Windows Analysis Report
https://australianfoodandfibre.servicedeskplus.net.au/app/itdesk/ui/requests/867000003351579/details

Overview

General Information

Sample URL: https://australianfoodandfibre.servicedeskplus.net.au/app/itdesk/ui/requests/867000003351579/details
Analysis ID: 1500939
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D HTTP Parser: Title: Redirecting does not match URL
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: Title: Sign in to your account does not match URL
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: <input type="password" .../> found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D HTTP Parser: No favicon
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/b2a7b211-552b-4fc5-ad0d-b35b3a237e3e/saml2?SAMLRequest=fVJbb5swFP4ryO%2BAMZckVojEGk2L1G2oyfrQl8rgQ2LJ2MzHZJdfP6BrFWlaX7%2Fj892Otyh6PfBq9BfzAN9HQB%2F87LVBvgxKMjrDrUCF3IgekPuWH6vP95xFlA%2FOettaTYLDviTPhcw2LE2STnarrBCySaEp0nzdrCnrRCGSFcs2tCDBIzhU1pRkIpl2EUc4GPTC%2BAmiLAvpOmSbE814xjgroiSlTyT4aF0Li9GSdEIjzKu1QFRXeEPqv5Y%2BKCOVOb%2Fvv3l5hPzT6VSH9dfjiQQVIjg%2FubuzBsce3BHcVbXw7eG%2BJBfvB%2BRxLNrWjsZj9NtebNTaPhJjjOpslInn3nCIV5QmLJsDk2A%2FtaqM8EvmVw5tz8pEvWqdRdt5a7QyMHPFDROrhiVJmOesCbOuzUMhqQybNG9SwdIVpLDIsCXvVUlwX6ZwJXma7JDddp7xpVZ3c8z3uxCvucnuJtQ2vuF6IR74rHXY11ar9ldQaW1%2F3DkQftL3boTlUL3w%2F5dLomRBlAy75SmHXihdSekAcfIf%2F6vzBt7%2B1N0f&RelayState=aHR0cHM6Ly9hdXN0cmFsaWFuZm9vZGFuZGZpYnJlLnNlcnZpY2VkZXNrcGx1cy5uZXQuYXUvYXBwL2l0ZGVzay91aS9yZXF1ZXN0cy84NjcwMDAwMDMzNTE1NzkvZGV0YWlsc19fSUFNX19TRFBPbkRlbWFuZF9fSUFNX19fX0lBTV9fZmFsc2U%3D&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.5:49774 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /app/itdesk/ui/requests/867000003351579/details HTTP/1.1Host: australianfoodandfibre.servicedeskplus.net.auConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /Login.jsp?serviceurl=%2Fapp%2Fitdesk%2Fui%2Frequests%2F867000003351579%2Fdetails HTTP/1.1Host: australianfoodandfibre.servicedeskplus.net.auConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: zalb_d63ded2016=334acadbc5509b416865a4b31a1455f9; sdpcscook=e0a4aa81-c837-4c81-9c03-403e58b77894; _zcsr_tmp=e0a4aa81-c837-4c81-9c03-403e58b77894
Source: global traffic HTTP traffic detected: GET /samlauthrequest/aff-limited.com.au?serviceurl=https%3A%2F%2Faustralianfoodandfibre.servicedeskplus.net.au%2Fapp%2Fitdesk%2Fui%2Frequests%2F867000003351579%2Fdetails&servicename=SDPOnDemand&portal_id=7001242490&hide_signup=false HTTP/1.1Host: accounts.zoho.com.auConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_qzvqnltrxpy99ajspyxbgq2.css HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_2P9n4TNNrWcgKwW6Mt6tGA2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_tzwwq6wdslxjdiwzdatg6a2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_tzwwq6wdslxjdiwzdatg6a2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_2P9n4TNNrWcgKwW6Mt6tGA2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/watsonsupportwithjquery.3.5.min_dc940oomzau4rsu8qesnvg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_2P9n4TNNrWcgKwW6Mt6tGA2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/frameworksupport.min_oadrnc13magb009k4d20lg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/watsonsupportwithjquery.3.5.min_dc940oomzau4rsu8qesnvg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/watson.min_q5ptmu8aniymd4ftuqdkda2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/frameworksupport.min_oadrnc13magb009k4d20lg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/watson.min_q5ptmu8aniymd4ftuqdkda2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6c7dc46bb93924417b57.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_758d4d3367a37038a3b2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_6c7dc46bb93924417b57.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /81d6b03a-0oaqvemumiggapupispz73q-euqm382uqpsqys7gkkc/logintenantbranding/0/illustration?ts=637640617494988131 HTTP/1.1Host: aadcdn.msftauthimages.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_758d4d3367a37038a3b2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_92013fd9f2f609d397ae.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /81d6b03a-0oaqvemumiggapupispz73q-euqm382uqpsqys7gkkc/logintenantbranding/0/illustration?ts=637640617494988131 HTTP/1.1Host: aadcdn.msftauthimages.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_92013fd9f2f609d397ae.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: australianfoodandfibre.servicedeskplus.net.au
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: accounts.zoho.com.au
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: identity.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauthimages.net
Source: global traffic DNS traffic detected: DNS query: autologon.microsoftazuread-sso.com
Source: chromecache_172.2.dr, chromecache_176.2.dr String found in binary or memory: http://feross.org
Source: chromecache_162.2.dr, chromecache_165.2.dr String found in binary or memory: http://gsgd.co.uk/sandbox/jquery/easing/
Source: chromecache_166.2.dr, chromecache_171.2.dr, chromecache_150.2.dr String found in binary or memory: http://knockoutjs.com/
Source: chromecache_166.2.dr, chromecache_171.2.dr, chromecache_150.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
Source: chromecache_179.2.dr, chromecache_156.2.dr, chromecache_166.2.dr, chromecache_171.2.dr, chromecache_172.2.dr, chromecache_176.2.dr, chromecache_150.2.dr, chromecache_149.2.dr, chromecache_160.2.dr, chromecache_168.2.dr, chromecache_163.2.dr String found in binary or memory: https://github.com/douglascrockford/JSON-js
Source: chromecache_146.2.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_146.2.dr String found in binary or memory: https://login.windows-ppe.net
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: classification engine Classification label: clean2.win@22/59@24/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2596 --field-trial-handle=1680,i,1339453569381203706,9538536799603884749,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://australianfoodandfibre.servicedeskplus.net.au/app/itdesk/ui/requests/867000003351579/details"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2596 --field-trial-handle=1680,i,1339453569381203706,9538536799603884749,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs