Windows Analysis Report
https://marconmetalfab-my.sharepoint.com/:f:/g/personal/geoff_marconmetal_com/Egx-2orK-3dKvN4XpDa8l7IBwPjZvHM_vr-d9tM4HS51lg?e=pPnQKf

Overview

General Information

Sample URL: https://marconmetalfab-my.sharepoint.com/:f:/g/personal/geoff_marconmetal_com/Egx-2orK-3dKvN4XpDa8l7IBwPjZvHM_vr-d9tM4HS51lg?e=pPnQKf
Analysis ID: 1426990
Infos:

Detection

Score: 24
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Downloads suspicious files via Chrome
Allocates memory with a write watch (potentially for evading sandboxes)
Creates a process in suspended mode (likely to inject code)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTML body contains low number of good links
HTML title does not match URL
May sleep (evasive loops) to hinder dynamic analysis
Sample execution stops while process was sleeping (likely an evasion)
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

Source: https://login.microsoftonline.com/1b4a5f72-0ec0-4b75-ac79-5c88057e14f0/oauth2/v2.0/authorize?client_id=08e18876-6177-487e-b8b5-cf950c1e598c&scope=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F_forms%2Fspfxsinglesignon.aspx&client-request-id=2bb80481-4693-42e7-a493-72a2997eab15&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=3.7.1&client_info=1&code_challenge=R1-cndK7Ef3tMozq7CqwDhqUJTQAWgU6poSz4hZQMtE&code_challenge_method=S256&prompt=none&nonce=d4c77666-d6a4-4dd3-9566-dc96871f6335&state=eyJpZCI6ImM0ZDc0ZDBiLTI5NjAtNGMyMi1hY2I4LWE5ZjZlZmQzMTQ1YiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19 HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/1b4a5f72-0ec0-4b75-ac79-5c88057e14f0/oauth2/v2.0/authorize?client_id=08e18876-6177-487e-b8b5-cf950c1e598c&scope=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F_forms%2Fspfxsinglesignon.aspx&client-request-id=2bb80481-4693-42e7-a493-72a2997eab15&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=3.7.1&client_info=1&code_challenge=R1-cndK7Ef3tMozq7CqwDhqUJTQAWgU6poSz4hZQMtE&code_challenge_method=S256&prompt=none&nonce=d4c77666-d6a4-4dd3-9566-dc96871f6335&state=eyJpZCI6ImM0ZDc0ZDBiLTI5NjAtNGMyMi1hY2I4LWE5ZjZlZmQzMTQ1YiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19 HTTP Parser: Title: Redirecting does not match URL
Source: https://login.microsoftonline.com/1b4a5f72-0ec0-4b75-ac79-5c88057e14f0/oauth2/v2.0/authorize?client_id=08e18876-6177-487e-b8b5-cf950c1e598c&scope=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F_forms%2Fspfxsinglesignon.aspx&client-request-id=2bb80481-4693-42e7-a493-72a2997eab15&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=3.7.1&client_info=1&code_challenge=R1-cndK7Ef3tMozq7CqwDhqUJTQAWgU6poSz4hZQMtE&code_challenge_method=S256&prompt=none&nonce=d4c77666-d6a4-4dd3-9566-dc96871f6335&state=eyJpZCI6ImM0ZDc0ZDBiLTI5NjAtNGMyMi1hY2I4LWE5ZjZlZmQzMTQ1YiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19 HTTP Parser: No favicon
Source: about:blank HTTP Parser: No favicon
Source: https://login.microsoftonline.com/1b4a5f72-0ec0-4b75-ac79-5c88057e14f0/oauth2/v2.0/authorize?client_id=08e18876-6177-487e-b8b5-cf950c1e598c&scope=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F_forms%2Fspfxsinglesignon.aspx&client-request-id=2bb80481-4693-42e7-a493-72a2997eab15&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=3.7.1&client_info=1&code_challenge=R1-cndK7Ef3tMozq7CqwDhqUJTQAWgU6poSz4hZQMtE&code_challenge_method=S256&prompt=none&nonce=d4c77666-d6a4-4dd3-9566-dc96871f6335&state=eyJpZCI6ImM0ZDc0ZDBiLTI5NjAtNGMyMi1hY2I4LWE5ZjZlZmQzMTQ1YiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/1b4a5f72-0ec0-4b75-ac79-5c88057e14f0/oauth2/v2.0/authorize?client_id=08e18876-6177-487e-b8b5-cf950c1e598c&scope=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fmarconmetalfab-my.sharepoint.com%2F_forms%2Fspfxsinglesignon.aspx&client-request-id=2bb80481-4693-42e7-a493-72a2997eab15&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=3.7.1&client_info=1&code_challenge=R1-cndK7Ef3tMozq7CqwDhqUJTQAWgU6poSz4hZQMtE&code_challenge_method=S256&prompt=none&nonce=d4c77666-d6a4-4dd3-9566-dc96871f6335&state=eyJpZCI6ImM0ZDc0ZDBiLTI5NjAtNGMyMi1hY2I4LWE5ZjZlZmQzMTQ1YiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19 HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49846 version: TLS 1.0
Source: C:\Windows\SysWOW64\unarchiver.exe File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dll Jump to behavior
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.5:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.5:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49846 version: TLS 1.0
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown TCP traffic detected without corresponding DNS query: 184.25.164.138
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /:f:/g/personal/geoff_marconmetal_com/Egx-2orK-3dKvN4XpDa8l7IBwPjZvHM_vr-d9tM4HS51lg?e=pPnQKf HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/geoff_marconmetal_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%2FHighway%20Specialties%20Inc&ga=1 HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /personal/geoff_marconmetal_com/_api/v2.1/graphql HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://marconmetalfab-my.sharepoint.com/personal/geoff_marconmetal_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%2FHighway%20Specialties%20Inc&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/geoff_marconmetal_com/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/geoff_marconmetal_com/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%27&RootFolder=%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%2FHighway%20Specialties%20Inc&TryNewExperienceSingle=TRUE HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&navigationPreloadHeaderValue=%7B%22supportsFeatures%22%3A%5B1855%5D%7D&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%5D&list=v2&defaultBrotli=true&authenticateFast=true&wwData=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099649,3]&spStartApplicationWebBundle=true&enableIntegrities=true HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveCache-Control: max-age=0Accept: */*Service-Worker: scriptSec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: serviceworkerReferer: https://marconmetalfab-my.sharepoint.com/personal/geoff_marconmetal_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%2FHighway%20Specialties%20Inc&ga=1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_vti_bin/afdcache.ashx/_userprofile/userphoto.jpg?_oat_=1713329197_0a59f79cca9a9742636800ad62a99b3285d028d0c3c31f8cbd1cbb6336ab58be&P1=1713297155&P2=1878891387&P3=1&P4=m3oBsWi8WLGfDScEbR3%2BTNLAa0JqKSZkK6Tph5LF%2B9fSEu8oohRCSe1x2KaTsomyCfKwMKltZOe8dLPv0wVr6hAk07UlhHy88BTo3we%2FPP556u8uMQgGCscBGDEcCGYZsyEqeTKuBhlFNa7dZamnTZT0GjZHHBKNlnwduBW5YC1J78UUcPZhtsiX1gvsZ63FPr6nxUPIFRzTEFxkkeBN333HzCslPR2uub41ieb2BVpx%2B8BFA8wrroNnc5NNFFnDEVPUekl9dRTietTlJmVGkeLp0GuE1wO2CKObdZSxKiUIA5%2BbzrFhPaJxBCbxcXTm3ucxKKWg5LjxvOfEw0NpyA%3D%3D&size=M&accountname=geoff%40marconmetal.com HTTP/1.1Host: marconmetalfab.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://marconmetalfab-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_layouts/15/SPComponentRegistry.ashx?projects=[%22STS%22]&languages=%5B%5D HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveAccept: application/jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/jsonSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&navigationPreloadHeaderValue=%7B%22supportsFeatures%22%3A%5B1855%5D%7D&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%5D&list=v2&defaultBrotli=true&authenticateFast=true&wwData=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099649,3]&spStartApplicationWebBundle=true&enableIntegrities=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/SPComponentRegistry.ashx?projects=[%22spfx%22]&languages=%5B%5D HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveAccept: application/jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/jsonSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&navigationPreloadHeaderValue=%7B%22supportsFeatures%22%3A%5B1855%5D%7D&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%5D&list=v2&defaultBrotli=true&authenticateFast=true&wwData=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099649,3]&spStartApplicationWebBundle=true&enableIntegrities=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_vti_bin/afdcache.ashx/_userprofile/userphoto.jpg?_oat_=1713329197_0a59f79cca9a9742636800ad62a99b3285d028d0c3c31f8cbd1cbb6336ab58be&P1=1713297155&P2=1878891387&P3=1&P4=m3oBsWi8WLGfDScEbR3%2BTNLAa0JqKSZkK6Tph5LF%2B9fSEu8oohRCSe1x2KaTsomyCfKwMKltZOe8dLPv0wVr6hAk07UlhHy88BTo3we%2FPP556u8uMQgGCscBGDEcCGYZsyEqeTKuBhlFNa7dZamnTZT0GjZHHBKNlnwduBW5YC1J78UUcPZhtsiX1gvsZ63FPr6nxUPIFRzTEFxkkeBN333HzCslPR2uub41ieb2BVpx%2B8BFA8wrroNnc5NNFFnDEVPUekl9dRTietTlJmVGkeLp0GuE1wO2CKObdZSxKiUIA5%2BbzrFhPaJxBCbxcXTm3ucxKKWg5LjxvOfEw0NpyA%3D%3D&size=M&accountname=geoff%40marconmetal.com HTTP/1.1Host: marconmetalfab.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_3b4rnVNi70Sso4_c42_ImQ2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_forms/spfxsinglesignon.aspx HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=1b37db02-e2a4-43e1-bf9c-e14fc2e5f5ff
Source: global traffic HTTP traffic detected: GET /personal/geoff_marconmetal_com/_api/v2.0/sites/root/lists/9a160b24-163c-44c4-8027-3b8b39920db2/subscriptions/socketIo?listItemIds= HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Content-Type: application/json;odata=verbosePrefer: NotificationSessionsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/personal/geoff_marconmetal_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%2FHighway%20Specialties%20Inc&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=1b37db02-e2a4-43e1-bf9c-e14fc2e5f5ff
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?f508a347b1ae13b210d26edbae1bbcf0 HTTP/1.1Host: 40537e41ac9ef6fc94f24d1d37f077da.fp.measure.office.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://marconmetalfab-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?a8d1397ac1fd5010e5c4b5b9812b932d HTTP/1.1Host: 40537e41ac9ef6fc94f24d1d37f077da.fp.measure.office.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://marconmetalfab-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?f508a347b1ae13b210d26edbae1bbcf0 HTTP/1.1Host: 40537e41ac9ef6fc94f24d1d37f077da.fp.measure.office.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?a8d1397ac1fd5010e5c4b5b9812b932d HTTP/1.1Host: 40537e41ac9ef6fc94f24d1d37f077da.fp.measure.office.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?47acd1152fe4f8e45105b024851c4673 HTTP/1.1Host: tr-ooc-acdc.office.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://marconmetalfab-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?57e72089d718af64ee01cb7ebc6b5356 HTTP/1.1Host: tr-ooc-acdc.office.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://marconmetalfab-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?47acd1152fe4f8e45105b024851c4673 HTTP/1.1Host: tr-ooc-acdc.office.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /apc/trans.gif?57e72089d718af64ee01cb7ebc6b5356 HTTP/1.1Host: tr-ooc-acdc.office.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: global traffic HTTP traffic detected: GET /personal/geoff_marconmetal_com/_layouts/15/AccessDenied.aspx?correlation=b3a71fa1%2D2019%2D5000%2D5574%2D0e0560556b78 HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=1b37db02-e2a4-43e1-bf9c-e14fc2e5f5ff
Source: unknown DNS traffic detected: queries for: marconmetalfab-my.sharepoint.com
Source: unknown HTTP traffic detected: POST /personal/geoff_marconmetal_com/_api/v2.1/graphql HTTP/1.1Host: marconmetalfab-my.sharepoint.comConnection: keep-aliveContent-Length: 507sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"accept: application/json;odata=verboseContent-Type: application/json;odata=verboseX-ServiceWorker-Strategy: CacheFirstsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Origin: https://marconmetalfab-my.sharepoint.comSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://marconmetalfab-my.sharepoint.com/personal/geoff_marconmetal_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fgeoff%5Fmarconmetal%5Fcom%2FDocuments%2FHighway%20Specialties%20Inc&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=
Source: global traffic HTTP traffic detected: HTTP/1.1 503 Service UnavailableCache-Control: no-cache, no-storePragma: no-cacheContent-Length: 155Content-Type: application/jsonExpires: -1Retry-After: 119P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"Set-Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2JkN2JiYTVlYjRiOWZmMDQzYWY3ZjFhMTFlY2RlYzdlN2Q5YzI3NjkzNTlhNmY4ODQ1ZjM5NjRhYzIxOWY4N2EsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jYmQ3YmJhNWViNGI5ZmYwNDNhZjdmMWExMWVjZGVjN2U3ZDljMjc2OTM1OWE2Zjg4NDVmMzk2NGFjMjE5Zjg3YSwxMzM1Nzc2ODI2ODAwMDAwMDAsMCwxMzM1Nzg1NDM2ODIxNzAxNDYsMC4wLjAuMCwyNTgsMWI0YTVmNzItMGVjMC00Yjc1LWFjNzktNWM4ODA1N2UxNGYwLCwsYTNhNzFmYTEtYzA1NC01MDAwLTU1NzQtMDBjMGM4OWQxNjkyLGEzYTcxZmExLWMwNTQtNTAwMC01NTc0LTAwYzBjODlkMTY5MixOVHdpUkpGQlcwaThBSGYxZTNJTW93LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTE5ODksRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFVlNjFXaGFpUlpNVG5WSWcvOXhxQzc2Z0l5eEd6YzNoVndBTHFWT2t5NDNmalcxb2JmRE1DSkNXUEpNWXFmQzZScEx1U3NaWjUxR3lwMk1YcytvdWFoRWZlNm5tLzN4N0NxSGZDQ041ek5ka21mWVZYWjRvbUVmQVI2cDFWbjZ5ZnR3OGlyaTNtMmtXdWl6amo0Wnd6c2tGMmxJdlNacVFxazF1ajFkVWI3bytFeVhWQk9MaWVUTjgySnU5Rkt5NzU5YTZqL3Q4dngwS2I0OTB2UVB1d2pHNDl3ZHlmTmRwTmFNbmswdkVkTUhFb0lkQXNNSkI3dUcvVTdGaXg2OEt6RGNZdEV2enNCZkplT2NFVEhEY1JjZ01sQVpIRUg3Q1NCMGN5dGxoZzNZejlsc3E4cUNyWGxiSk4xY0t1WURSQXppNU5vTGh0bzQzV2d6WjRSTUt4QT09PC9TUD4=; path=/; SameSite=None; secure; HttpOnlyX-NetworkStatistics: 0,8409600,0,485,4464374,0,2609522X-SharePointHealthScore: 2X-VroomVersion: 2.0X-DataBoundary: NONEX-1DSCollectorUrl: https://mobile.events.data.microsoft.com/OneCollector/1.0/X-AriaCollectorURL: https://browser.pipe.aria.microsoft.com/Collector/3.0/SPRequestGuid: a8a71fa1-c029-5000-1c30-667f31d561a0request-id: a8a71fa1-c029-5000-1c30-667f31d561a0MS-CV: oR+nqCnAAFAcMGZ/MdVhoA.0Report-To: {"group":"network-errors","max_age":7200,"endpoints":[{"url":"https://spo.nel.measure.office.net/api/report?tenantId=00000000-0000-0000-0000-000000000000&destinationEndpoint=Edge-Prod-ATL33r5a&frontEnd=AFD&RemoteIP=81.181.57.0"}]}NEL: {"report_to":"network-errors","max_age":7200,"success_fraction":0.001,"failure_fraction":1.0}Strict-Transport-Security: max-age=31536000X-FRAME-OPTIONS: SAMEORIGINContent-Security-Policy: frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.office365.com *.powerapps.com *.yammer.com engage.cloud.microsoft *.officeapps.live.com *.office.com *.microsoft365.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com securebroker.sharepointonline.com;SPRequestDuration: 43SPIisLatency: 1X-Powered-By: ASP.NETMicrosoftSharePointTeamServices: 16.0.0.24727X-Content-Type-Options: nosniffX-MS-InvokeApp: 1; RequireReadOnlyX-Cache: CONFIG_NOCACHEX-MSEdge-Ref: Ref A: B1BB6FDBCDF548489347FCA6F1
Source: chromecache_1314.2.dr, chromecache_1350.2.dr, chromecache_1149.2.dr String found in binary or memory: http://fb.me/use-check-prop-types
Source: chromecache_1291.2.dr String found in binary or memory: http://knockoutjs.com/
Source: chromecache_1616.2.dr String found in binary or memory: http://linkless.header/
Source: chromecache_1554.2.dr, chromecache_1355.2.dr, chromecache_1593.2.dr, chromecache_1619.2.dr String found in binary or memory: http://www.contoso.com
Source: chromecache_1239.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php
Source: chromecache_1291.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
Source: chromecache_1168.2.dr, chromecache_1402.2.dr, chromecache_1645.2.dr, chromecache_1452.2.dr String found in binary or memory: https://1drv.com/
Source: chromecache_1203.2.dr String found in binary or memory: https://aka.ms/msaljs/optional-claims
Source: chromecache_1134.2.dr String found in binary or memory: https://alcdn.msauth.net/lib/1.4.12/js/msal.min.js
Source: chromecache_1206.2.dr String found in binary or memory: https://apps.test.powerapps.com/sdk/preload
Source: chromecache_1168.2.dr, chromecache_1402.2.dr, chromecache_1645.2.dr, chromecache_1452.2.dr String found in binary or memory: https://centralus1-mediad.svc.ms
Source: chromecache_1264.2.dr, chromecache_1400.2.dr String found in binary or memory: https://facebook.github.io/react/docs/more-about-refs.html#the-ref-callback-attribute
Source: chromecache_1291.2.dr String found in binary or memory: https://github.com/douglascrockford/JSON-js
Source: 7za.exe, 00000007.00000003.2300056466.0000000000D00000.00000004.00000800.00020000.00000000.sdmp, 7za.exe, 00000007.00000003.2300093677.0000000000CD0000.00000004.00000800.00020000.00000000.sdmp, ProjectFile.pdf.7.dr, OneDrive_2024-04-16.zip.crdownload.0.dr, chromecache_1456.2.dr String found in binary or memory: https://ironworldfencings.com/?ktatupif)
Source: chromecache_1505.2.dr String found in binary or memory: https://lists.live.com/
Source: chromecache_1168.2.dr, chromecache_1402.2.dr, chromecache_1645.2.dr, chromecache_1452.2.dr String found in binary or memory: https://livefilestore.com/
Source: chromecache_1203.2.dr String found in binary or memory: https://login.chinacloudapi.cn
Source: chromecache_1203.2.dr String found in binary or memory: https://login.chinacloudapi.cn/
Source: chromecache_1203.2.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_1203.2.dr String found in binary or memory: https://login.microsoftonline.com/
Source: chromecache_1203.2.dr String found in binary or memory: https://login.microsoftonline.de
Source: chromecache_1203.2.dr String found in binary or memory: https://login.microsoftonline.us
Source: chromecache_1203.2.dr String found in binary or memory: https://login.microsoftonline.us/
Source: chromecache_1203.2.dr String found in binary or memory: https://login.partner.microsoftonline.cn/
Source: chromecache_1203.2.dr String found in binary or memory: https://login.windows-ppe.net
Source: chromecache_1246.2.dr String found in binary or memory: https://login.windows.net
Source: chromecache_1266.2.dr, chromecache_1516.2.dr String found in binary or memory: https://loki.delve.office.com
Source: chromecache_1333.2.dr, chromecache_1231.2.dr String found in binary or memory: https://make.powerautomate.com
Source: chromecache_1472.2.dr, chromecache_1333.2.dr String found in binary or memory: https://make.preprod.powerautomate.com
Source: chromecache_1472.2.dr, chromecache_1333.2.dr String found in binary or memory: https://make.test.powerautomate.com
Source: chromecache_1134.2.dr String found in binary or memory: https://marconmetalfab-my.sharepoint.com/_layouts/15/msal_browser_min.js
Source: chromecache_1168.2.dr, chromecache_1402.2.dr, chromecache_1645.2.dr, chromecache_1145.2.dr, chromecache_1578.2.dr, chromecache_1613.2.dr, chromecache_1452.2.dr String found in binary or memory: https://media.cloudapp.net
Source: chromecache_1274.2.dr String found in binary or memory: https://microsoft.spfx3rdparty.com
Source: chromecache_1307.2.dr, chromecache_1441.2.dr, chromecache_1518.2.dr String found in binary or memory: https://my.microsoftpersonalcontent.com
Source: chromecache_1168.2.dr, chromecache_1402.2.dr, chromecache_1645.2.dr, chromecache_1145.2.dr, chromecache_1578.2.dr, chromecache_1613.2.dr, chromecache_1452.2.dr String found in binary or memory: https://northcentralus1-medias.svc.ms
Source: chromecache_1627.2.dr String found in binary or memory: https://odspwebdevdeploy.blob.core.windows.net
Source: chromecache_1186.2.dr, chromecache_1627.2.dr String found in binary or memory: https://onedrive.live.com/?gologin=1
Source: chromecache_1436.2.dr, chromecache_1533.2.dr, chromecache_1602.2.dr, chromecache_1278.2.dr, chromecache_1391.2.dr, chromecache_1333.2.dr, chromecache_1409.2.dr, chromecache_1285.2.dr, chromecache_1360.2.dr, chromecache_1401.2.dr, chromecache_1518.2.dr String found in binary or memory: https://outlook.office.com/search
Source: chromecache_1224.2.dr String found in binary or memory: https://outlook.office365.com
Source: chromecache_1224.2.dr String found in binary or memory: https://outlook.office365.com/SchedulingB2/api/v1.0/me/findmeetinglocations
Source: chromecache_1344.2.dr, chromecache_1191.2.dr, chromecache_1533.2.dr, chromecache_1602.2.dr, chromecache_1168.2.dr, chromecache_1645.2.dr, chromecache_1166.2.dr, chromecache_1333.2.dr, chromecache_1231.2.dr, chromecache_1357.2.dr, chromecache_1404.2.dr, chromecache_1285.2.dr, chromecache_1360.2.dr, chromecache_1452.2.dr String found in binary or memory: https://portal.office.com/
Source: 7za.exe, 00000007.00000003.2300056466.0000000000D00000.00000004.00000800.00020000.00000000.sdmp, 7za.exe, 00000007.00000003.2300093677.0000000000CD0000.00000004.00000800.00020000.00000000.sdmp, ProjectFile.pdf.7.dr, OneDrive_2024-04-16.zip.crdownload.0.dr, chromecache_1456.2.dr String found in binary or memory: https://protect-us.mimecast.com/s/YnhECYEByWHQZnnu0v4IM?domain=zixcorp.com)
Source: chromecache_1452.2.dr String found in binary or memory: https://reactjs.org/link/react-polyfills
Source: chromecache_1186.2.dr String found in binary or memory: https://res-1.cdn.office.net
Source: chromecache_1246.2.dr, chromecache_1498.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/fabric-cdn-prod_20230815.002/assets
Source: chromecache_1186.2.dr, chromecache_1647.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-03-29.002/
Source: chromecache_1647.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-03-29.002/stsserviceworkerprefetch/stsservicew
Source: chromecache_1491.2.dr, chromecache_1647.2.dr, chromecache_1298.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-05.007/
Source: chromecache_1647.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-05.007/spserviceworker.js
Source: chromecache_1491.2.dr, chromecache_1298.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-05.007/spwebworker.js
Source: chromecache_1186.2.dr String found in binary or memory: https://res-2.cdn.office.net/files/odsp-web-prod_2024-03-29.002/
Source: chromecache_1613.2.dr String found in binary or memory: https://sharepoint.uservoice.com/forums/329214-sites-and-collaboration
Source: chromecache_1186.2.dr String found in binary or memory: https://shell.cdn.office.net
Source: chromecache_1186.2.dr, chromecache_1647.2.dr String found in binary or memory: https://shell.cdn.office.net/api/ShellBootstrapper/business/OneShell
Source: chromecache_1402.2.dr, chromecache_1613.2.dr String found in binary or memory: https://shellppe.msocdn.com
Source: chromecache_1402.2.dr, chromecache_1613.2.dr String found in binary or memory: https://shellprod.msocdn.com
Source: chromecache_1186.2.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/odsp-common-library-prod_2019-02-15_20190219.002/require.js
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-bold.w
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-regula
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-semili
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semilight.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-regular.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semibold.wof
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semilight.wo
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-bold.wof
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-light.wo
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-regular.
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semibold
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semiligh
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semilight.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff2
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-light.woff
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-regular.wo
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semibold.w
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semilight.
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-bold.wof
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-light.wo
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-regular.
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semibold
Source: chromecache_1392.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semiligh
Source: chromecache_1341.2.dr, chromecache_1168.2.dr, chromecache_1645.2.dr String found in binary or memory: https://substrate.office.com
Source: chromecache_1496.2.dr, chromecache_1200.2.dr String found in binary or memory: https://support.office.com/en-us/article/Manage-lists-and-libraries-with-many-items-b8588dae-9387-48
Source: chromecache_1203.2.dr String found in binary or memory: https://tools.ietf.org/html/rfc7515
Source: chromecache_1627.2.dr String found in binary or memory: https://www.office.com/login?prompt=select_account&ru=%2Flaunch%2F$
Source: chromecache_1186.2.dr String found in binary or memory: https://www.office.com/login?prompt=select_account&ru=%2Flaunch%2Fonedrive
Source: chromecache_1627.2.dr String found in binary or memory: https://www.office.com/login?ru=%2Flaunch%2F$
Source: chromecache_1186.2.dr String found in binary or memory: https://www.office.com/login?ru=%2Flaunch%2Fonedrive
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49864
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49940
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49862
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49906 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49814
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49857
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49934
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49933
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 49925 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 49862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50103
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49928
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49927
Source: unknown Network traffic detected: HTTP traffic on port 50103 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49925
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49969
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49847
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49846
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49923
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49920
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49995 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49933 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49940 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49824 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49831 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49847 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49831
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49995
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49864 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49923 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49927 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49969 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49814 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49934 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49906
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49846 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49825
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49824
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.5:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.5:49746 version: TLS 1.2

System Summary

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File dump: C:\Users\user\Downloads\OneDrive_2024-04-16.zip (copy) Jump to dropped file
Source: classification engine Classification label: sus24.win@43/986@51/10
Source: ProjectFile.pdf.7.dr Initial sample: https://protect-us.mimecast.com/s/ynhecyebywhqznnu0v4im?domain=zixcorp.com
Source: ProjectFile.pdf.7.dr Initial sample: mailto:kwarner@highwayspecialties.com
Source: ProjectFile.pdf.7.dr Initial sample: https://protect-us.mimecast.com/s/YnhECYEByWHQZnnu0v4IM?domain=zixcorp.com
Source: ProjectFile.pdf.7.dr Initial sample: https://ironworldfencings.com/?ktatupif
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6628:120:WilError_03
Source: C:\Windows\SysWOW64\unarchiver.exe File created: C:\Users\user\AppData\Local\Temp\unarchiver.log Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2292,i,6842952580014095026,5169618242676845040,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://marconmetalfab-my.sharepoint.com/:f:/g/personal/geoff_marconmetal_com/Egx-2orK-3dKvN4XpDa8l7IBwPjZvHM_vr-d9tM4HS51lg?e=pPnQKf"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\OneDrive_2024-04-16.zip"
Source: C:\Windows\SysWOW64\unarchiver.exe Process created: C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\sggy1xab.1rq" "C:\Users\user\Downloads\OneDrive_2024-04-16.zip"
Source: C:\Windows\SysWOW64\7za.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\unarchiver.exe Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C "C:\Users\user\AppData\Local\Temp\sggy1xab.1rq\Highway Specialties Inc\ProjectFile.pdf"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\sggy1xab.1rq\Highway Specialties Inc\ProjectFile.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2096 --field-trial-handle=1512,i,10468106504033230155,13761112678755485583,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2292,i,6842952580014095026,5169618242676845040,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\OneDrive_2024-04-16.zip" Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process created: C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\sggy1xab.1rq" "C:\Users\user\Downloads\OneDrive_2024-04-16.zip" Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C "C:\Users\user\AppData\Local\Temp\sggy1xab.1rq\Highway Specialties Inc\ProjectFile.pdf" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\sggy1xab.1rq\Highway Specialties Inc\ProjectFile.pdf" Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2096 --field-trial-handle=1512,i,10468106504033230155,13761112678755485583,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\7za.exe Section loaded: 7z.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: sfc_os.dll Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe File opened: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\crash_reporter.cfg Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\unarchiver.exe File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dll Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Memory allocated: FD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Memory allocated: 2C40000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Memory allocated: 4C40000 memory commit | memory reserve | memory write watch Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Window / User API: threadDelayed 793 Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Window / User API: threadDelayed 9205 Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 5052 Thread sleep count: 793 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 5052 Thread sleep time: -396500s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 5052 Thread sleep count: 9205 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 5052 Thread sleep time: -4602500s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\unarchiver.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\unarchiver.exe Code function: 6_2_00C1B1D6 GetSystemInfo, 6_2_00C1B1D6
Source: chromecache_1611.2.dr, chromecache_1582.2.dr, chromecache_1211.2.dr Binary or memory string: ",ConnectVirtualMachine:"
Source: chromecache_1611.2.dr, chromecache_1582.2.dr, chromecache_1211.2.dr Binary or memory string: ",DisconnectVirtualMachine:"
Source: C:\Windows\SysWOW64\unarchiver.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process created: C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\sggy1xab.1rq" "C:\Users\user\Downloads\OneDrive_2024-04-16.zip" Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Process created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /C "C:\Users\user\AppData\Local\Temp\sggy1xab.1rq\Highway Specialties Inc\ProjectFile.pdf" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\sggy1xab.1rq\Highway Specialties Inc\ProjectFile.pdf" Jump to behavior
Source: C:\Windows\SysWOW64\unarchiver.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs