Click to jump to signature section
Source: https://794609.documents.savethenote2.com/healthesystems/viewAgreement?tsid=ZGFyeWxAaGVhbHRoZXN5c3RlbXMuY29t#%25EMAILX | SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering |
Source: unknown | HTTPS traffic detected: 163.181.56.168:443 -> 192.168.2.4:49775 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 23.35.236.56:443 -> 192.168.2.4:49803 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.190.159.70:443 -> 192.168.2.4:49805 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.190.159.70:443 -> 192.168.2.4:49806 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.50.102.62:443 -> 192.168.2.4:49807 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.50.102.62:443 -> 192.168.2.4:49808 version: TLS 1.2 |
Source: unknown | DNS traffic detected: queries for: clients2.google.com |
Source: unknown | Network traffic detected: HTTP traffic on port 49758 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49765 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49720 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49763 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49761 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49780 |
Source: unknown | Network traffic detected: HTTP traffic on port 49720 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49803 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49807 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49805 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49758 |
Source: unknown | Network traffic detected: HTTP traffic on port 49753 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49757 |
Source: unknown | Network traffic detected: HTTP traffic on port 49755 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49756 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49755 |
Source: unknown | Network traffic detected: HTTP traffic on port 49757 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49754 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49753 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49775 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49752 |
Source: unknown | Network traffic detected: HTTP traffic on port 49761 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49765 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49763 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49780 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49804 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49808 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49806 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49808 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49807 |
Source: unknown | Network traffic detected: HTTP traffic on port 49752 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49775 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49806 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49805 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49804 |
Source: unknown | Network traffic detected: HTTP traffic on port 49754 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49803 |
Source: unknown | Network traffic detected: HTTP traffic on port 49756 -> 443 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 131.253.33.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.248.119.254 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.184.220.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.236.56 |
Source: global traffic | HTTP traffic detected: GET /v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=310091&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:D9BC7EDF-91E8-C8ED-3ED4-3B144B30C00C&ctry=US&time=20220308T094328Z&lc=en-US&pl=en-US&idtp=mid&uid=a9223225-82ba-4622-a95e-dcecd6738abd&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=340fcbd17d984582956074ac2676dc1d&ctmode=MultiSession&arch=x64&cdm=1&cdmver=10.0.17134.1&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.17134.1&disphorzres=1280&dispsize=17.1&dispvertres=1024&isu=0&lo=1417890&metered=false&nettype=ethernet&npid=sc-310091&oemName=VMware%2C%20Inc.&oemid=VMware%2C%20Inc.&ossku=Professional&rver=2&smBiosDm=VMware7%2C1&tl=2&tsu=1417890&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing= HTTP/1.1Accept-Encoding: gzip, deflateX-SDK-CACHE: chs=0&imp=0&chf=0&ds=50583&fs=32089&sc=6Cache-Control: no-cacheMS-CV: 3Frur/zANU+2hPRe.0User-Agent: WindowsShellClient/9.0.40929.0 (Windows)X-SDK-HWF: tch0,m301,m751,mA01,mT01Host: arc.msn.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=314559&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:D9BC7EDF-91E8-C8ED-3ED4-3B144B30C00C&ctry=US&time=20220308T094328Z&lc=en-US&pl=en-US&idtp=mid&uid=a9223225-82ba-4622-a95e-dcecd6738abd&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=0cd746982547431ebc0f1410502cc6dc&ctmode=MultiSession&arch=x64&cdm=1&cdmver=10.0.17134.1&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.17134.1&disphorzres=1280&dispsize=17.1&dispvertres=1024&isu=0&lo=1417890&metered=false&nettype=ethernet&npid=sc-314559&oemName=VMware%2C%20Inc.&oemid=VMware%2C%20Inc.&ossku=Professional&smBiosDm=VMware7%2C1&tl=2&tsu=1417890&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing= HTTP/1.1Accept-Encoding: gzip, deflateX-SDK-CACHE: chs=0&imp=0&chf=0&ds=50583&fs=32089&sc=6Cache-Control: no-cacheMS-CV: 3Frur/zANU+2hPRe.0User-Agent: WindowsShellClient/9.0.40929.0 (Windows)X-SDK-HWF: tch0,m301,m751,mA01,mT01Host: arc.msn.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-85.0.4183.121Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8 |
Source: global traffic | HTTP traffic detected: GET /healthesystems/viewAgreement?tsid=ZGFyeWxAaGVhbHRoZXN5c3RlbXMuY29t HTTP/1.1Host: 794609.documents.savethenote2.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8 |
Source: global traffic | HTTP traffic detected: GET /300/150/?image=824 HTTP/1.1Host: picsum.photosConnection: keep-aliveOrigin: https://794609.documents.savethenote2.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://794609.documents.savethenote2.com/healthesystems/viewAgreement?tsid=ZGFyeWxAaGVhbHRoZXN5c3RlbXMuY29tAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8 |
Source: global traffic | HTTP traffic detected: GET //2.6.3/images/icon_light.f13cff3.png HTTP/1.1Host: cstaticdun.126.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://794609.documents.savethenote2.com/healthesystems/viewAgreement?tsid=ZGFyeWxAaGVhbHRoZXN5c3RlbXMuY29tAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8 |
Source: global traffic | HTTP traffic detected: GET /id/824/300/150.jpg?hmac=YLOxcCAmebF9Wvsp1kXa3AWYWkixtbvoNd_HdkCBBTE HTTP/1.1Host: i.picsum.photosConnection: keep-aliveOrigin: nullUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://794609.documents.savethenote2.com/healthesystems/viewAgreement?tsid=ZGFyeWxAaGVhbHRoZXN5c3RlbXMuY29tAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 794609.documents.savethenote2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://794609.documents.savethenote2.com/healthesystems/viewAgreement?tsid=ZGFyeWxAaGVhbHRoZXN5c3RlbXMuY29tAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8 |
Source: global traffic | HTTP traffic detected: GET //2.6.3/images/icon_light.f13cff3.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: cstaticdun.126.net |
Source: global traffic | HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Thu, 20 Apr 2017 16:10:39 GMTUser-Agent: Microsoft BITS/7.8Host: fs.microsoft.com |
Source: global traffic | HTTP traffic detected: GET /v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=280815&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:D9BC7EDF-91E8-C8ED-3ED4-3B144B30C00C&ctry=US&time=20220517T134422Z&lc=en-US&pl=en-US&idtp=mid&uid=a9223225-82ba-4622-a95e-dcecd6738abd&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=a7b9b775e4244c17a2ebb9b348f2e15b&ctmode=MultiSession&arch=x64&cdm=1&cdmver=10.0.17134.1&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.17134.1&disphorzres=1280&dispsize=17.1&dispvertres=1024&isu=0&lo=1518931&metered=false&nettype=ethernet&npid=sc-280815&oemName=hqfxfl%2C%20Inc.&oemid=hqfxfl%2C%20Inc.&ossku=Professional&smBiosDm=hqfxfl7%2C1&tl=2&tsu=1518931&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing= HTTP/1.1Accept-Encoding: gzip, deflateX-SDK-CACHE: chs=0&imp=0&chf=0&ds=50583&fs=32089&sc=6X-SDK-HW-TOKEN: t=EwDgAppeBAAUlAKXDAofTQM+n+MaRVFKzH/ehWgAARv7pEmU4rHAqGoJtj7oLSB7v2mwo43vyD+jN/gk3QZIlZytJXk/gSdJdrqom9LMkpbx5q52rTOUcWeySoU1PLcNmtBMdJaE6JD0HtBaB5hCqsJVawrWly7rtJA8RvE8yD5/UA7Go+f/Y5zG9wg5eei7acRCsS7+kaTbNsSVG+99ds/Q2CN2lULRIyni/dGAvALBGERxqjkkAvrMGuVYqrXHljAAZpFbJEYX4mICp3VJTA0p6oFnLhdLQnZFrFHiBwNh/zPgYz3DH1DGAHfXOCa9J8Ht4vCrKGPIrpA3r5dFe8wNhXN1b0bwPmboXlmVS9zyZQtCNG4TcACF9m3bQWYDZgAACLw17X7Ub0dbsAGKuSJVgxSwi0tKQ+TNf8JJmL63B6BCOLjUH5I+HTsU8HL8yBmScnGFeIUjxwABKk+yQ5FuYoKT5el5ZHhj8bK/Lqgj2K0jXexFv7So5dDFHGWBt/QM4LK7IXpkrhPtQexjN1XRl9ZimwP4ARxK2pvZ4JDKsiviJE5gvFkNdqB1Qcmt1xO3KPVbtBBK4Ima8M5aPihMW+E4jO3oLOEE79zsH0ZpeZUcspD2tc9+tCOKvnjbx8UmAnJ4g7gN9gXI4NtvliRjBiozoyQJqTkrjnFofBvyaou/IPhBBD3yALwiEV8aKDiVhLAGu6bgzrHeiPPOR/huZtUW9poR1Qg+eB1ypgElFq0oSFqqFtidpV1/oDjd87FjqUtfMiu2gC7SmpbaRkCnKkBmwkEbBkbOVZ1dihVEFnZcOv/mED6OR6bAIZqSXYR4WK0KQVoEnKI75+po0gwgsjfS7vnrhE/wtE4SqLk+byXg0nYEmbeCw7UW7SOGzDrZmR2ki1DEXXfenU4Gj2a7j/92itPbvh214HIE+AdnxOU3zRK9XliCU2wNcbhbXD7y9+BCqM3DEKZmGBLVAQ==&p=Cache-Control: no-cacheMS-CV: yZRXp+ETA0iBnc90.0User-Agent: WindowsShellClient/9.0.40929.0 (Windows)X-SDK-HWF: tch0,m301,m751,mA01,mT01Host: arc.msn.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=338389&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:D9BC7EDF-91E8-C8ED-3ED4-3B144B30C00C&ctry=US&time=20220517T134422Z&lc=en-US&pl=en-US&idtp=mid&uid=a9223225-82ba-4622-a95e-dcecd6738abd&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=88de42ba51a74435b63ce5307e97d3db&ctmode=MultiSession&arch=x64&cdm=1&cdmver=10.0.17134.1&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.17134.1&disphorzres=1280&dispsize=17.1&dispvertres=1024&isu=0&lo=1518931&metered=false&nettype=ethernet&npid=sc-338389&oemName=hqfxfl%2C%20Inc.&oemid=hqfxfl%2C%20Inc.&ossku=Professional&smBiosDm=hqfxfl7%2C1&tl=2&tsu=1518931&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing= HTTP/1.1Accept-Encoding: gzip, deflateX-SDK-CACHE: chs=0&imp=0&chf=0&ds=50583&fs=32089&sc=6X-SDK-HW-TOKEN: t=EwDgAppeBAAUlAKXDAofTQM+n+MaRVFKzH/ehWgAAYsYKM5ZU2Pb/75z7e4LkjPFpqpXjR3ia8MwwiKgB042MZCULMjptCZQbXpXYTIhKbJ4vhYwiZu05TXgF+bzBFAPoIf+cYoXdWxtXqTod94sJJWfQ6OYTFdX7heii6jJwXFfP8w4XBsKTzmFP/j3T2rysSlmlPEH6NyTIJAe+xtuOzwsMkHq9LCEeeIhl5/Xn1X0kQl3D2r9/nTMXYHny8N455ERdLDjTld7e27bmlq0RTK0OzxW9pkPFm006asI+yrfcg026+McHDK1YfEnKubX2GRshPOd/d/v/Dm1mYGXI19oT8IflwJKcQELOjev7cGQTNrTFxicy/1WGNAmZZYDZgAACKQR4ZejftO5sAH80dZ2R2rL48TFIxX0JqvOA3il6Q7oHrPELZYGQ2kZaFg2844HDd71owhVaOWvnMbJT1ouHXTKAvn8n3548hiodrutgVBXPnwf9anVHO+HBDHouooXHP5y7JY6GrrydpoUojV4MAGYtZHIu2EziJ68sZPUARTQhbEezd8mOwMvEEQegHv9yFCqq23/4iUrXq2v1HywyX0p9MNp55o4iUmimGn/gcA6+WK8VqBX77uAlB5Ib7DlkZgMqj32uzBndxA5KoklC1Bqasf9I5WfR23gxL1xfT8lmliCkIhcddART8CHYT0DDrPq7HmV+jL5Y9QLBJDB8jpkGlC/QZl1WpskHkpivv0j/V1IAkMbI0ZJBnkJMPMSPJJ4iAcOuzhTVzM9G7SYKbCBG5JyKyfJv6EA5Z7ohDI3UWuN8yoivQ/m6ubqs4jZxzWtm/hiO92BYld4gsrufiGO+KQn35fEJwFJrDXCVh2LG0cuE254mIv97LcIWQAIfuEqYyOJ/Q59k+4qDO3HlL7UdavBbeMKkO6DUqMpYS9MRxg/rJqNZ4Zf0H/UzMJSm1QgtmzDwDkXry7VAQ==&p=Cache-Control: no-cacheMS-CV: yZRXp+ETA0iBnc90.0User-Agent: WindowsShellClient/9.0.40929.0 (Windows)X-SDK-HWF: tch0,m301,m751,mA01,mT01Host: arc.msn.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 17 May 2022 13:43:51 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeAccept-Ranges: bytesContent-Length: 10855Content-Type: text/html |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 17 May 2022 13:43:52 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, closeAccept-Ranges: bytesContent-Length: 10855Content-Type: text/html |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://accounts.google.com |
Source: craw_window.js.0.dr | String found in binary or memory: https://accounts.google.com/MergeSession |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://apis.google.com |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://clients2.google.com |
Source: manifest.json.0.dr | String found in binary or memory: https://clients2.google.com/service/update2/crx |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://clients2.googleusercontent.com |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr, f3713998-9dc4-4d07-a259-ed8b9f4487ce.tmp.1.dr | String found in binary or memory: https://dns.google |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://fonts.googleapis.com |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://fonts.gstatic.com |
Source: craw_window.js.0.dr, craw_background.js.0.dr | String found in binary or memory: https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://ogs.google.com |
Source: craw_window.js.0.dr, manifest.json.0.dr | String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://play.google.com |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://r5---sn-h0jeln7l.gvt1.com |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://redirector.gvt1.com |
Source: craw_window.js.0.dr, manifest.json.0.dr | String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://ssl.gstatic.com |
Source: craw_window.js.0.dr, craw_background.js.0.dr | String found in binary or memory: https://www-googleapis-staging.sandbox.google.com |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://www.google.com |
Source: manifest.json.0.dr | String found in binary or memory: https://www.google.com/ |
Source: craw_window.js.0.dr | String found in binary or memory: https://www.google.com/accounts/OAuthLogin?issueuberauth=1 |
Source: craw_window.js.0.dr | String found in binary or memory: https://www.google.com/images/cleardot.gif |
Source: craw_window.js.0.dr | String found in binary or memory: https://www.google.com/images/dot2.gif |
Source: craw_window.js.0.dr | String found in binary or memory: https://www.google.com/images/x2.gif |
Source: craw_background.js.0.dr | String found in binary or memory: https://www.google.com/intl/en-US/chrome/blank.html |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr, craw_window.js.0.dr, craw_background.js.0.dr | String found in binary or memory: https://www.googleapis.com |
Source: manifest.json.0.dr | String found in binary or memory: https://www.googleapis.com/ |
Source: manifest.json.0.dr | String found in binary or memory: https://www.googleapis.com/auth/chromewebstore |
Source: manifest.json.0.dr | String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly |
Source: manifest.json.0.dr | String found in binary or memory: https://www.googleapis.com/auth/sierra |
Source: manifest.json.0.dr | String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox |
Source: 89c591ae-3842-475c-aea8-3969c74e8deb.tmp.1.dr | String found in binary or memory: https://www.gstatic.com |
Source: unknown | HTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitContent-type: text/xmlX-MSEdge-ExternalExpType: JointCoordX-MSEdge-ExternalExp: d-thshld39,d-thshld42,d-thshld77,d-thshld78,d-thshldspcl40X-PositionerType: DesktopX-Search-CortanaAvailableCapabilities: CortanaExperience,SpeechLanguageX-Search-SafeSearch: ModerateX-Device-MachineId: {A2AB526A-D38D-4FC9-8BA0-E34B8D6354E8}X-UserAgeClass: UnknownX-BM-Market: USX-BM-DateFormat: M/d/yyyyX-CortanaAccessAboveLock: falseX-Device-OSSKU: 48X-BM-DTZ: 60X-BM-FirstEnabledTime: 132061327679472806X-DeviceID: 0100748C0900D485X-BM-DeviceScale: 100X-Search-TimeZone: Bias=-60; StandardBias=0; TimeZoneKeyName=W. Europe Standard TimeX-BM-Theme: 000000;0078d7X-BM-DeviceDimensionsLogical: 1232x1024X-BM-DeviceDimensions: 1232x1024X-Search-RPSToken: t%3DEwDYAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAcrCUQHVmc1QWYMPz0DXFqeRx8wamoowmwbwUSyNYpjtyJpJRDfEtLg1rKS4/zxABCoKsuMFRUBIP7PFid4xD2qKyI0URDzKuBMFjFkKzlG3Ps9MGF%2BBZXTdKnpAzZrlgOtRPCtamchXz28q0CRmPxXD6ZHI2rcMOvnUBLbt1zkoTBTKYibaVaGygpAEYQDTKkpAamKV8eOep8EnHN50LiR92MCKiQtLylSx/qTDVfvmE81bne2UzPZEbqlm/DPuKdzajAWp%2BXa91MUXk%2BgPu95uggy8QPGrNOWbn7IkTjFjqBdAhJ5m/BiU45rQu3ck%2B6RC%2BU%2BEalYU42PwbfQmsDwDZgAACHBtXI8rJNLaqAG5bveMLq14sdqoo9yPGDTdHxA7OjsAOmIxUTUXgi%2B44zK9rStYOMPMq4e6et15tJFBbG2jKGVdJMY3ZkTFu%2BHWNopmckOWLVgFNq79y3hmsdxc1wOedU50wO01k4tR95v4Imjx%2BJujGLa9TWHvuxeDQi9Y4ybY/y9vY1LteXSo0kKHbGazTsLNxyFfmSDOcn8ClbW9bmk0c4jHKD1yRpmMUoJ6GMEDPMqNOCkwrk63Ab7wPb/Ik//Xt/R1gr%2Bom7Tc2OeYYcdyru5UC/xxsJOAvl6NlTvqnrrwv3tNwIcpsdUqBF6TuxWSlAQvZrc4R0FfqAmC1gmCnHgcn6LOJmRb0NP4X2cysqVe7yMirSTCCMByWMIyPaVuut%2BME7E/g1i7%2BF6GOmOb4jaw5esWXZItZITutJph%2B%2BiB5Jhj5m5K8KwagRMAS5gWCtioSFd8CezxoiPqJxEvqdn2z7PYPJa2IEPLnuo8hgVRtHuU8/aTQiACqk%2BA7ilNPbpjD1XsiVE35rwQalWYecZgjOX1bVhMm1bTSpRC5s14qea2UC8ENIkJSR9nRsud1AE%3D%26p%3DX-Agent-DeviceId: 0100748C0900D485X-BM-CBT: 1646732532X-Device-isOptin: trueX-Device-Touch: falseX-Device-ClientSession: B3FD0EB2977A44E390C07B484049F516X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-BM-ClientFeatures: pbitcpdisabled,AmbientWidescreen,rs1musicprod,CortanaSPAXamlHeaderAccept: */*Accept-Language: en-USAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.10.7.17134; 10.0.0.0.17134.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/17.17134Host: www.bing.comContent-Length: 87238Conne |