Click to jump to signature section
Source: file:///C:/Users/user/Desktop/securedoc_20241028T070148.html | LLM: Score: 10 Reasons: HTML file with login form DOM: 0.0.pages.csv |
Source: securedoc_20241028T070148.html | HTTP Parser: document.write |
Source: securedoc_20241028T070148.html | HTTP Parser: location.href |
Source: securedoc_20241028T070148.html | HTTP Parser: .location |
Source: securedoc_20241028T070148.html | HTTP Parser: .location |
Source: securedoc_20241028T070148.html | HTTP Parser: Tompkins ClientAlerts <TIAClientAlerts@tompkinsfinancial.com> |
Source: securedoc_20241028T070148.html | HTTP Parser: Base64 decoded: Zeppelin rules! |
Source: securedoc_20241028T070148.html | HTTP Parser: Title: Secure Registered Envelope:Capital Blue Cross: Gag Clause Prohibition Attestation Due 12.31.2024 does not match URL |
Source: file:///C:/Users/user/Desktop/securedoc_20241028T070148.html | HTTP Parser: Title: Secure Registered Envelope:Capital Blue Cross: Gag Clause Prohibition Attestation Due 12.31.2024 does not match URL |
Source: file:///C:/Users/user/Desktop/securedoc_20241028T070148.html | HTTP Parser: Has password / email / username input fields |
Source: securedoc_20241028T070148.html | HTTP Parser: <input type="password" .../> found |
Source: file:///C:/Users/user/Desktop/securedoc_20241028T070148.html | HTTP Parser: <input type="password" .../> found |
Source: securedoc_20241028T070148.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241028T070148.html | HTTP Parser: No favicon |
Source: https://res.cisco.com/websafe/help?topic=AddrNotShown | HTTP Parser: No favicon |
Source: securedoc_20241028T070148.html | HTTP Parser: No <meta name="author".. found |
Source: file:///C:/Users/user/Desktop/securedoc_20241028T070148.html | HTTP Parser: No <meta name="author".. found |
Source: unknown | HTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.4:49739 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49763 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49777 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.4:55889 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:55891 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:56016 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:56107 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:56108 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.4:56109 version: TLS 1.2 |
Source: global traffic | TCP traffic: 192.168.2.4:49745 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.4:55888 -> 1.1.1.1:53 |
Source: global traffic | HTTP traffic detected: GET /?p=0&d=%7B%27name%27%3Anull,%0D%0A%27msgID%27%3A%27%7C1__d94e1f9600000192d2ca05ded84792bf017da47c%40esa2%2Ehc5811-91%2Eiphmx%2Ecom%27,%0D%0A%27flags%27%3A3073,%0D%0A%27rid%27%3A%27c3VzYW4gZ29yZG9uIDxzZ29yZG9uQHRvbXBraW5zZmluYW5jaWFsLmNvbT4%3D%27,%0D%0A%27algnames%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%27AES%27%7D,%27keyHash%27%3A%27SHA-256%27%7D,%0D%0A%27algparams%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%7B%27IV%27%3A%27gSFVkYOu1Y3UkMOIZWQXMQ%3D%3D%27%7D%7D%7D,%0D%0A%27keyserverhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27securereplyhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27openerhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27toc%27%3A%5B%0D%0A%5B%27Body-1730113308129%2Etxt%27,1,%0D%0A%27%27,%0D%0A%27%27,%0D%0A13,%5B0,8415%5D,%27Body-1730113308129%2Etxt%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27image003%2Epng%27,2,%0D%0A%27%27,%0D%0A%27image003%2Epng%27,%0D%0A21,%5B8415,19175%5D,%27image003%2Epng%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27MessageBar%2Ehtml%27,4,%0D%0A%27%27,%0D%0A%27%27,%0D%0A1,%5B27590,30890%5D,%27MessageBar%2Ehtml%27,%0D%0A%27ISO-8859-1%27%5D%0D%0A%5D,%0D%0A%27salt%27%3A%272pw3EGj9%2FtsABMAfwh2rJUEIde0%3D%27,%0D%0A%27data%27%3A%5B%0D%0A%27%27,%27tUsZ%2FH%2BJdTmbz4jzArkw%2FppPaVmS5HEV70bdWgYHbXZosCmVgAXddacI9N42JABOKX5jk3Kcmw812ymvXNEtZr9jT3eqUWzAt06N7CmGnHLQFEofzHke%2FCir8AYoVPmKAhXqPnDiaFzo8lt%2BsLhEzAeXJQgsdz5t78yamP8MNJSMM4PbLHDWDTstCEVFuNVP6GGwG%2FJDeMo3ePCHjgOwZ%2BwlzJ6V09qvIfMGLq2mGnBrtDgju8dXpnjkqC9ZB1RHEKLGw4jBfG3PR5%2FBzr0SK1q70pM6jCukP1JNnmEX0mzR08njV4nv9qmI8cQ7p72OS6pjks0te0QxEYz8AR8CwW6EtXAOxZq5BRaTy4y%2FwG80HNZiXrKEziGlnmxr52SJUMo4qqVzOsf3QAMrBDR5DLZTdembXWiSKM8Dgnyfc13VY7wW6xOin2vJMqvRdw136QC37CykLzJWWMv5piPaBFd81Ov1ys%2BHM1G0hU6lDJmoEflYlcnGu7ZqQ0cHARc0D1NDS%2FEdayuxSzcOHrQVtYDbvNNx9rR1dr5ZaWaAHeyuOCyv9lVoC0ZfStpfCf9M4ftuu6CIYh7vVNzf6JKib3AvEbN4xZx45wWTNdf3Gxipt5BqYXMJSFBuDTIIug4BlRkqZ2CEIFpPBLDpQkk9CrKXkffVsc2KEwNld1jdcwBI3rvOyeAlhm1KLVsqnVL9govSsOx03WSdbzbyvF2WzO0A97PM52VMR9JjBgxA4WSt1T24bWUQBiqlofX7W4yV3fvR2RrrbJvnqq2lMPoMnTL2taapQ1Qg72wQmcKf3P9ni%2FbboYFqqfScQmqnfGKLr81P%2B076WSKpoS2KtRvuDvr%2Fk8hwb0EB%2BqsmJUrxRbGa08R1XGra7v%2FX3eoO4OrtiQexV3h4HsU2OrvYorzfkyPjlMoodEVUotD6U3CMJ8Ngbt%2Fl1%2FhhgA5QgcZ5m1uHB9qZgTmrXpJw7fEwlW1%2FtaqAym063Dl3sXMtgL4aDSS8vqkbBidB3zgf5UvbOnKJjO7OllHjdjqbRuj7bdW3sNDGIKqnWCFYUjJPA9NYQVAElrYPWnfjFRoS3bgEcxO%2B5t62apUJ6F3jdl1W563zw7FnOPui5ye9xOebZbt6XrnInoxV9Rr66iilrK8P0yllQ7HIPNtBGDe5t%2FcKAaMRze9Aqajvyi9EPDAIa2YKNsPgkJGMxCssv%2FpI1Ls9IlDygR9H |