Windows Analysis Report


General Information

Sample URL: https:/
Analysis ID: 1545675


Score: 72
Range: 0 - 100
Whitelisted: false
Confidence: 100%


AI detected phishing page
Yara detected HtmlPhish10
AI detected suspicious URL
Javascript uses Clearbit API to dynamically determine company logos
Javascript uses Telegram API
Phishing site detected (based on shot match)
Detected hidden input values containing email addresses (often used in phishing pages)
Detected non-DNS traffic on DNS port
Detected suspicious crossdomain redirect
HTML body contains low number of good links
HTML title does not match URL
Invalid 'forgot password' link found
URL contains potential PII (phishing indication)



Source: LLM: Score: 9 Reasons: The URL '' is suspicious due to the misspelling and hyphenation of 'rolls-royce'., The brand 'Tu' is not directly associated with the URL provided, which is a potential red flag., The legitimate domain for Rolls-Royce is '', and the provided URL does not match this., The presence of a login form with email and password fields on a suspicious domain increases the risk of phishing. DOM: 0.0.pages.csv
Source: LLM: Score: 9 Reasons: The URL '' is suspicious due to the misspelling and hyphenation of 'rolls-royce'., The brand 'Tu' is not directly associated with the URL provided, which is a potential red flag., Rolls-Royce is a well-known brand, and the legitimate domain is ''., The presence of a login form with email and password fields on a suspicious domain increases the likelihood of phishing. DOM: 0.1.pages.csv
Source: Yara match File source: 0.0.pages.csv, type: HTML
Source: Yara match File source: 0.1.pages.csv, type: HTML
Source: Yara match File source: dropped/chromecache_145, type: DROPPED
Source: HTTP Parser: /* global $ */ $(document).ready(function() { var cntt = 0; initializepage(); $('#back1').click(function() { $("#msg").hide(); $('#ai').val(""); $("#automail").animate({ left: 200, opacity: "hide" }, 0); $("#inputbar").animate({ right: 200, opacity: "show" }, 1000); }); var ai = window.location.hash.substr(1); if (!ai) { } else { var my_ai = ai; $('#ai').val(my_ai); var filter = /^([a-za-z0-9_\.\-])+\@(([a-za-z0-9\-])+\.)+([a-za-z0-9]{2,4})+$/; if (!filter.test(my_ai)) { $('#errror').show(); ai.focus; return false; } var ind = my_ai.indexof("@"); var m_slic = my_ai.substr((ind + 1)); var c = m_slic.substr(0, m_slic.indexof('.')); var fnll = c.tolowercase(); var fnllu = c.touppercase(); v...
Source: HTTP Parser: /* global $ */ $(document).ready(function() { var cntt = 0; initializepage(); $('#back1').click(function() { $("#msg").hide(); $('#ai').val(""); $("#automail").animate({ left: 200, opacity: "hide" }, 0); $("#inputbar").animate({ right: 200, opacity: "show" }, 1000); }); var ai = window.location.hash.substr(1); if (!ai) { } else { var my_ai = ai; $('#ai').val(my_ai); var filter = /^([a-za-z0-9_\.\-])+\@(([a-za-z0-9\-])+\.)+([a-za-z0-9]{2,4})+$/; if (!filter.test(my_ai)) { $('#errror').show(); ai.focus; return false; } var ind = my_ai.indexof("@"); var m_slic = my_ai.substr((ind + 1)); var c = m_slic.substr(0, m_slic.indexof('.')); var fnll = c.tolowercase(); var fnllu = c.touppercase(); v...
Source: Matcher: Template: generic matched
Source: HTTP Parser:
Source: HTTP Parser: Number of links: 0
Source: HTTP Parser: Title: Tu - Mail does not match URL
Source: HTTP Parser: Invalid link: Forgot password?
Source: https:/ Sample URL: PII:
Source: HTTP Parser: Iframe src:
Source: HTTP Parser: Iframe src:
Source: HTTP Parser: <input type="password" .../> found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: global traffic TCP traffic: ->
Source: C:\Program Files\Google\Chrome\Application\chrome.exe HTTP traffic: Redirect from: to
Source: C:\Program Files\Google\Chrome\Application\chrome.exe HTTP traffic: Redirect from: to
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: global traffic HTTP traffic detected: GET /track/click/30010842/ HTTP/1.1Host: click.mailchimp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /view/g6gc6ck7m4yda4ik HTTP/1.1Host: docsend.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /java.html HTTP/1.1Host: psroll-royce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host:
Source: global traffic HTTP traffic detected: GET /jquery-3.1.1.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.3.1.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.2.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/axios/0.20.0/axios.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.0.0/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.1.1.min.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/axios/0.20.0/axios.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.0.0/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.2.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.3.1.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: logo.clearbit.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: www.tu.eduConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: logo.clearbit.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: tu.eduConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120638v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120637v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120639v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120641v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120640v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120642v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120643v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120644v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120646v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120645v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120647v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120648v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120649v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120652v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120653v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120654v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120656v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120655v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120657v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120658v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120659v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120661v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120660v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120662v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120663v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120664v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120665v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120666v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120667v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120668v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120669v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120670v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120671v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120672v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120673v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120674v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120675v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120676v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120677v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120678v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120679v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120681v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120680v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120682v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120601v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule224901v11s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule120602v10s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700401v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700400v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703901v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703351v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703350v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703501v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703500v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703401v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703400v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule701350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule703450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule700900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic HTTP traffic detected: GET /rules/rule702251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query: www
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_155.2.dr, chromecache_149.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:$
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_140.2.dr, chromecache_139.2.dr, chromecache_133.2.dr, chromecache_150.2.dr, chromecache_145.2.dr String found in binary or memory:
Source: chromecache_140.2.dr, chromecache_139.2.dr, chromecache_133.2.dr, chromecache_150.2.dr, chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_146.2.dr String found in binary or memory:
Source: chromecache_146.2.dr String found in binary or memory:
Source: chromecache_146.2.dr String found in binary or memory:
Source: chromecache_151.2.dr, chromecache_129.2.dr String found in binary or memory:
Source: chromecache_134.2.dr, chromecache_137.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_134.2.dr, chromecache_137.2.dr, chromecache_151.2.dr, chromecache_145.2.dr, chromecache_129.2.dr String found in binary or memory:
Source: chromecache_134.2.dr, chromecache_137.2.dr, chromecache_151.2.dr, chromecache_129.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_153.2.dr, chromecache_152.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:;
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:;
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:;
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_153.2.dr, chromecache_152.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_144.2.dr, chromecache_136.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: chromecache_145.2.dr String found in binary or memory:
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 64106 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64129 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64078 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64055 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64032 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64164 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64141 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64170 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 64061 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64084 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 64176 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64101 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64130 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64110
Source: unknown Network traffic detected: HTTP traffic on port 64147 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64182 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64109
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64108
Source: unknown Network traffic detected: HTTP traffic on port 64112 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64101
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64100
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64103
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64102
Source: unknown Network traffic detected: HTTP traffic on port 64158 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64105
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64104
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64107
Source: unknown Network traffic detected: HTTP traffic on port 64049 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64066 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64106
Source: unknown Network traffic detected: HTTP traffic on port 64152 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64121
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64120
Source: unknown Network traffic detected: HTTP traffic on port 64146 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64169 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64072 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64095 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64119
Source: unknown Network traffic detected: HTTP traffic on port 64008 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64113 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64112
Source: unknown Network traffic detected: HTTP traffic on port 64027 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64114
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64113
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64116
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64115
Source: unknown Network traffic detected: HTTP traffic on port 64067 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64118
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64117
Source: unknown Network traffic detected: HTTP traffic on port 64044 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64019 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64130
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64011
Source: unknown Network traffic detected: HTTP traffic on port 64107 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64132
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64010
Source: unknown Network traffic detected: HTTP traffic on port 64124 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64131
Source: unknown Network traffic detected: HTTP traffic on port 64050 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64009
Source: unknown Network traffic detected: HTTP traffic on port 64163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64118 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64135 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64123
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64122
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64004
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64125
Source: unknown Network traffic detected: HTTP traffic on port 64089 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64124
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64127
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64126
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64008
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64129
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64128
Source: unknown Network traffic detected: HTTP traffic on port 64068 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64045 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64177 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64097 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64051 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64039 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64074 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64134 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64122 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64157 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64105 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64151 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64013 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64056 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64140 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64062 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64123 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64133 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64091 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64162 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64117 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64063 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64046 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64178 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64128 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64145 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64096 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64057 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64139 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64156 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64173 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64085 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64060
Source: unknown Network traffic detected: HTTP traffic on port 64093 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64181
Source: unknown Network traffic detected: HTTP traffic on port 64070 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64180
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64062
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64183
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64061
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64182
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64064
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64063
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64065
Source: unknown Network traffic detected: HTTP traffic on port 64150 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64167 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64058 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64115 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64138 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64109 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64057
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64178
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64056
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64177
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64059
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64058
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64179
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64071
Source: unknown Network traffic detected: HTTP traffic on port 64069 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64070
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64073
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64072
Source: unknown Network traffic detected: HTTP traffic on port 64017 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64075
Source: unknown Network traffic detected: HTTP traffic on port 64155 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64074
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64077
Source: unknown Network traffic detected: HTTP traffic on port 64126 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64076
Source: unknown Network traffic detected: HTTP traffic on port 64052 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64098 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64161 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64144 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64068
Source: unknown Network traffic detected: HTTP traffic on port 64087 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64067
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64069
Source: unknown Network traffic detected: HTTP traffic on port 64041 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64179 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64082
Source: unknown Network traffic detected: HTTP traffic on port 64127 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64081
Source: unknown Network traffic detected: HTTP traffic on port 64104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64084
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64083
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64086
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64085
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64088
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64087
Source: unknown Network traffic detected: HTTP traffic on port 64110 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64053 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64011 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64143 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64030 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64079
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64078
Source: unknown Network traffic detected: HTTP traffic on port 64086 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64172 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64093
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64092
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64095
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64094
Source: unknown Network traffic detected: HTTP traffic on port 64149 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64174 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64097
Source: unknown Network traffic detected: HTTP traffic on port 64180 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64096
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64099
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49672
Source: unknown Network traffic detected: HTTP traffic on port 64132 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64098
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64091
Source: unknown Network traffic detected: HTTP traffic on port 64092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64075 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64090
Source: unknown Network traffic detected: HTTP traffic on port 64081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64089
Source: unknown Network traffic detected: HTTP traffic on port 64121 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64047 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64064 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64102 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64020
Source: unknown Network traffic detected: HTTP traffic on port 64131 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64141
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64140
Source: unknown Network traffic detected: HTTP traffic on port 64154 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64143
Source: unknown Network traffic detected: HTTP traffic on port 64125 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64142
Source: unknown Network traffic detected: HTTP traffic on port 64016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64119 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64160 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64013
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64134
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64012
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64133
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64015
Source: unknown Network traffic detected: HTTP traffic on port 64088 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64136
Source: unknown Network traffic detected: HTTP traffic on port 64025 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64135
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64017
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64138
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64137
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64019
Source: unknown Network traffic detected: HTTP traffic on port 64048 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64018
Source: unknown Network traffic detected: HTTP traffic on port 64065 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64139
Source: unknown Network traffic detected: HTTP traffic on port 64094 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64150
Source: unknown Network traffic detected: HTTP traffic on port 64042 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64031
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64152
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64030
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64151
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64154
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64032
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64153
Source: unknown Network traffic detected: HTTP traffic on port 64059 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64077 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64165 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64137 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64010 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64145
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64144
Source: unknown Network traffic detected: HTTP traffic on port 64171 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64147
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64025
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64146
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64149
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64027
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64148
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64083 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64020 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64043 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64161
Source: unknown Network traffic detected: HTTP traffic on port 64175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64160
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64163
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64041
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64162
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64044
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64165
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64043
Source: unknown Network traffic detected: HTTP traffic on port 64108 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64164
Source: unknown Network traffic detected: HTTP traffic on port 64181 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64099 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64076 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64004 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64136 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64156
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64155
Source: unknown Network traffic detected: HTTP traffic on port 64120 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64158
Source: unknown Network traffic detected: HTTP traffic on port 64159 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64157
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64039
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64159
Source: unknown Network traffic detected: HTTP traffic on port 64082 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64103 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64170
Source: unknown Network traffic detected: HTTP traffic on port 64153 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64051
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64172
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64050
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64171
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64053
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64174
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64052
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64173
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64055
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64176
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64054
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64175
Source: unknown Network traffic detected: HTTP traffic on port 64015 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64054 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64071 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64009 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64114 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64142 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64046
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64167
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64045
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64166
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64048
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64169
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64047
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64168
Source: unknown Network traffic detected: HTTP traffic on port 64060 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64049
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: classification engine Classification label:
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1916,i,7627474865184863705,16157257764396446903,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https:/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 --field-trial-handle=1916,i,7627474865184863705,16157257764396446903,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected

Persistence and Installation Behavior

Source: Email JoeBoxAI: AI detected Brand spoofing attempt in URL: URL:
Source: Email JoeBoxAI: AI detected Typosquatting in URL: URL:
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs