[object BarProp]","personalbar":"[object BarProp]","scrollbars":"[object BarProp]","statusbar":"[object BarProp]","toolbar":"[object BarProp]","status":"","closed":false,"frames":"[object Window]","length":0,"top":"[object Window]","opener":null,"parent":"[object Window]","frameElement":null,"navigator":"[object Navigator]","origin":"https://x2bm.com","external":"[object External]","screen":"[object Screen]","innerWidth":1280,"innerHeight":897,"scrollX":0,"pageXOffset":0,"scrollY":0,"pageYOffset":0,"visualViewport":"[object VisualViewport]","screenX":0,"screenY":0,"outerWidth":1280,"outerHeight":984,"devicePixelRatio":1,"event":"[object Event]","clientInformation":"[object Navigator]","screenLeft":0,"screenTop":0,"styleMedia":"[object StyleMedia]","onsearch":null,"trustedTypes":"[object TrustedTypePolicyFactory]","performance":"[object Performance]","onappinstalled":null,"onbeforeinstallprompt":null,"crypto":"[object Crypto]","indexedDB":"[object IDBFactory]","sessionStorage":"[object Storage]","localStorage":"[object Storage]","onbeforexrselect":null,"onabort":null,"onbeforeinput":null,"onbeforematch":null,"onbeforetoggle":null,"onblur":null,"oncancel":null,"oncanplay":null,"oncanplaythrough":null,"onchange":null,"onclick":null,"onclose":null,"oncontentvisibilityautostatechange":null,"oncontextlost":null,"oncontextmenu":null,"oncontextrestored":null,"oncuechange":null,"ondblclick":null,"ondrag":null,"ondragend":null,"ondragenter":null,"ondragleave":null,"ondragover":null,"ondragstart":null,"ondrop":null,"ondurationchange":null,"onemptied":null,"onended":null,"onerror":null,"onfocus":null,"onformdata":null,"oninput":null,"oninvalid":null,"onkeydown":null,"onkeypress":null,"onkeyup":null,"onload":null,"onloadeddata":null,"onloadedmetadata":null,"onloadstart":null,"onmousedown":null,"onmouseenter":null,"onmouseleave":null,"onmousemove":null,"onmouseout":null,"onmouseover":null,"onmouseup":null,"onmousewheel":null,"onpause":null,"onplay":null,"onplaying":null,"onprogress":null,"onratechange":null,"onreset":null,"onresize":null,"onscroll":null,"onsecuritypolicyviolation":null,"onseeked":null,"onseeking":null,"onselect":null,"onslotchange":null,"onst
            Source: https://planrenovecaldera.com/cloudportal/0365cloudportalHTTP Parser: Number of links: 0
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Number of links: 0
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: <input type="password" .../> found but no <form action="...
            Source: https://planrenovecaldera.com/cloudportal/0365cloudportalHTTP Parser: Base64 decoded: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=
            Source: https://planrenovecaldera.com/cloudportal/0365cloudportalHTTP Parser: Title: Verify Your Identity does not match URL
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Title: Authenticating ... does not match URL
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Forgot password?
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Terms of use
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Privacy & cookies
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Terms of use
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Privacy & cookies
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Terms of use
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Privacy & cookies
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Terms of use
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Privacy & cookies
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Terms of use
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: Invalid link: Privacy & cookies
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: HTML title missing
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: <input type="password" .../> found
            Source: https://vardhadevelco.com/365confirmation.phpHTTP Parser: No favicon
            Source: https://planrenovecaldera.com/cloudportal/0365cloudportalHTTP Parser: No favicon
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No favicon
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No favicon
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No favicon
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No favicon
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No favicon
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No favicon
            Source: https://planrenovecaldera.com/cloudportal/0365cloudportalHTTP Parser: No <meta name="author".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="author".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="author".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="author".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="author".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="author".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="author".. found
            Source: https://planrenovecaldera.com/cloudportal/0365cloudportalHTTP Parser: No <meta name="copyright".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="copyright".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="copyright".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="copyright".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="copyright".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="copyright".. found
            Source: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comHTTP Parser: No <meta name="copyright".. found
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
            Source: unknownHTTPS traffic detected: 51.210.156.4:443 -> 192.168.2.17:49716 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 51.210.156.4:443 -> 192.168.2.17:49715 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 51.210.156.4:443 -> 192.168.2.17:49717 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 216.58.206.36:443 -> 192.168.2.17:49727 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.17:49738 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 172.67.216.162:443 -> 192.168.2.17:49744 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 172.67.216.162:443 -> 192.168.2.17:49745 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.17:49753 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.17:49756 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49778 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49777 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49786 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49785 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.17.25.14:443 -> 192.168.2.17:49798 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 18.245.31.5:443 -> 192.168.2.17:49797 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 95.101.54.104:443 -> 192.168.2.17:49799 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 95.101.182.65:443 -> 192.168.2.17:49810 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49823 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 95.101.182.65:443 -> 192.168.2.17:49830 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 216.58.206.36:443 -> 192.168.2.17:49964 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 18.245.31.5:443 -> 192.168.2.17:50033 version: TLS 1.2
            Source: chrome.exeMemory has grown: Private usage: 1MB later: 36MB

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2057333 - Severity 1 - ET PHISHING MAMBA Credential Phish Landing Page 2024-11-08 : 192.168.2.17:49778 -> 162.241.203.10:443
            Source: Network trafficSuricata IDS: 2056643 - Severity 2 - ET PHISHING Javascript Browser Fingerprinting POST Request : 192.168.2.17:49786 -> 162.241.203.10:443
            Source: Network trafficSuricata IDS: 2056643 - Severity 2 - ET PHISHING Javascript Browser Fingerprinting POST Request : 192.168.2.17:50030 -> 162.241.203.10:443
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 52.123.128.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 52.123.128.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 52.123.128.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 52.123.128.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 52.123.128.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 184.86.251.25
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 52.123.128.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 51.132.193.104
            Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
            Source: unknownTCP traffic detected without corresponding DNS query: 52.109.28.46
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: unknownTCP traffic detected without corresponding DNS query: 13.107.246.60
            Source: global trafficHTTP traffic detected: GET /365confirmation.php HTTP/1.1Host: vardhadevelco.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CLf3ygE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /365confirmation.php HTTP/1.1Host: vardhadevelco.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: vardhadevelco.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: vardhadevelco.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120600v5s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /cloudportal/0365cloudportal HTTP/1.1Host: planrenovecaldera.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /cloudportal/images/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: planrenovecaldera.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planrenovecaldera.com/cloudportal/0365cloudportalAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /logo/Microsoft_Outlook/Microsoft_Outlook-Logo.wine.png HTTP/1.1Host: download.logo.wineConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://planrenovecaldera.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /cloudportal/images/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: planrenovecaldera.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planrenovecaldera.com/cloudportal/0365cloudportalAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: planrenovecaldera.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planrenovecaldera.com/cloudportal/0365cloudportalAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.com HTTP/1.1Host: x2bm.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://planrenovecaldera.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /files/images/Logo.png HTTP/1.1Host: x2bm.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120637v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120639v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120638v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120640v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120641v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120642v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120643v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120644v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120645v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120646v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120647v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120649v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120648v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/6.1.1/css/all.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /4.7.5/socket.io.min.js HTTP/1.1Host: cdn.socket.ioConnection: keep-aliveOrigin: https://x2bm.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /w3css/4/w3.css HTTP/1.1Host: www.w3schools.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120652v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120653v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120654v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120655v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120656v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: x2bm.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120657v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120658v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120659v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120660v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /w3css/4/w3.css HTTP/1.1Host: www.w3schools.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Range: bytes=15877-15877If-Range: "0285dd8ff97db1:0"
            Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_code_b41922ebdaebec16b19999fc6054a15a.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120661v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120662v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120663v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /rules/rule120664v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: x2bm.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /rules/rule120665v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.svc.static.microsoft
            Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_code_b41922ebdaebec16b19999fc6054a15a.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /w3css/4/w3.css HTTP/1.1Host: www.w3schools.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Range: bytes=15877-15877If-Range: "0285dd8ff97db1:0"
            Source: global trafficHTTP traffic detected: GET /4.7.5/socket.io.min.js HTTP/1.1Host: cdn.socket.ioConnection: keep-aliveOrigin: https://x2bm.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Range: bytes=32768-32768If-Range: "777eb8fd4f8320b6e5cc9a7159bdec6a"
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: x2bm.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /w3css/4/w3.css HTTP/1.1Host: www.w3schools.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://x2bm.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Range: bytes=15877-15877If-Range: "0285dd8ff97db1:0"
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: x2bm.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: global trafficDNS traffic detected: DNS query: vardhadevelco.com
            Source: global trafficDNS traffic detected: DNS query: www.google.com
            Source: global trafficDNS traffic detected: DNS query: planrenovecaldera.com
            Source: global trafficDNS traffic detected: DNS query: download.logo.wine
            Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
            Source: global trafficDNS traffic detected: DNS query: x2bm.com
            Source: global trafficDNS traffic detected: DNS query: cdn.socket.io
            Source: global trafficDNS traffic detected: DNS query: www.w3schools.com
            Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
            Source: global trafficDNS traffic detected: DNS query: aadcdn.msftauth.net
            Source: global trafficDNS traffic detected: DNS query: beacons.gcp.gvt2.com
            Source: global trafficDNS traffic detected: DNS query: beacons.gvt2.com
            Source: unknownHTTP traffic detected: POST /o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.com HTTP/1.1Host: x2bm.comConnection: keep-aliveContent-Length: 146838Cache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Origin: https://x2bm.comContent-Type: application/x-www-form-urlencodedUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://x2bm.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPU5HZHVRMFU9JnVpZD1VU0VSMjQwMjIwMjVVMTkwMjI0MTA=N0123Nbillg@microsoft.comAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
            Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
            Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
            Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
            Source: unknownNetwork traffic detected: HTTP traffic on port 50039 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49964 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
            Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49964
            Source: unknownNetwork traffic detected: HTTP traffic on port 50034 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50031 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
            Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49677
            Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
            Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
            Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
            Source: unknownNetwork traffic detected: HTTP traffic on port 50032 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49682 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50029
            Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50035 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50026
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50030
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
            Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50029 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50039
            Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50032
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50031
            Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50034
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50033
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50035
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50038
            Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
            Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
            Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50027 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50030 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
            Source: unknownHTTPS traffic detected: 51.210.156.4:443 -> 192.168.2.17:49716 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 51.210.156.4:443 -> 192.168.2.17:49715 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 51.210.156.4:443 -> 192.168.2.17:49717 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 216.58.206.36:443 -> 192.168.2.17:49727 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.17:49738 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 172.67.216.162:443 -> 192.168.2.17:49744 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 172.67.216.162:443 -> 192.168.2.17:49745 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.17:49753 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 35.190.80.1:443 -> 192.168.2.17:49756 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49778 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49777 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49786 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49785 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.17.25.14:443 -> 192.168.2.17:49798 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 18.245.31.5:443 -> 192.168.2.17:49797 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 95.101.54.104:443 -> 192.168.2.17:49799 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 95.101.182.65:443 -> 192.168.2.17:49810 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 162.241.203.10:443 -> 192.168.2.17:49823 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 95.101.182.65:443 -> 192.168.2.17:49830 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 216.58.206.36:443 -> 192.168.2.17:49964 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 18.245.31.5:443 -> 192.168.2.17:50033 version: TLS 1.2
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir2332_437245095
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir2332_437245095
            Source: classification engineClassification label: mal84.phis.win@24/0@45/233
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
            Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,10196678198657757390,3594446482516654740,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2248 /prefetch:3
            Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://vardhadevelco.com/365confirmation.php"
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1924,i,10196678198657757390,3594446482516654740,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2248 /prefetch:3
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
            Browser Extensions
            1
            Process Injection
            12
            Masquerading
            OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            Extra Window Memory Injection
            1
            Process Injection
            LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            File Deletion
            Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Extra Window Memory Injection
            NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
            Ingress Tool Transfer
            Traffic DuplicationData Destruction

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            https://vardhadevelco.com/365confirmation.php0%Avira URL Cloudsafe
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            https://planrenovecaldera.com/cloudportal/images/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg0%Avira URL Cloudsafe
            https://vardhadevelco.com/favicon.ico0%Avira URL Cloudsafe
            https://download.logo.wine/logo/Microsoft_Outlook/Microsoft_Outlook-Logo.wine.png0%Avira URL Cloudsafe
            https://planrenovecaldera.com/favicon.ico0%Avira URL Cloudsafe
            https://cdn.socket.io/4.7.5/socket.io.min.js0%Avira URL Cloudsafe
            https://x2bm.com/favicon.ico0%Avira URL Cloudsafe
            https://x2bm.com/files/images/Logo.png0%Avira URL Cloudsafe
            https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/css/all.min.css0%Avira URL Cloudsafe
            https://aadcdn.msftauth.net/shared/1.0/content/images/picker_verify_code_b41922ebdaebec16b19999fc6054a15a.svg0%Avira URL Cloudsafe
            https://a.nel.cloudflare.com/report/v4?s=VyBFkAHVLOmj%2F9GiVlmeeA6dv5cddZmw9unXJ0yObcKCeoj27S2pltJpcDXw5PWzFpv0EiQnJhC8pOL6RpmpDYvqu%2FXzxE%2FwySsSUlsgjYVSwfYAnShbzt0oAd7odVKDaxdwgLg%3D0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            a.nel.cloudflare.com
            35.190.80.1
            truefalse
              high
              s-part-0044.t-0009.fb-t-msedge.net
              13.107.253.72
              truefalse
                high
                e329293.dscd.akamaiedge.net
                95.101.182.65
                truefalse
                  high
                  beacons-handoff.gcp.gvt2.com
                  142.250.180.67
                  truefalse
                    high
                    beacons.gvt2.com
                    142.250.180.67
                    truefalse
                      high
                      vardhadevelco.com
                      51.210.156.4
                      truefalse
                        high
                        x2bm.com
                        162.241.203.10
                        truetrue
                          unknown
                          d2vgu95hoyrpkh.cloudfront.net
                          18.245.31.5
                          truefalse
                            unknown
                            planrenovecaldera.com
                            172.67.216.162
                            truefalse
                              high
                              cdnjs.cloudflare.com
                              104.17.25.14
                              truefalse
                                high
                                www.google.com
                                216.58.206.36
                                truefalse
                                  high
                                  download.logo.wine
                                  188.114.96.3
                                  truefalse
                                    high
                                    s-part-0032.t-0009.t-msedge.net
                                    13.107.246.60
                                    truefalse
                                      high
                                      a1400.dscb.akamai.net
                                      95.101.54.104
                                      truefalse
                                        high
                                        aadcdn.msftauth.net
                                        unknown
                                        unknownfalse
                                          high
                                          beacons.gcp.gvt2.com
                                          unknown
                                          unknownfalse
                                            high
                                            www.w3schools.com
                                            unknown
                                            unknownfalse
                                              high
                                              cdn.socket.io
                                              unknown
                                              unknownfalse
                                                high
                                                NameMaliciousAntivirus DetectionReputation
                                                https://otelrules.svc.static.microsoft/rules/other-Win32-v19.bundlefalse
                                                  high
                                                  https://otelrules.svc.static.microsoft/rules/rule120639v0s19.xmlfalse
                                                    high
                                                    https://otelrules.svc.static.microsoft/rules/rule120630v0s19.xmlfalse
                                                      high
                                                      https://otelrules.svc.static.microsoft/rules/rule120645v0s19.xmlfalse
                                                        high
                                                        https://planrenovecaldera.com/cloudportal/0365cloudportalfalse
                                                          unknown
                                                          https://planrenovecaldera.com/cloudportal/images/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svgfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://otelrules.svc.static.microsoft/rules/rule120654v0s19.xmlfalse
                                                            high
                                                            https://otelrules.svc.static.microsoft/rules/rule120648v0s19.xmlfalse
                                                              high
                                                              https://otelrules.svc.static.microsoft/rules/rule120657v0s19.xmlfalse
                                                                high
                                                                https://vardhadevelco.com/365confirmation.phptrue
                                                                  unknown
                                                                  https://otelrules.svc.static.microsoft/rules/rule120660v0s19.xmlfalse
                                                                    high
                                                                    https://otelrules.svc.static.microsoft/rules/rule120621v0s19.xmlfalse
                                                                      high
                                                                      https://otelrules.svc.static.microsoft/rules/rule120663v0s19.xmlfalse
                                                                        high
                                                                        https://otelrules.svc.static.microsoft/rules/rule120624v0s19.xmlfalse
                                                                          high
                                                                          https://otelrules.svc.static.microsoft/rules/rule120615v0s19.xmlfalse
                                                                            high
                                                                            https://otelrules.svc.static.microsoft/rules/rule120651v0s19.xmlfalse
                                                                              high
                                                                              https://otelrules.svc.static.microsoft/rules/rule120633v0s19.xmlfalse
                                                                                high
                                                                                https://otelrules.svc.static.microsoft/rules/rule120609v0s19.xmlfalse
                                                                                  high
                                                                                  https://otelrules.svc.static.microsoft/rules/rule120636v0s19.xmlfalse
                                                                                    high
                                                                                    https://otelrules.svc.static.microsoft/rules/rule120627v0s19.xmlfalse
                                                                                      high
                                                                                      https://otelrules.svc.static.microsoft/rules/rule120618v0s19.xmlfalse
                                                                                        high
                                                                                        https://otelrules.svc.static.microsoft/rules/rule120642v0s19.xmlfalse
                                                                                          high
                                                                                          https://otelrules.svc.static.microsoft/rules/rule120629v0s19.xmlfalse
                                                                                            high
                                                                                            https://otelrules.svc.static.microsoft/rules/rule120623v0s19.xmlfalse
                                                                                              high
                                                                                              https://otelrules.svc.static.microsoft/rules/rule120652v0s19.xmlfalse
                                                                                                high
                                                                                                https://planrenovecaldera.com/favicon.icofalse
                                                                                                • Avira URL Cloud: safe
                                                                                                unknown
                                                                                                https://x2bm.com/favicon.icotrue
                                                                                                • Avira URL Cloud: safe
                                                                                                unknown
                                                                                                https://otelrules.svc.static.microsoft/rules/rule120658v0s19.xmlfalse
                                                                                                  high
                                                                                                  https://otelrules.svc.static.microsoft/rules/rule120635v0s19.xmlfalse
                                                                                                    high
                                                                                                    https://otelrules.svc.static.microsoft/rules/rule120612v0s19.xmlfalse
                                                                                                      high
                                                                                                      https://otelrules.svc.static.microsoft/rules/rule120640v0s19.xmlfalse
                                                                                                        high
                                                                                                        https://otelrules.svc.static.microsoft/rules/rule120634v0s19.xmlfalse
                                                                                                          high
                                                                                                          https://otelrules.svc.static.microsoft/rules/rule120641v0s19.xmlfalse
                                                                                                            high
                                                                                                            https://otelrules.svc.static.microsoft/rules/rule120628v0s19.xmlfalse
                                                                                                              high
                                                                                                              https://x2bm.com/files/images/Logo.pngtrue
                                                                                                              • Avira URL Cloud: safe
                                                                                                              unknown
                                                                                                              https://otelrules.svc.static.microsoft/rules/rule120617v0s19.xmlfalse
                                                                                                                high
                                                                                                                https://otelrules.svc.static.microsoft/rules/rule120611v0s19.xmlfalse
                                                                                                                  high
                                                                                                                  https://otelrules.svc.static.microsoft/rules/rule120646v0s19.xmlfalse
                                                                                                                    high
                                                                                                                    https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
                                                                                                                      high
                                                                                                                      https://otelrules.svc.static.microsoft/rules/rule120664v0s19.xmlfalse
                                                                                                                        high
                                                                                                                        https://otelrules.svc.static.microsoft/rules/rule120610v0s19.xmlfalse
                                                                                                                          high
                                                                                                                          https://otelrules.svc.static.microsoft/rules/rule120619v0s19.xmlfalse
                                                                                                                            high
                                                                                                                            https://otelrules.svc.static.microsoft/rules/rule120613v0s19.xmlfalse
                                                                                                                              high
                                                                                                                              https://otelrules.svc.static.microsoft/rules/rule120625v0s19.xmlfalse
                                                                                                                                high
                                                                                                                                https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/css/all.min.cssfalse
                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                unknown
                                                                                                                                https://otelrules.svc.static.microsoft/rules/rule120662v0s19.xmlfalse
                                                                                                                                  high
                                                                                                                                  https://otelrules.svc.static.microsoft/rules/rule120622v0s19.xmlfalse
                                                                                                                                    high
                                                                                                                                    https://otelrules.svc.static.microsoft/rules/rule120653v0s19.xmlfalse
                                                                                                                                      high
                                                                                                                                      https://www.w3schools.com/w3css/4/w3.cssfalse
                                                                                                                                        high
                                                                                                                                        https://otelrules.svc.static.microsoft/rules/rule120616v0s19.xmlfalse
                                                                                                                                          high
                                                                                                                                          https://otelrules.svc.static.microsoft/rules/rule120631v0s19.xmlfalse
                                                                                                                                            high
                                                                                                                                            https://vardhadevelco.com/favicon.icofalse
                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                            unknown
                                                                                                                                            https://otelrules.svc.static.microsoft/rules/rule120656v0s19.xmlfalse
                                                                                                                                              high
                                                                                                                                              https://otelrules.svc.static.microsoft/rules/rule120647v0s19.xmlfalse
                                                                                                                                                high
                                                                                                                                                https://cdn.socket.io/4.7.5/socket.io.min.jsfalse
                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                unknown
                                                                                                                                                https://otelrules.svc.static.microsoft/rules/rule120665v0s19.xmlfalse
                                                                                                                                                  high
                                                                                                                                                  https://otelrules.svc.static.microsoft/rules/rule120659v0s19.xmlfalse
                                                                                                                                                    high
                                                                                                                                                    https://otelrules.svc.static.microsoft/rules/rule120626v0s19.xmlfalse
                                                                                                                                                      high
                                                                                                                                                      https://otelrules.svc.static.microsoft/rules/rule120620v0s19.xmlfalse
                                                                                                                                                        high
                                                                                                                                                        https://otelrules.svc.static.microsoft/rules/rule120632v0s19.xmlfalse
                                                                                                                                                          high
                                                                                                                                                          https://otelrules.svc.static.microsoft/rules/rule120600v5s19.xmlfalse
                                                                                                                                                            high
                                                                                                                                                            https://a.nel.cloudflare.com/report/v4?s=VyBFkAHVLOmj%2F9GiVlmeeA6dv5cddZmw9unXJ0yObcKCeoj27S2pltJpcDXw5PWzFpv0EiQnJhC8pOL6RpmpDYvqu%2FXzxE%2FwySsSUlsgjYVSwfYAnShbzt0oAd7odVKDaxdwgLg%3Dfalse
                                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                                            unknown
                                                                                                                                                            https://otelrules.svc.static.microsoft/rules/rule120638v0s19.xmlfalse
                                                                                                                                                              high
                                                                                                                                                              https://aadcdn.msftauth.net/shared/1.0/content/images/picker_verify_code_b41922ebdaebec16b19999fc6054a15a.svgfalse
                                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                                              unknown
                                                                                                                                                              https://otelrules.svc.static.microsoft/rules/rule120644v0s19.xmlfalse
                                                                                                                                                                high
                                                                                                                                                                https://download.logo.wine/logo/Microsoft_Outlook/Microsoft_Outlook-Logo.wine.pngfalse
                                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                                unknown
                                                                                                                                                                https://otelrules.svc.static.microsoft/rules/rule120650v0s19.xmlfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://otelrules.svc.static.microsoft/rules/rule120608v0s19.xmlfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://otelrules.svc.static.microsoft/rules/rule120637v0s19.xmlfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://otelrules.svc.static.microsoft/rules/rule120643v0s19.xmlfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://otelrules.svc.static.microsoft/rules/rule120649v0s19.xmlfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://otelrules.svc.static.microsoft/rules/rule120661v0s19.xmlfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://otelrules.svc.static.microsoft/rules/rule120655v0s19.xmlfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://otelrules.svc.static.microsoft/rules/rule120614v0s19.xmlfalse
                                                                                                                                                                                high
                                                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                                                • 75% < No. of IPs
                                                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                95.101.182.65
                                                                                                                                                                                e329293.dscd.akamaiedge.netEuropean Union
                                                                                                                                                                                20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                51.210.156.4
                                                                                                                                                                                vardhadevelco.comFrance
                                                                                                                                                                                16276OVHFRfalse
                                                                                                                                                                                216.58.206.78
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                173.194.76.84
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                13.107.246.60
                                                                                                                                                                                s-part-0032.t-0009.t-msedge.netUnited States
                                                                                                                                                                                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                216.58.206.36
                                                                                                                                                                                www.google.comUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                142.250.181.238
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                18.245.31.5
                                                                                                                                                                                d2vgu95hoyrpkh.cloudfront.netUnited States
                                                                                                                                                                                16509AMAZON-02USfalse
                                                                                                                                                                                35.190.80.1
                                                                                                                                                                                a.nel.cloudflare.comUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                142.250.184.227
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                172.217.18.110
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                162.241.203.10
                                                                                                                                                                                x2bm.comUnited States
                                                                                                                                                                                26337OIS1UStrue
                                                                                                                                                                                142.250.74.195
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                142.250.184.195
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                1.1.1.1
                                                                                                                                                                                unknownAustralia
                                                                                                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                                                                                                172.67.216.162
                                                                                                                                                                                planrenovecaldera.comUnited States
                                                                                                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                                                                                                142.250.185.234
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                172.217.18.3
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                216.58.206.42
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                2.16.164.34
                                                                                                                                                                                unknownEuropean Union
                                                                                                                                                                                20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                64.233.167.84
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                13.107.253.72
                                                                                                                                                                                s-part-0044.t-0009.fb-t-msedge.netUnited States
                                                                                                                                                                                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                188.114.96.3
                                                                                                                                                                                download.logo.wineEuropean Union
                                                                                                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                                                                                                104.17.25.14
                                                                                                                                                                                cdnjs.cloudflare.comUnited States
                                                                                                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                                                                                                95.101.54.104
                                                                                                                                                                                a1400.dscb.akamai.netEuropean Union
                                                                                                                                                                                34164AKAMAI-LONGBfalse
                                                                                                                                                                                IP
                                                                                                                                                                                192.168.2.17
                                                                                                                                                                                Joe Sandbox version:42.0.0 Malachite
                                                                                                                                                                                Analysis ID:1643219
                                                                                                                                                                                Start date and time:2025-03-19 16:37:45 +01:00
                                                                                                                                                                                Joe Sandbox product:CloudBasic
                                                                                                                                                                                Overall analysis duration:
                                                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                                                Report type:full
                                                                                                                                                                                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                                                                                                Sample URL:https://vardhadevelco.com/365confirmation.php
                                                                                                                                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                Number of analysed new started processes analysed:14
                                                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                                                Technologies:
                                                                                                                                                                                • EGA enabled
                                                                                                                                                                                Analysis Mode:stream
                                                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                                                Detection:MAL
                                                                                                                                                                                Classification:mal84.phis.win@24/0@45/233
                                                                                                                                                                                • Exclude process from analysis (whitelisted): svchost.exe
                                                                                                                                                                                • Excluded IPs from analysis (whitelisted): 216.58.206.78, 172.217.18.3, 142.250.181.238, 64.233.167.84
                                                                                                                                                                                • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, clientservices.googleapis.com, clients.l.google.com
                                                                                                                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                • VT rate limit hit for: https://vardhadevelco.com/365confirmation.php
                                                                                                                                                                                No created / dropped files found
                                                                                                                                                                                No static file info