Windows Analysis Report
https://nam.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fadmin.microsoft.com%2Fadminportal%2Fhome%3F%23%2FsubscriΡtions&p=bT0yNzlhNjA0ZS05MTMyLTQyNDYtYjQwOC1kZTQzOWFlMmRmNTMmcz0wMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAmdT1hZW8mbD1ob21l

Overview

General Information

Sample URL: https://nam.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fadmin.microsoft.com%2Fadminportal%2Fhome%3F%23%2FsubscriΡtions&p=bT0yNzlhNjA0ZS05MTMyLTQyNDYtYjQwOC1kZTQzOWFlMmRmNTMmcz0wMDAwM
Analysis ID: 1520812
Infos:

Detection

Score: 4
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Detected non-DNS traffic on DNS port
Detected suspicious crossdomain redirect
Found iframes
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: Iframe src: https://fpt.live.com?session_id=3d90045f99d5477f8d646f39ea9b8305&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SI
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: Iframe src: https://fpt.live.com?session_id=3d90045f99d5477f8d646f39ea9b8305&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SI
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: Iframe src: https://fpt.live.com?session_id=3d90045f99d5477f8d646f39ea9b8305&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SI
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: Iframe src: https://fpt.live.com?session_id=3d90045f99d5477f8d646f39ea9b8305&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SI
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: Iframe src: https://fpt.live.com?session_id=3d90045f99d5477f8d646f39ea9b8305&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SI
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0 HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: Number of links: 0
Source: https://account.live.com/ResetPassword.aspx?wreply=https://login.live.com/oauth20_authorize.srf%3fusername%3dcheese1%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3den-US%26username%3dcheese1%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26uaid%3d3d90045f99d5477f8d646f39ea9b8305%26contextid%3d78E186C1D25663E1%26opid%3d7ED6D70942355491%26bk%3d1727474130&id=293577&uiflavor=web&client_id=1E00004417ACAE&uaid=3d90045f99d5477f8d646f39ea9b8305&mkt=EN-US&lc=1033&bk=1727474130 HTTP Parser: Number of links: 0
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0 HTTP Parser: Base64 decoded: 4e9f3596-81a3-4f26-a701-1e7eef161b0e2e2197c5-6f39-4437-a6eb-b44725c2090e
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0 HTTP Parser: Title: Redirecting does not match URL
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: Title: Sign in to your account does not match URL
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: Title: Sign in to your Microsoft account does not match URL
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: Title: Sign in to your Microsoft account does not match URL
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: <input type="password" .../> found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: <input type="password" .../> found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0 HTTP Parser: No favicon
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: No favicon
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: No <meta name="author".. found
Source: https://account.live.com/ResetPassword.aspx?wreply=https://login.live.com/oauth20_authorize.srf%3fusername%3dcheese1%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3den-US%26username%3dcheese1%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26uaid%3d3d90045f99d5477f8d646f39ea9b8305%26contextid%3d78E186C1D25663E1%26opid%3d7ED6D70942355491%26bk%3d1727474130&id=293577&uiflavor=web&client_id=1E00004417ACAE&uaid=3d90045f99d5477f8d646f39ea9b8305&mkt=EN-US&lc=1033&bk=1727474130 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0 HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000006-0000-0ff1-ce00-000000000000&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DpWdY_La98SL5S3YBdzZjTyEiDBzCtTv9kp8Go3LkXk2orFc9lY5SKnCqDpzvW1lO-Mb8rvW_VyRZmDm2oiMRYKJ8R79xio1HHMxNJgSk4RJiYGSGozIYI6zWC7X4f0Tj6WGow_3XGKexCyWX5OLd6fQnd_gWsOwhEKJmiE0uhwirX267kB3EwtkqnZLzROCG&response_mode=form_post&nonce=638630708229418802.NGU5ZjM1OTYtODFhMy00ZjI2LWE3MDEtMWU3ZWVmMTYxYjBlMmUyMTk3YzUtNmYzOS00NDM3LWE2ZWItYjQ0NzI1YzIwOTBl&redirect_uri=https%3A%2F%2Fadmin.microsoft.com%2Flanding&ui_locales=en-US&mkt=en-US&client-request-id=3d90045f-99d5-477f-8d64-6f39ea9b8305&x-client-SKU=ID_NET472&x-client-ver=7.6.2.0&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAAjZIxjNtUHMbt5C53F5U2ahHqeBIdEJDk2c45zkmHRGI358SOL7FTx5aQlcb2-cX2ez773SXxUkE7sCDdhjg2xi5UXUBMzDd1gKUTCyo6qQgxVWLhoi6MfMOnT_p_y1_fr7zVrPE1tgY-LDI1Zv8eeCu-uvYq8H2mOvPW6T9Kb5crzsb5wa_fPOp-5eLW1bePNy_oHSeCZ15thuOn9PsBIUm2X69P3RiiWgxnKc6wT9bXejRFLkTHP9L0C5r-g6YvCpseqo71p4WM5wSeA00gsGyrwQgCYGuD7njPnquMZlhEE-8H6goAey6ziilxqigR1RxztvkgVg1rac3bkRqPV6oRclY-JoPYyjUdgIGoctd91jZlYs2HYJDLjJXLC81oRy8Lt7RPT0nArg2nMPf-Luz4OI2dBGfkoviK1hIPyW4HI-TNSG1d8xCBsymBGB2lOPFSAr3sIDFdy1GmLUFX9nTOaru5PTdWEhTbeYcYZ60wEbqYU8JJyOL0_qwVWXt6H3VOxCQ_M5lIq6oPhfTMdB6sRnYsxiyG6sjq94RRs7WEmDk8VJeD3rEeNkY9aHX1Ls5lS-Zzs9OcNHxgzHmzixcON-n2vWVnZU72NMXl_SFynWMz0xaB1O_FUAKnwQKmE5Zvhm1OWpDwBNlKPtI63efF0vU6MUaXxZvXTyHo7iYp9mHkvdigrzbe296qlO4WdqkP3gXF_e3tcoW6S-1Sbzbo7zaveWCa_3z2-us70u... HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&username=cheese1&client_id=51483342-085c-4d86-bf88-cf50c7252078&contextid=78E186C1D25663E1&opid=7ED6D70942355491&bk=1727474117&uaid=3d90045f99d5477f8d646f39ea9b8305&pid=15216 HTTP Parser: No <meta name="copyright".. found
Source: https://account.live.com/ResetPassword.aspx?wreply=https://login.live.com/oauth20_authorize.srf%3fusername%3dcheese1%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3den-US%26username%3dcheese1%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26uaid%3d3d90045f99d5477f8d646f39ea9b8305%26contextid%3d78E186C1D25663E1%26opid%3d7ED6D70942355491%26bk%3d1727474130&id=293577&uiflavor=web&client_id=1E00004417ACAE&uaid=3d90045f99d5477f8d646f39ea9b8305&mkt=EN-US&lc=1033&bk=1727474130 HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49750 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:52689 -> 1.1.1.1:53
Source: C:\Program Files\Google\Chrome\Application\chrome.exe HTTP traffic: Redirect from: nam.safelink.emails.azure.net to https://admin.microsoft.com/adminportal/home?#/subscriptions
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global traffic HTTP traffic detected: GET /redirect/?destination=https%3A%2F%2Fadmin.microsoft.com%2Fadminportal%2Fhome%3F%23%2Fsubscriptions&p=bT0yNzlhNjA0ZS05MTMyLTQyNDYtYjQwOC1kZTQzOWFlMmRmNTMmcz0wMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAmdT1hZW8mbD1ob21l HTTP/1.1Host: nam.safelink.emails.azure.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_qzvqnltrxpy99ajspyxbgq2.css HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_ELtAAt2Ya8ISGuc0PJcBKA2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_1yb3e7oii5t28dgo4xrtow2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_1yb3e7oii5t28dgo4xrtow2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_ELtAAt2Ya8ISGuc0PJcBKA2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_117b650bccea354984d8.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_117b650bccea354984d8.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_4285088f1dbaf52a876d.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_4285088f1dbaf52a876d.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=aUrdNzKYFXN+zUT&MD=2cpo+sxf HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=aUrdNzKYFXN+zUT&MD=2cpo+sxf HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/js/login_en_aPH1MdAMytMMq1WvwJPhJA2.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/js/login_en_aPH1MdAMytMMq1WvwJPhJA2.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/chunks/oneds-analytics-js_077217740c853b5d4fe8.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/2_bc3d32a696895f78c19d.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/2_bc3d32a696895f78c19d.svg HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/chunks/oneds-analytics-js_077217740c853b5d4fe8.js HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /16.000.30374.3/images/favicon.ico HTTP/1.1Host: logincdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /16.000.30374.3/images/favicon.ico HTTP/1.1Host: logincdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/js/reset-password-signinname_en_iGkKHb6MchyJTpOn_ZeIdw2.js HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://account.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/js/reset-password-signinname_en_iGkKHb6MchyJTpOn_ZeIdw2.js HTTP/1.1Host: logincdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/chunks/oneds-analytics-js_077217740c853b5d4fe8.js HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://account.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/2_bc3d32a696895f78c19d.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/chunks/oneds-analytics-js_077217740c853b5d4fe8.js HTTP/1.1Host: logincdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/favicon.ico?v=2 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/2_bc3d32a696895f78c19d.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/favicon.ico?v=2 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: nam.safelink.emails.azure.net
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: identity.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: logincdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: acctcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: fpt.live.com
Source: global traffic DNS traffic detected: DNS query: account.live.com
Source: chromecache_172.1.dr, chromecache_167.1.dr String found in binary or memory: http://fb.me/use-check-prop-types
Source: chromecache_172.1.dr, chromecache_167.1.dr String found in binary or memory: https://localcdn.centro-dev.com:5555/inline.bundle.js.map
Source: chromecache_159.1.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_159.1.dr String found in binary or memory: https://login.windows-ppe.net
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52696 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 52709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 52735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52703
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52701
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52702
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52700
Source: unknown Network traffic detected: HTTP traffic on port 52713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52709
Source: unknown Network traffic detected: HTTP traffic on port 52707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49702
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52713
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52695 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52723
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52720
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52735
Source: unknown Network traffic detected: HTTP traffic on port 52697 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52695
Source: unknown Network traffic detected: HTTP traffic on port 49702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52696
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52732
Source: unknown Network traffic detected: HTTP traffic on port 52731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52697
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52731
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 52740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52741
Source: unknown Network traffic detected: HTTP traffic on port 52734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 52720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 52745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49750 version: TLS 1.2
Source: classification engine Classification label: clean4.win@28/93@26/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1952,i,3575760107684391540,14792378179534548501,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://nam.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fadmin.microsoft.com%2Fadminportal%2Fhome%3F%23%2Fsubscriptions&p=bT0yNzlhNjA0ZS05MTMyLTQyNDYtYjQwOC1kZTQzOWFlMmRmNTMmcz0wMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAmdT1hZW8mbD1ob21l"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1952,i,3575760107684391540,14792378179534548501,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs