Windows Analysis Report
Purchase Order IBT LPO-2320.eml

Overview

General Information

Sample name: Purchase Order IBT LPO-2320.eml
Analysis ID: 1522682
MD5: 821c1536a459e770769e160eb5e51963
SHA1: 72f74407f4c97bb0cc04f5c6fd5c546f59cd82e4
SHA256: 3e3e469c7a1d9e815fa0414604e89049b629ac39b850f19cf0f2613fdd49718b
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for domain / URL
HTML page contains hidden javascript code
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores files to the Windows start menu directory

Classification

AV Detection

barindex
Source: https://ibtikar-uae.com/#webpage Virustotal: Detection: 6% Perma Link
Source: https://ibtikar-uae.com/about-us/ Virustotal: Detection: 5% Perma Link
Source: https://ibtikar-uae.com/#organization Virustotal: Detection: 6% Perma Link
Source: https://www.ibtikar-uae.com/ Virustotal: Detection: 6% Perma Link
Source: https://ibtikar-uae.com/ HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 32 32"><path d="M27.01355,23.48859l-1.753,1.75305a5.001,5.001,0,0,1-5.19928,1.18243c-1.97193-.69372-4.87335-2.36438-8.43848-5.9295S6.387,14.028,5.6933,12.05615A5.00078,5.00078,0,0,1,6.87573,6.85687L8.62...
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.17:49698 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.17:49704 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.17:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.17:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49713 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.17:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49803 version: TLS 1.2
Source: unknown HTTPS traffic detected: 2.23.209.135:443 -> 192.168.2.17:49804 version: TLS 1.2
Source: global traffic HTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br
Source: Joe Sandbox View IP Address: 23.56.162.185 23.56.162.185
Source: Joe Sandbox View IP Address: 239.255.255.250 239.255.255.250
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: Joe Sandbox View JA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: Joe Sandbox View JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.32.74
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=za46K4HxvTZRKbm&MD=RKoBGS3L HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: www.ibtikar-uae.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=za46K4HxvTZRKbm&MD=RKoBGS3L HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/click-to-chat-for-whatsapp/new/inc/assets/css/main.css?ver=4.6 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-includes/css/dist/block-library/style.min.css?ver=6.6.2 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/dynamic_avia/avia-merged-styles-01fa8b2a5466da1875f9f7eee44f980d---6645f186d06cb.css HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/dynamic_avia/avia_posts_css/post-19.css?ver=ver-1721301848 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/call-now-button/resources/style/modern.css?ver=1.4.9 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-includes/js/jquery/jquery.min.js?ver=3.7.1 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/google-analytics-for-wordpress/assets/js/frontend-gtag.min.js?ver=8.28.0 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/20220816120000-495x400.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/pixie_1703154708623-1500x844.png HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/LIU4-1500x844.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-includes/js/jquery/jquery.min.js?ver=3.7.1 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/google-analytics-for-wordpress/assets/js/frontend-gtag.min.js?ver=8.28.0 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/20220816120000-495x400.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/font-awesome-4/css/font-awesome.min.css?ver=4.7.0 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/LIU4-1500x844.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-templatebuilder/avia-template-builder/assets/fonts/entypo-fontello.woff2 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://ibtikar-uae.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/Emtelle-001-1500x843.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/click-to-chat-for-whatsapp/new/inc/assets/js/app.js?ver=4.6 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-consent-mode-3d6495dceaebc28bcca3.js HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/pixie_1703154708623-1500x844.png HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/wp-smushit/app/assets/js/smush-lazy-load.min.js?ver=3.16.4 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/click-to-chat-for-whatsapp/new/inc/assets/js/app.js?ver=4.6 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/wp-consent-api/assets/js/wp-consent-api.min.js?ver=1.0.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-consent-mode-3d6495dceaebc28bcca3.js HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/Emtelle-001-1500x843.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/font-awesome-4/fonts/fontawesome-webfont.woff2?v=4.7.0 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://ibtikar-uae.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://ibtikar-uae.com/wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/font-awesome-4/css/font-awesome.min.css?ver=4.7.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/wp-smushit/app/assets/js/smush-lazy-load.min.js?ver=3.16.4 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/js/layerslider.utils.js?ver=7.6.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/plugins/wp-consent-api/assets/js/wp-consent-api.min.js?ver=1.0.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/js/layerslider.kreaturamedia.jquery.js?ver=7.6.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/js/layerslider.transitions.js?ver=7.6.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/js/layerslider.utils.js?ver=7.6.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/dynamic_avia/avia-footer-scripts-1a0ccbba836a0df866b4dd532c375556---6645f18726954.js HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/js/layerslider.kreaturamedia.jquery.js?ver=7.6.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/js/layerslider.transitions.js?ver=7.6.7 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/skins/noskin/skin.css HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-includes/js/wp-emoji-release.min.js?ver=6.6.2 HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937
Source: global traffic HTTP traffic detected: GET /wp-includes/js/wp-emoji-release.min.js?ver=6.6.2 HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/1.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944
Source: global traffic HTTP traffic detected: GET /pagead/landing?gcs=G1--&gcd=13l3l3l3l5l1&tag_exp=101671035~101747727&rnd=386531665.1727702944&url=https%3A%2F%2Fibtikar-uae.com%2F&dma=0&npa=0&gtm=45He49p0n91TDJ6M5SFv9186951691za200&auid=1747626717.1727702944 HTTP/1.1Host: googleads.g.doubleclick.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJC2yQEIprbJAQipncoBCLf3ygEIlqHLAQiFoM0BCLnKzQEIitPNAQjB1M0BCLrYzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/1.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/IBT-NEW-LOGO-AUDAX.svg HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /site.webmanifest HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: manifestReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/skins/noskin/loading.gif HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/skins/noskin/skin.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/IBT-NEW-LOGO-AUDAX.svg HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layerslider/skins/noskin/loading.gif HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/2.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ibtikar-uae.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /wp-content/uploads/2023/12/2.webp HTTP/1.1Host: ibtikar-uae.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _ga_YTELS51ZXH=GS1.1.1727702937.1.0.1727702937.0.0.0; _ga=GA1.1.417202391.1727702937; _gcl_au=1.1.1747626717.1727702944; _ga_3KWLN7LXG8=GS1.1.1727702945.1.0.1727702945.0.0.0
Source: global traffic HTTP traffic detected: GET /ab HTTP/1.1Host: evoke-windowsservices-tas.msedge.netCache-Control: no-store, no-cacheX-PHOTOS-CALLERID: 9NMPJ99VJBWVX-EVOKE-RING: X-WINNEXT-RING: PublicX-WINNEXT-TELEMETRYLEVEL: BasicX-WINNEXT-OSVERSION: 10.0.19045.0X-WINNEXT-APPVERSION: 1.23082.131.0X-WINNEXT-PLATFORM: DesktopX-WINNEXT-CANTAILOR: FalseX-MSEDGE-CLIENTID: {c1afbad7-f7da-40f2-92f9-8846a91d69bd}X-WINNEXT-PUBDEVICEID: dbfen2nYS7HW6ON4OdOknKxxv2CCI5LJBTojzDztjwI=If-None-Match: 2056388360_-1434155563Accept-Encoding: gzip, deflate, br
Source: global traffic HTTP traffic detected: GET /client/config?cc=CH&setlang=en-CH HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-UserAgeClass: UnknownX-BM-Market: CHX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: -240X-DeviceID: 01000A41090080B6X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Search-TimeZone: Bias=300; DaylightBias=-60; TimeZoneKeyName=Eastern Standard TimeX-BM-Theme: 000000;0078d7X-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAYRLKYZ5zwhjfPUX266BmCnQh/CqnDGunrPuykd8WCODkxeo74TkBIATvm8tlpx6hNyBsvGIhyChj2AAwSHK6Y5I2DMQm8h8AmCXUh1yao%2BlopyDfIvKFJEz6bPTuu/9Y29kqiSyEfC6aWiipSKVnY4R2Ysbjg6nMHLiIG/8duBd0FiQF6YqKbmQ2S2TZJlJ41K0fxtKTcHahM2TWPpLrgaJITqN5Z9Y5LGqKGlSx7Ta4CFXBBshR5bW3m3y3ENJXIGK20reLoQyZhSC8Mvg1Z48dEi4NNJWLRm6ItNyC4BCMRXeszOv9lESRyIB92YPaBWwKYj6Kpqn0KNz%2BuLLPEkQZgAAEGZveBe/5P7aWFe3eaUlUiewAcJWUGO9QGtcAe0eR7maLuakMSaf7cQrJQ6kdPX6W28XfZJN2J9JePuSf31PyMvlGmItES%2BCWpCMiBUSAevNmmlKT7FVmgWh8YbCHT1ey4ZqC5rfJi1htny7Xfy/QZSBBm7YRiCQDQbw/e9f9hF%2Bc9FcYkwXAaRJEeVc74pjK6bCo%2BGEEuU4s495zCJuOQ6TlnXjq4y/1DYgO57HGAXclOC%2BmZ7uX6pTqk1cEDOSaumweOW9GX5bU4tgaLFJxkmcIFPBOrTMo3GXUf8zTptBUDxyhkomRKCBUM%2BmjcnM0RmXuXbY2Fqe2rMHVZiJjAnDYRWwHLUaHptvaUax6WVDfQTHeppF4I4chyidPbsV5Bt8zBhpTpHjsDIfNha6dKYH9btbCPiXO/b%2B%2Bi/9y1QL5gRZJaMUAz1Z9Wer4033UAOJWF6NAB%2BfTCbLrCsnvR6B7w1FeYY4XPg6eKymCw84%2B5r6xqvi1gcjayBPZzKkfViMWQ0u52klU6aromj5w8oXyhr1I85Kgr0wHkk9EVxLzREW4yT2/N4fjeny2IFrtDqRFyNOQni116pdnryQoG9QOtcB%26p%3DX-Agent-DeviceId: 01000A41090080B6X-BM-CBT: 1727702980User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045X-Device-isOptin: falseAccept-language: en-GB, en, en-USX-Device-Touch: falseX-Device-ClientSession: 3DDDBDC8F5DE4FCCB866AABC94AE0350X-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=C4EAB6C130004333A34B5668AE4E4D10&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20240207; SRCHHPGUSR=SRCHLANG=en; MUID=4590362BB5CF472B95BBEDB3112D4B7B; MUIDB=4590362BB5CF472B95BBEDB3112D4B7B
Source: chromecache_215.19.dr String found in binary or memory: </li></ul></div><ul class='noLightbox social_bookmarks icon_count_6'><li class='social_bookmarks_facebook av-social-link-facebook social_icon_1'><a target="_blank" aria-label="Link to Facebook" href='https://www.facebook.com/ibtikarae' aria-hidden='false' data-av_icon=' equals www.facebook.com (Facebook)
Source: chromecache_215.19.dr String found in binary or memory: <ul class='noLightbox social_bookmarks icon_count_6'><li class='social_bookmarks_facebook av-social-link-facebook social_icon_1'><a target="_blank" aria-label="Link to Facebook" href='https://www.facebook.com/ibtikarae' aria-hidden='false' data-av_icon=' equals www.facebook.com (Facebook)
Source: chromecache_215.19.dr String found in binary or memory: ' data-av_iconfont='entypo-fontello' title='WhatsApp' rel="noopener"><span class='avia_hidden_link_text'>WhatsApp</span></a></li><li class='social_bookmarks_youtube av-social-link-youtube social_icon_4'><a target="_blank" aria-label="Link to Youtube" href='https://www.youtube.com/@ibtikar-uae/featured' aria-hidden='false' data-av_icon=' equals www.youtube.com (Youtube)
Source: chromecache_262.19.dr, chromecache_260.19.dr String found in binary or memory: Math.round(q);v["gtm.videoElapsedTime"]=Math.round(f);v["gtm.videoPercent"]=r;v["gtm.videoVisible"]=t;return v},Yj:function(){e=zb()},nd:function(){d()}}};var gc=ja(["data-gtm-yt-inspected-"]),FC=["www.youtube.com","www.youtube-nocookie.com"],GC,HC=!1; equals www.youtube.com (Youtube)
Source: chromecache_262.19.dr, chromecache_260.19.dr String found in binary or memory: c?"runIfCanceled":"runIfUncanceled",[]);if(!g.length)return!0;var k=lA(a,c,e);N(121);if(k["gtm.elementUrl"]==="https://www.facebook.com/tr/")return N(122),!0;if(d&&f){for(var m=Kb(b,g.length),n=0;n<g.length;++n)g[n](k,m);return m.done}for(var p=0;p<g.length;++p)g[p](k,function(){});return!0},oA=function(){var a=[],b=function(c){return ob(a,function(d){return d.form===c})};return{store:function(c,d){var e=b(c);e?e.button=d:a.push({form:c,button:d})},get:function(c){var d=b(c);return d?d.button:null}}}, equals www.facebook.com (Facebook)
Source: chromecache_235.19.dr String found in binary or memory: else{n.scroll_top();var p={zIndex:3},u=t.easing;if(v>r){p.left='-110%'};if(t.transition==='fade'){p.left='0%';p.opacity=0;u='easeOutQuad'};d.height(d.height());e[o].css(p).avia_animate({'left':'0%',opacity:1},t.timing,u);e[s].avia_animate({opacity:0},t.timing,u,function(){e[s].attr({'style':''}).removeClass('open_slide');e[o].addClass('open_slide');d.avia_animate({height:e[o].outerHeight()+2},t.timing/2,t.easing,function(){d.attr({'style':''});s=o;v=r;c=!1;n.remove_video();if(f){a.trigger('av_resize_finished');i.avia_utilities.activate_shortcode_scripts(e[o]);i.avia_utilities.avia_ajax_call(e[o]);f=!1}})})}},ajax_get_contents:function(t,a){if(e[t]!==undefined){n.show_item(t,a);return};var o=i('#avia-tmpl-portfolio-preview-'+t.replace(/ID_/,''));if(o.length==0){setTimeout(function(){n.ajax_get_contents(t,a);return},500)};e[t]=o.html();e[t]=e[t].replace('/*<![CDATA[*/','').replace('*]]>','');n.attach_item(t);i.avia_utilities.preload({container:e[t],single_callback:function(){n.show_item(t,a)}})},add_controls:function(){u=l.find('.ajax_controlls');l.avia_keyboard_controls({27:'.avia_close',37:'.ajax_previous',39:'.ajax_next'});p.each(function(){var t=i(this),e;t.addClass('no_combo').on('click',function(i){e=t.find('.slideshow_overlay');if(e.length){i.stopPropagation();n.load_item.apply(t.find('a').eq(0));return!1}})})},control_click:function(){var o,f=r.find('.active_portfolio_item').data('ajax-id'),d=r.find('.post-entry-'+f);switch(this.hash){case'#next':o=d.nextAll('.post-entry:visible').eq(0).find('a').eq(0);if(!o.length){o=i('.post-entry:visible',r).eq(0).find('a').eq(0)};o.trigger('click');break;case'#prev':o=d.prevAll('.post-entry:visible').eq(0).find('a').eq(0);if(!o.length){o=i('.post-entry:visible',r).last().find('a').eq(0)};o.trigger('click');break;case'#close':c=!0;l.slideUp(t.timing,t.easing,function(){r.find('.active_portfolio_item').removeClass('active_portfolio_item');e[s].attr({'style':''}).removeClass('open_slide');l.removeClass('open_container');c=s=v=!1;n.remove_video();a.trigger('av_resize_finished')});break};return!1},resize_reset:function(){if(s===!1){d.html('');e=[]}}};n.add_controls();r.on('click','a',n.load_item);u.on('click','a',n.control_click);o.on('debouncedresize',n.resize_reset)})}}(jQuery));(function(a){'use strict';a.fn.avia_sc_progressbar=function(t){return this.each(function(){var t=a(this),i=t.find('.avia-progress-bar');t.on('avia_start_animation',function(){i.each(function(t){var i=a(this);setTimeout(function(){i.find('.progress').addClass('avia_start_animation');i.find('.progressbar-percent').avia_sc_animated_number({instant_start:!0,simple_up:!0,start_timer:10})},(t*250))})})})}}(jQuery));(function(e){'use strict';e.AviaVideoAPI=function(i,t,o){this.videoElement=t;this.$video=e(t);this.$option_container=o?e(o):this.$video;this.load_btn=this.$option_container.find('.av-click-to-play-overlay');this.video_wrapper=this.$video.parents('ul').eq(0);this.lazy_load=this.video_wrapper.hasClass('av-show-video-on-click')?!
Source: chromecache_262.19.dr, chromecache_260.19.dr String found in binary or memory: if(!(e||f||g||k.length||m.length))return;var p={eh:e,ah:f,bh:g,Ph:k,Qh:m,Ge:n,Bb:b},q=C.YT;if(q)return q.ready&&q.ready(d),b;var r=C.onYouTubeIframeAPIReady;C.onYouTubeIframeAPIReady=function(){r&&r();d()};F(function(){for(var t=E.getElementsByTagName("script"),u=t.length,v=0;v<u;v++){var w=t[v].getAttribute("src");if(QC(w,"iframe_api")||QC(w,"player_api"))return b}for(var x=E.getElementsByTagName("iframe"),y=x.length,A=0;A<y;A++)if(!HC&&OC(x[A],p.Ge))return wc("https://www.youtube.com/iframe_api"), equals www.youtube.com (Youtube)
Source: chromecache_234.19.dr, chromecache_220.19.dr, chromecache_228.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr String found in binary or memory: return b}DC.H="internal.enableAutoEventOnTimer";var gc=ja(["data-gtm-yt-inspected-"]),FC=["www.youtube.com","www.youtube-nocookie.com"],GC,HC=!1; equals www.youtube.com (Youtube)
Source: chromecache_262.19.dr, chromecache_260.19.dr String found in binary or memory: var SB=function(a,b,c,d,e){var f=Jz("fsl",c?"nv.mwt":"mwt",0),g;g=c?Jz("fsl","nv.ids",[]):Jz("fsl","ids",[]);if(!g.length)return!0;var k=Oz(a,"gtm.formSubmit",g),m=a.action;m&&m.tagName&&(m=a.cloneNode(!1).action);N(121);if(m==="https://www.facebook.com/tr/")return N(122),!0;k["gtm.elementUrl"]=m;k["gtm.formCanceled"]=c;a.getAttribute("name")!=null&&(k["gtm.interactedFormName"]=a.getAttribute("name"));e&&(k["gtm.formSubmitElement"]=e,k["gtm.formSubmitElementText"]=e.value);if(d&&f){if(!wy(k,yy(b, equals www.facebook.com (Facebook)
Source: global traffic DNS traffic detected: DNS query: x1.i.lencr.org
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: unknown HTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 3592Host: login.live.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: http://b.c2r.ts.cdn.office.net/pr
Source: 77EC63BDA74BD0D0E0426DC8F80085060.14.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
Source: chromecache_214.19.dr String found in binary or memory: http://fontawesome.io
Source: chromecache_214.19.dr String found in binary or memory: http://fontawesome.io/license
Source: chromecache_215.19.dr String found in binary or memory: http://gmpg.org/xfn/11
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: http://weather.service.msn.com/data.aspx
Source: IBTIKAR-DXB-SUP-LOA.2320 (002).pdf.0.dr, IBTIKAR-DXB-SUP-LOA.2320.pdf.0.dr String found in binary or memory: http://www.ibtikar-uae.com/)
Source: 2D85F72862B55C4EADD9E66E06947F3D0.14.dr String found in binary or memory: http://x1.i.lencr.org/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: chromecache_260.19.dr String found in binary or memory: https://adservice.google.com/pagead/regclk?
Source: chromecache_215.19.dr String found in binary or memory: https://ae.linkedin.com/company/ibtikaruae
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://analysis.windows.net/powerbi/api
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.aadrm.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.aadrm.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.addins.omex.office.net/api/addins/search
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.addins.store.office.com/app/query
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.cortana.ai
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.diagnostics.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.diagnosticssdf.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.microsoftstream.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.microsoftstream.com/api/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.office.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.officescripts.microsoftusercontent.com/api
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.onedrive.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.powerbi.com/v1.0/myorg/imports
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://api.scheduler.
Source: chromecache_215.19.dr String found in binary or memory: https://api.w.org/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://apis.live.net/v5.0/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://apis.mobile.m365.svc.cloud.microsoft
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://app.powerbi.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://arc.msn.com/v4/api/selection
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://augloop.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://augloop.office.com/v2
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://autodiscover-s.outlook.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: chromecache_215.19.dr String found in binary or memory: https://callnowbutton.com)
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://canary.designerapp.
Source: chromecache_234.19.dr, chromecache_220.19.dr, chromecache_262.19.dr, chromecache_228.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr, chromecache_260.19.dr String found in binary or memory: https://cct.google/taggy/agent.js
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.designerapp.osi.office.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.designerapp.osi.office.net/designer-mobile
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/fonts
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-assets
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-dynamic-strings
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-home-screen
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.entity.
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.hubblecontent.osi.office.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cdn.int.designerapp.osi.office.net/fonts
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/c2r/v1.0/DeltaAdvisory
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/c2r/v1.0/InteractiveInstallation
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://consent.config.office.com/consentcheckin/v1.0/consents
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://consent.config.office.com/consentweb/v1.0/consents
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cortana.ai
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cortana.ai/api
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://cr.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://d.docs.live.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dataservice.o365filtering.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dataservice.o365filtering.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://designerapp.azurewebsites.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dev.cortana.ai
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: chromecache_215.19.dr String found in binary or memory: https://developers.google.com/analytics/devguides/collection/analyticsjs/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://devnull.onenote.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://directory.services.
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ecs.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ecs.office.com/config/v1/Designer
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ecs.office.com/config/v2/Office
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://edge.skype.com/registrar/prod
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://edge.skype.com/rps
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/v2.1601652342626
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://entitlement.diagnostics.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://fpastorage.cdn.office.net/%s
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://fpastorage.cdn.office.net/firstpartyapp/addins.xml
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://globaldisco.crm.dynamics.com
Source: chromecache_228.19.dr String found in binary or memory: https://google.com
Source: chromecache_228.19.dr String found in binary or memory: https://googleads.g.doubleclick.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://graph.ppe.windows.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://graph.ppe.windows.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://graph.windows.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://graph.windows.net/
Source: chromecache_215.19.dr String found in binary or memory: https://holithemes.com/plugins/click-to-chat/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/pivots/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?secureurl=1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/#logo
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/#organization
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/#webpage
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/#website
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/&quot;
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/?s=
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/about-us/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/abu-dhabi-civil-defence-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/adnoc-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/careers/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/cmw-command-of-military-works-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/comments/feed/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/contact-us/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/dubai-civil-defence-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/feed/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/news/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/pgc-presidential-guard-command-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/projects/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/service/fabric-fire-retardant/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/service/wood-fire-retardant/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/cable-protective-coating/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/cementitious-paint/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/epoxy-intumescent/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/intumescent-paints/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/solvent-intumescent-coating/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/services/wood-fire-retardant/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/sharjah-civil-defence-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/tip-tawazun-industrial-park-approved/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-admin/admin-ajax.php
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/call-now-button/resources/style/modern.css?ver=1.4.9
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/click-to-chat-for-whatsapp/new/inc/assets/css/main.css?ve
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/click-to-chat-for-whatsapp/new/inc/assets/js/app.js?ver=4
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/google-analytics-for-wordpress/assets/js/frontend-gtag.mi
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-consent-mode
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/wp-consent-api/assets/js/wp-consent-api.min.js?ver=1.0.7
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/plugins/wp-smushit/app/assets/js/smush-lazy-load.min.js?ver=3.16.
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/themes/enfold/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/font-a
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/themes/enfold/config-layerslider/LayerSlider/assets/static/layers
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/assets
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/themes/enfold/framework/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/themes/enfold/js/html5shiv.js
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/20220816120000-495x400.webp
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/20220816120000-845x684.webp
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/IBT-NEW-LOGO-AUDAX.svg
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/cropped-favicon-32x32-1-180x180.png
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/cropped-favicon-32x32-1-192x192.png
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/cropped-favicon-32x32-1-270x270.png
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2023/12/cropped-favicon-32x32-1-32x32.png
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2024/05/Artboard-1.png
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/2024/05/Artboard-3.png
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/dynamic_avia/avia-footer-scripts-1a0ccbba836a0df866b4dd53
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/dynamic_avia/avia-merged-styles-01fa8b2a5466da1875f9f7eee
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-content/uploads/dynamic_avia/avia_posts_css/post-19.css?ver=ver-172130184
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-includes/css/dist/block-library/style.min.css?ver=6.6.2
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-json/
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fibtikar-uae.com%2F
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fibtikar-uae.com%2F&#038;format=xm
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/wp-json/wp/v2/pages/19
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/xmlrpc.php
Source: chromecache_215.19.dr String found in binary or memory: https://ibtikar-uae.com/xmlrpc.php?rsd
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ic3.teams.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://incidents.diagnostics.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://inclient.store.office.com/gyro/client
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://invites.office.com/
Source: chromecache_235.19.dr String found in binary or memory: https://isotope.metafizzy.co
Source: chromecache_252.19.dr, chromecache_259.19.dr, chromecache_258.19.dr, chromecache_221.19.dr, chromecache_263.19.dr, chromecache_219.19.dr String found in binary or memory: https://layerslider.com/
Source: chromecache_252.19.dr, chromecache_259.19.dr, chromecache_258.19.dr, chromecache_221.19.dr, chromecache_263.19.dr, chromecache_219.19.dr String found in binary or memory: https://layerslider.com/licensing/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://lifecycle.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.microsoftonline.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.microsoftonline.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.microsoftonline.com/organizations
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.windows.local
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://make.powerautomate.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://management.azure.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://management.azure.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messagebroker.mobile.m365.svc.cloud.microsoft
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.action.office.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.action.office.com/setcampaignaction
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.action.office.com/setuseraction16
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.engagement.office.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.engagement.office.com/campaignmetadataaggregator
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.lifecycle.office.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.lifecycle.office.com/getcustommessage16
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://messaging.office.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://mss.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://my.microsoftpersonalcontent.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ncus.contentsync.
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ncus.pagecontentsync.
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ods-diagnostics-ppe.trafficmanager.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://officeapps.live.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://officeci.azurewebsites.net/api/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://officepyservice.office.net/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://officepyservice.office.net/service.functionality
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: chromecache_215.19.dr String found in binary or memory: https://ogp.me/ns#
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://onedrive.live.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://onedrive.live.com/embed?
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://otelrules.azureedge.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://otelrules.svc.static.microsoft
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office365.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office365.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://outlook.office365.com/connectors
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: chromecache_260.19.dr String found in binary or memory: https://pagead2.googlesyndication.com
Source: chromecache_234.19.dr, chromecache_220.19.dr, chromecache_262.19.dr, chromecache_228.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr, chromecache_260.19.dr String found in binary or memory: https://pagead2.googlesyndication.com/pagead/gen_204?id=tcfe
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://pages.store.office.com/review/query
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://powerlift.acompli.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://pushchannel.1drv.ms
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: chromecache_215.19.dr String found in binary or memory: https://rankmath.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://res.cdn.office.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://res.cdn.office.net/polymer/models
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://safelinks.protection.outlook.com/api/GetPolicy
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org/CreativeWork
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org/ImageObject
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org/SiteNavigationElement
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org/WPFooter
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org/WPHeader
Source: chromecache_215.19.dr String found in binary or memory: https://schema.org/WebPage
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://service.officepy.microsoftusercontent.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://service.powerapps.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://settings.outlook.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://shell.suite.office.com:1443
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://skyapi.live.net/Activity/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://staging.cortana.ai
Source: chromecache_220.19.dr, chromecache_262.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr, chromecache_260.19.dr String found in binary or memory: https://stats.g.doubleclick.net/g/collect
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://store.office.cn/addinstemplate
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://store.office.de/addinstemplate
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://substrate.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://substrate.office.com/Notes-Internal.ReadWrite
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://tasks.office.com
Source: chromecache_234.19.dr, chromecache_220.19.dr, chromecache_262.19.dr, chromecache_228.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr, chromecache_260.19.dr String found in binary or memory: https://td.doubleclick.net
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://templatesmetadata.office.net/
Source: chromecache_215.19.dr String found in binary or memory: https://twitter.com/ibtikar_uae
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://useraudit.o365auditrealtimeingestion.manage.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: chromecache_215.19.dr String found in binary or memory: https://wa.me/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://web.microsoftstream.com/video/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://webshell.suite.office.com
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://word-edit.officeapps.live.com/we/rrdiscovery.ashx
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://wus2.contentsync.
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://wus2.pagecontentsync.
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: chromecache_260.19.dr String found in binary or memory: https://www.google.com
Source: chromecache_228.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr, chromecache_260.19.dr String found in binary or memory: https://www.googleadservices.com
Source: chromecache_260.19.dr String found in binary or memory: https://www.googletagmanager.com
Source: chromecache_234.19.dr, chromecache_228.19.dr String found in binary or memory: https://www.googletagmanager.com/a?
Source: chromecache_215.19.dr String found in binary or memory: https://www.googletagmanager.com/gtag/js?id=GT-P3MFNZZ
Source: chromecache_215.19.dr String found in binary or memory: https://www.googletagmanager.com/gtm.js?id=
Source: chromecache_215.19.dr String found in binary or memory: https://www.googletagmanager.com/ns.html?id=GTM-TDJ6M5SF
Source: chromecache_234.19.dr, chromecache_228.19.dr String found in binary or memory: https://www.googletagmanager.com/static/service_worker/
Source: chromecache_215.19.dr String found in binary or memory: https://www.instagram.com/ibtikar.uae/reel/C7BWsgkpwjB/
Source: chromecache_220.19.dr, chromecache_262.19.dr, chromecache_233.19.dr, chromecache_211.19.dr, chromecache_210.19.dr, chromecache_260.19.dr String found in binary or memory: https://www.merchant-center-analytics.goog
Source: chromecache_215.19.dr String found in binary or memory: https://www.monsterinsights.com/
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://www.odwebp.svc.ms
Source: B6C95852-636A-4BAB-AFE4-B11740CAEA4F.0.dr String found in binary or memory: https://www.yammer.com
Source: chromecache_215.19.dr String found in binary or memory: https://www.youtube.com/
Source: chromecache_262.19.dr, chromecache_260.19.dr, chromecache_235.19.dr String found in binary or memory: https://www.youtube.com/iframe_api
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49800 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49803 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49690
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49785 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49802 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49803
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49802
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49801
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49800
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49690 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.17:49698 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.17:49704 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.17:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.32.74:443 -> 192.168.2.17:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49713 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.17:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49803 version: TLS 1.2
Source: unknown HTTPS traffic detected: 2.23.209.135:443 -> 192.168.2.17:49804 version: TLS 1.2
Source: classification engine Classification label: mal48.winEML@35/152@5/6
Source: IBTIKAR-DXB-SUP-LOA.2320 (002).pdf.0.dr Initial sample: mailto:mutasim@ibtikar-uae.com
Source: IBTIKAR-DXB-SUP-LOA.2320 (002).pdf.0.dr Initial sample: http://www.ibtikar-uae.com/
Source: IBTIKAR-DXB-SUP-LOA.2320 (002).pdf.0.dr Initial sample: mailto:INFO@IBTIKAR-UAE.COM
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20240930T0928170125-6896.etl Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\Purchase Order IBT LPO-2320.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "01E8F81C-FB97-4957-8673-480D8E3DC168" "ACAD7160-66BA-40FE-8D0A-4EC80E786A6A" "6896" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\SVC71JUG\IBTIKAR-DXB-SUP-LOA.2320.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2264 --field-trial-handle=1568,i,18364615545858017905,282538023687992700,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://www.ibtikar-uae.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1888,i,18239215236048310824,2280694983875274173,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "01E8F81C-FB97-4957-8673-480D8E3DC168" "ACAD7160-66BA-40FE-8D0A-4EC80E786A6A" "6896" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\SVC71JUG\IBTIKAR-DXB-SUP-LOA.2320.pdf" Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://www.ibtikar-uae.com/ Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2264 --field-trial-handle=1568,i,18364615545858017905,282538023687992700,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1888,i,18239215236048310824,2280694983875274173,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: c2r64.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32 Jump to behavior
Source: Google Drive.lnk.18.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.18.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.18.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.18.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.18.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.18.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Window found: window name: SysTabControl32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File Volume queried: C:\Windows\SysWOW64 FullSizeInformation Jump to behavior
Source: Purchase Order IBT LPO-2320.eml Binary or memory string: LNvMjezWQemUnKbk4maMB4FEGkkxPCjStEgu2bp1Kzau/L807im5kpKrLh/wDngGOgc+7Puw710g
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information queried: ProcessInformation Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Queries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs