Windows Analysis Report
https://estgirls-my.sharepoint.com/:b:/g/personal/s7958766_estg_moe_gov_sa/EeCN0MAR0F5NufUZkT2Q-mcBn4v13Ov8FQ0oi798Dgtayg?e=zTKNmK

Overview

General Information

Sample URL: https://estgirls-my.sharepoint.com/:b:/g/personal/s7958766_estg_moe_gov_sa/EeCN0MAR0F5NufUZkT2Q-mcBn4v13Ov8FQ0oi798Dgtayg?e=zTKNmK
Analysis ID: 1428971
Infos:

Detection

HTMLPhisher
Score: 64
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Phishing site detected (based on favicon image match)
Yara detected HtmlPhish54
Phishing site detected (based on image similarity)
Phishing site detected (based on logo match)
Drops files with a non-matching file extension (content does not match file extension)
HTML body contains low number of good links
HTML title does not match URL
Phishing site detected (based on OCR NLP Model)
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: https://belovedkittenrescue.com Matcher: Template: microsoft matched with high similarity
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true Matcher: Template: microsoft matched with high similarity
Source: Yara match File source: 2.7.pages.csv, type: HTML
Source: Yara match File source: 1.6.pages.csv, type: HTML
Source: Yara match File source: 2.8.pages.csv, type: HTML
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true Matcher: Found strong image similarity, brand: MICROSOFT
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv Matcher: Template: microsoft matched
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0 HTTP Parser: Number of links: 0
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: Number of links: 0
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0 HTTP Parser: Title: Redirecting does not match URL
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: Title: Sign in to your account does not match URL
Source: Chrome DOM: 0.4 ML Model on OCR Text: Matched 98.0% probability on "contract.pdf Info 1/1 DOCUMENT IS PRIVATE C.I .1C.K TO UNI OCK Note: This Document was shared via Office365 and registered as private, Recipients "
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: <input type="password" .../> found
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0 HTTP Parser: No favicon
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0 HTTP Parser: No <meta name="author".. found
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0 HTTP Parser: No <meta name="copyright".. found
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49788 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49790 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49821 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:50116 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: global traffic HTTP traffic detected: GET /:b:/g/personal/s7958766_estg_moe_gov_sa/EeCN0MAR0F5NufUZkT2Q-mcBn4v13Ov8FQ0oi798Dgtayg?e=zTKNmK HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/s7958766_estg_moe_gov_sa/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%2Fcontract%2Epdf&parent=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments&ga=1 HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/s7958766_estg_moe_gov_sa/_api/v2.1/graphql HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://estgirls-my.sharepoint.com/personal/s7958766_estg_moe_gov_sa/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%2Fcontract%2Epdf&parent=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/s7958766_estg_moe_gov_sa/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/s7958766_estg_moe_gov_sa/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%5D&defaultBrotli=true&authenticateFast=true&wwData=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099649,3]&spStartApplicationWebBundle=true&enableIntegrities=true HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveCache-Control: max-age=0Accept: */*Service-Worker: scriptSec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: serviceworkerReferer: https://estgirls-my.sharepoint.com/personal/s7958766_estg_moe_gov_sa/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%2Fcontract%2Epdf&parent=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments&ga=1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=P1xUBD9uvDNMGwa&MD=LEa4PNHp HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /transform/thumbnail?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Festgirls-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!3wg9-hIsbkKjisgTkXNd6LRDPUacccZPsT38WqC54ml1Bruter-IRZ4fXQ1eVBg9%2Fitems%2F01PD5Q4JXARXIMAEOQLZG3T5IZSE6ZB6TH%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvZXN0Z2lybHMtbXkuc2hhcmVwb2ludC5jb21AYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiIiwiY2FjaGVrZXkiOiIwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNlNDM3NmVjMDI1NmQ1MTJlMjM3MzIwOWNmNDM5OTY5ZGE0ZDk0MzYzNGZlOTZjYTU1NmZmMWE3YTFjMTVhNGJlIiwiZW5kcG9pbnR1cmwiOiJURjgwRTBXRUM0cWNENzhvRWQxb0gwRjNxVXl4RlF6RXdvSjlrT1VybHlNPSIsImVuZHBvaW50dXJsTGVuZ3RoIjoiMTE4IiwiZXhwIjoiMTcxMzU4MjAwMCIsImlwYWRkciI6IjgxLjE4MS41Ny41MiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUiLCJuYmYiOiIxNzEzNTYwNDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJ5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBIiwic2l0ZWlkIjoiWm1FelpEQTRaR1l0TW1NeE1pMDBNalpsTFdFek9HRXRZemd4TXpreE56TTFaR1U0Iiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9.8Y66lcXGe2_cHFeRKyyRySxf12-D-9sDpuBarQzfz2I&cTag=%22c%3A%7BC0D08DE0-D011-4D5E-B9F5-19913D90FA67%7D%2C1%22&encodeFailures=1&width=1280&height=859&srcWidth=&srcHeight= HTTP/1.1Host: northeurope1-mediap.svc.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://estgirls-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/thumbnail?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Festgirls-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!3wg9-hIsbkKjisgTkXNd6LRDPUacccZPsT38WqC54ml1Bruter-IRZ4fXQ1eVBg9%2Fitems%2F01PD5Q4JXARXIMAEOQLZG3T5IZSE6ZB6TH%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvZXN0Z2lybHMtbXkuc2hhcmVwb2ludC5jb21AYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiIiwiY2FjaGVrZXkiOiIwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNlNDM3NmVjMDI1NmQ1MTJlMjM3MzIwOWNmNDM5OTY5ZGE0ZDk0MzYzNGZlOTZjYTU1NmZmMWE3YTFjMTVhNGJlIiwiZW5kcG9pbnR1cmwiOiJURjgwRTBXRUM0cWNENzhvRWQxb0gwRjNxVXl4RlF6RXdvSjlrT1VybHlNPSIsImVuZHBvaW50dXJsTGVuZ3RoIjoiMTE4IiwiZXhwIjoiMTcxMzU4MjAwMCIsImlwYWRkciI6IjgxLjE4MS41Ny41MiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUiLCJuYmYiOiIxNzEzNTYwNDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJ5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBIiwic2l0ZWlkIjoiWm1FelpEQTRaR1l0TW1NeE1pMDBNalpsTFdFek9HRXRZemd4TXpreE56TTFaR1U0Iiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9.8Y66lcXGe2_cHFeRKyyRySxf12-D-9sDpuBarQzfz2I&cTag=%22c%3A%7BC0D08DE0-D011-4D5E-B9F5-19913D90FA67%7D%2C1%22&encodeFailures=1&width=1280&height=859&srcWidth=&srcHeight= HTTP/1.1Host: northeurope1-mediap.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=odbmspdfwebworker&debug=false&bypass=false HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: workerReferer: https://estgirls-my.sharepoint.com/personal/s7958766_estg_moe_gov_sa/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%2Fcontract%2Epdf&parent=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=96a77dd9-6490-4fb8-b4ec-b19d1744dedb
Source: global traffic HTTP traffic detected: GET /transform/passthrough?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Festgirls-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!3wg9-hIsbkKjisgTkXNd6LRDPUacccZPsT38WqC54ml1Bruter-IRZ4fXQ1eVBg9%2Fitems%2F01PD5Q4JXARXIMAEOQLZG3T5IZSE6ZB6TH%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvZXN0Z2lybHMtbXkuc2hhcmVwb2ludC5jb21AYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiIiwiY2FjaGVrZXkiOiIwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNlNDM3NmVjMDI1NmQ1MTJlMjM3MzIwOWNmNDM5OTY5ZGE0ZDk0MzYzNGZlOTZjYTU1NmZmMWE3YTFjMTVhNGJlIiwiZW5kcG9pbnR1cmwiOiJURjgwRTBXRUM0cWNENzhvRWQxb0gwRjNxVXl4RlF6RXdvSjlrT1VybHlNPSIsImVuZHBvaW50dXJsTGVuZ3RoIjoiMTE4IiwiZXhwIjoiMTcxMzU4MjAwMCIsImlwYWRkciI6IjgxLjE4MS41Ny41MiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUiLCJuYmYiOiIxNzEzNTYwNDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJ5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBIiwic2l0ZWlkIjoiWm1FelpEQTRaR1l0TW1NeE1pMDBNalpsTFdFek9HRXRZemd4TXpreE56TTFaR1U0Iiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9.8Y66lcXGe2_cHFeRKyyRySxf12-D-9sDpuBarQzfz2I&cTag=%22c%3A%7BC0D08DE0-D011-4D5E-B9F5-19913D90FA67%7D%2C1%22 HTTP/1.1Host: northeurope1-mediap.svc.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://estgirls-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://estgirls-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/passthrough?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Festgirls-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!3wg9-hIsbkKjisgTkXNd6LRDPUacccZPsT38WqC54ml1Bruter-IRZ4fXQ1eVBg9%2Fitems%2F01PD5Q4JXARXIMAEOQLZG3T5IZSE6ZB6TH%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvZXN0Z2lybHMtbXkuc2hhcmVwb2ludC5jb21AYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiIiwiY2FjaGVrZXkiOiIwaC5mfG1lbWJlcnNoaXB8dXJuJTNhc3BvJTNhYW5vbiNlNDM3NmVjMDI1NmQ1MTJlMjM3MzIwOWNmNDM5OTY5ZGE0ZDk0MzYzNGZlOTZjYTU1NmZmMWE3YTFjMTVhNGJlIiwiZW5kcG9pbnR1cmwiOiJURjgwRTBXRUM0cWNENzhvRWQxb0gwRjNxVXl4RlF6RXdvSjlrT1VybHlNPSIsImVuZHBvaW50dXJsTGVuZ3RoIjoiMTE4IiwiZXhwIjoiMTcxMzU4MjAwMCIsImlwYWRkciI6IjgxLjE4MS41Ny41MiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUiLCJuYmYiOiIxNzEzNTYwNDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJ5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBIiwic2l0ZWlkIjoiWm1FelpEQTRaR1l0TW1NeE1pMDBNalpsTFdFek9HRXRZemd4TXpreE56TTFaR1U0Iiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9.8Y66lcXGe2_cHFeRKyyRySxf12-D-9sDpuBarQzfz2I&cTag=%22c%3A%7BC0D08DE0-D011-4D5E-B9F5-19913D90FA67%7D%2C1%22 HTTP/1.1Host: northeurope1-mediap.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drive/apps?select=*%2Cpromoted%2CbuiltIn&%24expand=actions HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Accept: application/jsonAccept-Language: en-USsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://estgirls-my.sharepoint.com/personal/s7958766_estg_moe_gov_sa/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%2Fcontract%2Epdf&parent=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brCookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=96a77dd9-6490-4fb8-b4ec-b19d1744dedb; ai_session=MC7cg7sGb4niasRNhHeGqm|1713563563245|1713563563245; MSFPC=GUID=8fa88435355d419089b10819bd882493&HASH=8fa8&LV=202404&V=4&LU=1713563567776
Source: global traffic HTTP traffic detected: GET /haqHYyzL HTTP/1.1Host: login.ms2.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=P1xUBD9uvDNMGwa&MD=LEa4PNHp HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949
Source: global traffic HTTP traffic detected: GET /login HTTP/1.1Host: www.belovedkittenrescue.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949
Source: global traffic HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0 HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; fpc=Aofr1nfN_4pKrIPBJZ__7B0; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8pcFyjEcqiqkPAwiu684dfPaLbM6W0ioChIyo6dxKFPjNJrYhNDKJr5XQwhhy7AHKqYy7H6T4Cry0NsEBR86OQuk41EN3kEl1utzyhYsM9dfbr6Ma5LxA6Q7GWvx84NiYr5V2L6kpxnyNhksrWGH5AbWIhCEK-DgqyLbl8203kkkgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB
Source: global traffic HTTP traffic detected: GET /s/584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949.js HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; fpc=Aofr1nfN_4pKrIPBJZ__7B0; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8pcFyjEcqiqkPAwiu684dfPaLbM6W0ioChIyo6dxKFPjNJrYhNDKJr5XQwhhy7AHKqYy7H6T4Cry0NsEBR86OQuk41EN3kEl1utzyhYsM9dfbr6Ma5LxA6Q7GWvx84NiYr5V2L6kpxnyNhksrWGH5AbWIhCEK-DgqyLbl8203kkkgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_ChpboAn7HyXj89A22M8mzg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.belovedkittenrescue.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; fpc=Aofr1nfN_4pKrIPBJZ__7B0; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8pcFyjEcqiqkPAwiu684dfPaLbM6W0ioChIyo6dxKFPjNJrYhNDKJr5XQwhhy7AHKqYy7H6T4Cry0NsEBR86OQuk41EN3kEl1utzyhYsM9dfbr6Ma5LxA6Q7GWvx84NiYr5V2L6kpxnyNhksrWGH5AbWIhCEK-DgqyLbl8203kkkgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
Source: global traffic HTTP traffic detected: GET /s/584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949 HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/jsonAccept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; fpc=Aofr1nfN_4pKrIPBJZ__7B0; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8pcFyjEcqiqkPAwiu684dfPaLbM6W0ioChIyo6dxKFPjNJrYhNDKJr5XQwhhy7AHKqYy7H6T4Cry0NsEBR86OQuk41EN3kEl1utzyhYsM9dfbr6Ma5LxA6Q7GWvx84NiYr5V2L6kpxnyNhksrWGH5AbWIhCEK-DgqyLbl8203kkkgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; fpc=Aofr1nfN_4pKrIPBJZ__7B0; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8pcFyjEcqiqkPAwiu684dfPaLbM6W0ioChIyo6dxKFPjNJrYhNDKJr5XQwhhy7AHKqYy7H6T4Cry0NsEBR86OQuk41EN3kEl1utzyhYsM9dfbr6Ma5LxA6Q7GWvx84NiYr5V2L6kpxnyNhksrWGH5AbWIhCEK-DgqyLbl8203kkkgAA; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1
Source: global traffic HTTP traffic detected: GET /s/584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949.js HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AS0AMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABGgEAAADnfolhJpSnRYB1SVj-Hgd8Kpntqq_4gmNBJ5pG8l-t5k3-ChVo3lmcJE9WYZ0VV53DfyXo8AyFvmujJCLNMXhLEmirPz1AAHSyLRhQ3JIPMxWqyjVi9EZhz3UPX7EPFYEgAA; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8mO3gLCwsSTEAmiclw0fpRPhViYEbIggp7UByWLZZQ4eQ_wnNambZOkV0qZKIkJd39hL04lsBlMAnIJdSNlj0PqSDX9K1YcYP30NjjQnA-hF6M05uvenMDawboGrOVO1EgZbm0WLYbGFnW8yfmk9Smg71Y70oVVHW3ZTqXg5WBOggAA; esctx-8bMw9lHib9U=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8SsJCvaRxQ0FDac5eQSN0btq7CH7dqGIjXDsEca1TCMd7w2olwYann2mLn2V8PG4HUS5ASftJWbAOQZHethxpz-065GpS1Euovc3dFldGspNYPRGzt6Dmt36UaHgkNZ014oUiDYLJrwlR1XGnXnWpGyAA; fpc=Aofr1nfN_4pKrIPBJZ__7B0
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.belovedkittenrescue.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_jHSrlUosdD1xxbmcR_lMNA2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.belovedkittenrescue.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_l2bvdjfwt697xziuhxpwsg2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.belovedkittenrescue.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: live.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Purpose: prefetchSec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; MUID=1C2B4ED456DD69360CBF5AB2574F68DB
Source: global traffic HTTP traffic detected: GET /s/584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949 HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/jsonAccept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AS0AMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABGgEAAADnfolhJpSnRYB1SVj-Hgd8Kpntqq_4gmNBJ5pG8l-t5k3-ChVo3lmcJE9WYZ0VV53DfyXo8AyFvmujJCLNMXhLEmirPz1AAHSyLRhQ3JIPMxWqyjVi9EZhz3UPX7EPFYEgAA; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8mO3gLCwsSTEAmiclw0fpRPhViYEbIggp7UByWLZZQ4eQ_wnNambZOkV0qZKIkJd39hL04lsBlMAnIJdSNlj0PqSDX9K1YcYP30NjjQnA-hF6M05uvenMDawboGrOVO1EgZbm0WLYbGFnW8yfmk9Smg71Y70oVVHW3ZTqXg5WBOggAA; esctx-8bMw9lHib9U=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8SsJCvaRxQ0FDac5eQSN0btq7CH7dqGIjXDsEca1TCMd7w2olwYann2mLn2V8PG4HUS5ASftJWbAOQZHethxpz-065GpS1Euovc3dFldGspNYPRGzt6Dmt36UaHgkNZ014oUiDYLJrwlR1XGnXnWpGyAA; fpc=Aofr1nfN_4pKrIPBJZ__7B0
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_7f0a8c2a247460fad87f.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_4d4b76a02ae121e3b20c.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /Me.htm?v=3 HTTP/1.1Host: live.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; uaid=01510e5e6eae4ce5939bb6d3230841f3; MSPRequ=id=N&lt=1713563587&co=1
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_eb638da25d4055fbbb57.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.belovedkittenrescue.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/s7958766_estg_moe_gov_sa/_layouts/15/AccessDenied.aspx?correlation=64a820a1%2D306e%2D8000%2D995c%2D9b6cc5c5e6ff HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=96a77dd9-6490-4fb8-b4ec-b19d1744dedb; ai_session=MC7cg7sGb4niasRNhHeGqm|1713563563245|1713563563245; MSFPC=GUID=8fa88435355d419089b10819bd882493&HASH=8fa8&LV=202404&V=4&LU=1713563567776
Source: global traffic HTTP traffic detected: GET /s/584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949 HTTP/1.1Host: login.belovedkittenrescue.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/jsonAccept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://login.belovedkittenrescue.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638491603836773377.YWYyN2ZmZTMtZmVkZC00MjkyLWE1MDUtMTAyMGM3ZmVkMTA5NTM0ZTVhNDEtNWVmNy00MWIwLWI4OGMtNGIxMTFhY2JmYjYw&ui_locales=en-US&mkt=en-US&client-request-id=600ecc9f-8cd6-4159-9546-3c8e804e0f30&state=gD_wYeOwKh_0M2IfdhDmNbsuzCciwOT89MBvGw2fAuLSi62L0WPMtOWaW54uSv219WlN2Vr8PeZQC-tVujsv53jwfLx2c7HjiAq-xzKdFFEN9jkogseCbwBBvyxMItpSkCr2Ktv8JTckAbOSFm3Bi3T9KNRXmVxT94fbxC9K2OQzho4BAtnJDCmBCSrVWxUPq9UHkav7236_fh3p7H3gPHcwdXq8J0eGYmPZsm-VvJOpvWj84Q9c4TdgB3Djdc4vzqAhU3uifCZAkpdA_Y0o4Q&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=trueAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: a405-c7b6=584d307eccd81b2443ec9cedbff3f8eccebcf5e97ea6f429adf85db6c7fbf949; x-ms-gateway-slice=estsfd; stsservicecookie=estsfd; MUID=1C2B4ED456DD69360CBF5AB2574F68DB; esctx-nHQZGErJRuA=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8bkpp32JSNstUewKLqiHTea8LvlhnK7BvugVAnBVgC_PIFZHYKLf3CDV3nfYqEwfVoCcCTXREKVuiRn9tpjmVooRnGONZbzPxo3tSldJRB6sU0hkhAySxsd0SyGAibJcJd4nB0uJOrSNIf7uwVeHNVCAA; AADSSO=NA|NoExtension; SSOCOOKIEPULLED=1; buid=0.AS0AMe_N-B6jSkuT5F9XHpElWltEZUfGMrBJg-Ydk3ZSdsoBAAA.AQABGgEAAADnfolhJpSnRYB1SVj-Hgd8Kpntqq_4gmNBJ5pG8l-t5k3-ChVo3lmcJE9WYZ0VV53DfyXo8AyFvmujJCLNMXhLEmirPz1AAHSyLRhQ3JIPMxWqyjVi9EZhz3UPX7EPFYEgAA; esctx=PAQABBwEAAADnfolhJpSnRYB1SVj-Hgd8mO3gLCwsSTEAmiclw0fpRPhViYEbIggp7UByWLZZQ4eQ_wnNambZOkV0qZKIkJd39hL04lsBlMAnIJdSNlj0PqSDX9K1YcYP30NjjQnA-hF6M05uvenMDawboGrOVO1EgZbm0WLYbGFnW8yfmk9Smg71Y70oVVHW3ZTqXg5WBOggAA; esctx-8bMw9lHib9U=AQABCQEAAADnfolhJpSnRYB1SVj-Hgd8SsJCvaRxQ0FDac5eQSN0btq7CH7dqGIjXDsEca1TCMd7w2olwYann2mLn2V8PG4HUS5ASftJWbAOQZHethxpz-065GpS1Euovc3dFldGspNYPRGzt6Dmt36UaHgkNZ014oUiDYLJrwlR1XGnXnWpGyAA; fpc=Aofr1nfN_4pKrIPBJZ__7B0; brcap=0
Source: unknown DNS traffic detected: queries for: estgirls-my.sharepoint.com
Source: unknown HTTP traffic detected: POST /personal/s7958766_estg_moe_gov_sa/_api/v2.1/graphql HTTP/1.1Host: estgirls-my.sharepoint.comConnection: keep-aliveContent-Length: 507sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"accept: application/json;odata=verboseContent-Type: application/json;odata=verboseX-ServiceWorker-Strategy: CacheFirstsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Origin: https://estgirls-my.sharepoint.comSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://estgirls-my.sharepoint.com/personal/s7958766_estg_moe_gov_sa/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments%2Fcontract%2Epdf&parent=%2Fpersonal%2Fs7958766%5Festg%5Fmoe%5Fgov%5Fsa%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uI2U0Mzc2ZWMwMjU2ZDUxMmUyMzczMjA5Y2Y0Mzk5NjlkYTRkOTQzNjM0ZmU5NmNhNTU2ZmYxYTdhMWMxNWE0YmUsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jZTQzNzZlYzAyNTZkNTEyZTIzNzMyMDljZjQzOTk2OWRhNGQ5NDM2MzRmZTk2Y2E1NTZmZjFhN2ExYzE1YTRiZSwxMzM1ODAzNzQzMDAwMDAwMDAsMCwxMzM1ODEyMzUzMDMyNTM3MDYsMC4wLjAuMCwyNTgsYjY4NzViYmItZjM3MS00ODBkLWFiYTEtMjk3MmNlMDQyYzJiLCwsNTRhODIwYTEtOTBiYS04MDAwLTlkNWQtMzE4ODYzYzhjZDU1LDU0YTgyMGExLTkwYmEtODAwMC05ZDVkLTMxODg2M2M4Y2Q1NSx5Y3g1bkRkcjhVcVM2NUhBUmhHa0VBLDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxODgyMTQsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LGhNRTI1VDIwbktQODAxRFhzZTk4U3l2eUdtRmRLUWphc3dEQlBWUXVPQUxwMERGSzM5aSsyaFozaVJJUE1FcWFyWEdFVkJIWjI2YkpvV0llTStsbUxnWHlKakc4UWdOckhpNjB6WlcvU1RjQ2l2eW15ek5ZYm1QRUpObXZveUhxbVozUXR0dm5NeFR5aENrTkVBTHh6ek43RUpOQTBNVmZHRjljYk43QTVpc3VxeGFYWGpRSlZzTjNub0ZEd1d6aytza1BPT2NLT2hPSkhHUU5adGpTdU1GTWJoV2t3N2xUY29TNGZTNzQ3NFNhenNEWjdLVDl2UnM5NWl0NG1ucy9wMHM5M053STIwNmtyUWRtcFRYdjJqLzN0c3MyWlladDF6cXZsRk1HZHZnVkpZUy81UWFJOGZ4OEQyUUQ1cHdBUENIS0dlcXowcmxFaUhodlY4MDVSUT09PC9TUD4=
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not Found
Source: chromecache_694.1.dr, chromecache_884.1.dr String found in binary or memory: http://scripts.sil.org/OFLThis
Source: chromecache_349.1.dr, chromecache_446.1.dr, chromecache_889.1.dr, chromecache_717.1.dr, chromecache_814.1.dr, chromecache_406.1.dr, chromecache_357.1.dr, chromecache_767.1.dr, chromecache_952.1.dr String found in binary or memory: http://www.contoso.com
Source: chromecache_762.1.dr String found in binary or memory: http://www.unicode.org/copyright.html
Source: chromecache_449.1.dr, chromecache_702.1.dr String found in binary or memory: https://1drv.com/
Source: chromecache_733.1.dr, chromecache_978.1.dr, chromecache_483.1.dr, chromecache_745.1.dr String found in binary or memory: https://200.hc.com/the-harpercollins-200/moby-dick/
Source: chromecache_449.1.dr, chromecache_702.1.dr String found in binary or memory: https://centralus1-mediad.svc.ms
Source: chromecache_979.1.dr String found in binary or memory: https://facebook.github.io/react/docs/more-about-refs.html#the-ref-callback-attribute
Source: chromecache_642.1.dr String found in binary or memory: https://github.com/uuidjs/uuid#getrandomvalues-not-supported
Source: chromecache_449.1.dr, chromecache_702.1.dr String found in binary or memory: https://livefilestore.com/
Source: chromecache_776.1.dr String found in binary or memory: https://loki.delve.office.com
Source: chromecache_449.1.dr, chromecache_702.1.dr String found in binary or memory: https://media.cloudapp.net
Source: chromecache_634.1.dr, chromecache_502.1.dr String found in binary or memory: https://my.microsoftpersonalcontent.com
Source: chromecache_449.1.dr, chromecache_702.1.dr String found in binary or memory: https://northcentralus1-medias.svc.ms
Source: chromecache_414.1.dr, chromecache_779.1.dr, chromecache_634.1.dr, chromecache_386.1.dr, chromecache_607.1.dr String found in binary or memory: https://outlook.office.com/search
Source: chromecache_425.1.dr String found in binary or memory: https://outlook.office365.com
Source: chromecache_425.1.dr String found in binary or memory: https://outlook.office365.com/SchedulingB2/api/v1.0/me/findmeetinglocations
Source: chromecache_449.1.dr, chromecache_414.1.dr, chromecache_386.1.dr, chromecache_515.1.dr, chromecache_607.1.dr String found in binary or memory: https://portal.office.com/
Source: chromecache_438.1.dr String found in binary or memory: https://reactjs.org/link/react-polyfills
Source: chromecache_505.1.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-05.011/
Source: chromecache_505.1.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-05.011/pdfwebworkers/mspdf/index.worker.js
Source: chromecache_505.1.dr String found in binary or memory: https://shell.cdn.office.net/api/ShellBootstrapper/business/OneShell
Source: chromecache_702.1.dr String found in binary or memory: https://shellppe.msocdn.com
Source: chromecache_702.1.dr String found in binary or memory: https://shellprod.msocdn.com
Source: chromecache_458.1.dr String found in binary or memory: https://support.office.com/en-us/article/Manage-lists-and-libraries-with-many-items-b8588dae-9387-48
Source: chromecache_733.1.dr, chromecache_978.1.dr, chromecache_483.1.dr, chromecache_745.1.dr String found in binary or memory: https://www.littlebrown.com/titles/j-d-salinger/the-catcher-in-the-rye/9780316769488/
Source: chromecache_733.1.dr, chromecache_978.1.dr, chromecache_483.1.dr, chromecache_745.1.dr String found in binary or memory: https://www.peachpit.com/store/dont-make-me-think-revisited-a-common-sense-approach-9780321965516
Source: chromecache_733.1.dr, chromecache_978.1.dr, chromecache_483.1.dr, chromecache_745.1.dr String found in binary or memory: https://www.penguinrandomhouse.com/books/196330/great-tales-and-poems-of-edgar-allan-poe-by-edgar-al
Source: chromecache_978.1.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Great-Gatsby/F-Scott-Fitzgerald/9781982146702#:~007E;007E
Source: chromecache_745.1.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Great-Gatsby/F-Scott-Fitzgerald/9781982146702#:~007E;:tex
Source: chromecache_733.1.dr, chromecache_483.1.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Great-Gatsby/F-Scott-Fitzgerald/9781982146702#:~:text=The
Source: chromecache_733.1.dr, chromecache_978.1.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Sun-Also-Rises/Ernest-Hemingway/9781982199524#:~007E;007E
Source: chromecache_483.1.dr, chromecache_745.1.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Sun-Also-Rises/Ernest-Hemingway/9781982199524#:~:text=The
Source: unknown Network traffic detected: HTTP traffic on port 50145 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50219
Source: unknown Network traffic detected: HTTP traffic on port 50174 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50175
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50174
Source: unknown Network traffic detected: HTTP traffic on port 49932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50176
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50179
Source: unknown Network traffic detected: HTTP traffic on port 50334 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50334
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50180
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50182
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50181
Source: unknown Network traffic detected: HTTP traffic on port 50180 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50183
Source: unknown Network traffic detected: HTTP traffic on port 50125 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50227
Source: unknown Network traffic detected: HTTP traffic on port 50148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50188
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50221
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50187
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50193
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50159 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50192
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50080 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 50197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50116
Source: unknown Network traffic detected: HTTP traffic on port 50227 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50119
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50118
Source: unknown Network traffic detected: HTTP traffic on port 49947 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50147 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50197
Source: unknown Network traffic detected: HTTP traffic on port 49918 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50078
Source: unknown Network traffic detected: HTTP traffic on port 50130 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50080
Source: unknown Network traffic detected: HTTP traffic on port 49688 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 50175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50119 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50167 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50192 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49790
Source: unknown Network traffic detected: HTTP traffic on port 50150 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50125
Source: unknown Network traffic detected: HTTP traffic on port 50181 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49821
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49700
Source: unknown Network traffic detected: HTTP traffic on port 50193 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49940
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50149 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50130
Source: unknown Network traffic detected: HTTP traffic on port 50187 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50135
Source: unknown Network traffic detected: HTTP traffic on port 50078 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50221 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50158 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50161 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50135 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50140
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49932
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50149
Source: unknown Network traffic detected: HTTP traffic on port 50173 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50141
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50146
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50145
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50148
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50147
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50150
Source: unknown Network traffic detected: HTTP traffic on port 50176 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50141 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 50166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50118 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49821 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50157
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50159
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50158
Source: unknown Network traffic detected: HTTP traffic on port 50182 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50179 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49940 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50160
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49918
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50161
Source: unknown Network traffic detected: HTTP traffic on port 50140 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50146 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50166
Source: unknown Network traffic detected: HTTP traffic on port 50188 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50168
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50167
Source: unknown Network traffic detected: HTTP traffic on port 50157 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49909
Source: unknown Network traffic detected: HTTP traffic on port 50160 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50173
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49788 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49790 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49821 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:50116 version: TLS 1.2
Source: classification engine Classification label: mal64.phis.win@14/1268@32/10
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://estgirls-my.sharepoint.com/:b:/g/personal/s7958766_estg_moe_gov_sa/EeCN0MAR0F5NufUZkT2Q-mcBn4v13Ov8FQ0oi798Dgtayg?e=zTKNmK
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=1940,i,10852417767403210094,1487600739097658030,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=1940,i,10852417767403210094,1487600739097658030,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 672
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 955 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 672 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs