Windows Analysis Report
https://security.microsoft.com/quarantine?id=97a71014-954b-4feb-794d-08dc6372e303%5C98d07de9-cb26-b9f0-ba1e-09ca04ceb516&recipientAddress=%40ENC%40D9yt9c5hG3%2F4wJDKGc%2FbR3AuhdsaTWJ0Bg22uw1BWgTyTC%2BWm%2FZe7jBqtCP%2FpiaYXc1LB9Cngaxkq7SO1S5t4A%3D%3D

Overview

General Information

Sample URL: https://security.microsoft.com/quarantine?id=97a71014-954b-4feb-794d-08dc6372e303%5C98d07de9-cb26-b9f0-ba1e-09ca04ceb516&recipientAddress=%40ENC%40D9yt9c5hG3%2F4wJDKGc%2FbR3AuhdsaTWJ0Bg22uw1BWgTyTC%2B
Analysis ID: 1430822
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found iframes
HTML body contains low number of good links
HTML title does not match URL
Submit button contains javascript call

Classification

Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: Iframe src: https://fpt.live.com/?session_id=c4c87b039cc74659b3188fb5a3c019f3&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SU&mkt=EN-US
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0 HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: Number of links: 0
Source: https://account.live.com/password/reset?wreply=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhdNPi-NkAAbwZjpbZwbcHRZZRhGcgwcR2yZvkyYdGKRt0iZtk6Zpm0kCGpo0TdI0efOvTdM9C97c26J40tueRBHEg-xBcJm9LHtR9hPIHkQUlj3a-QRentPv9jzPyVG9AkAFq6AfFrEKdvE-hZqmOauTZQI35mUcnxllqg6IMm6QDROfmyRJEvHdk9Pi_Se__va12vnh7Isfv3389r-PkPecNA2Ti2o1scx17KZ5xXfNGCZwkVZM6Fd_QpBnCPIngjw6SOo1Cm8QtQYAdRKgjQbAKrzPZzxt5qrPp8JS8NUxigoTaTWYeJgARqm2ZDCNbu6N4wiA2Wq-Smi0CobdvZ9IzrB947ndYGLXhrSd8qDjqleSq4JpptGy9-LgzrC5Th1wEzB2d9Y_B8cLGPt6CJP0q-Lz4jC0Am7ehkFgmWnlhllB6pqz1IWBGMPQilPXSi7p3dpGV5zOKXTgyO0eKXSF1WADzUxaXgF81oyC3hije45BKiQnMG3WLgsTetNZpH56tYiBPu9QnqYTzsJI1ig3l1sp26IDXFZbwGNYYtVIajUdj1pqc2TFMCNszou4eb8xwWCPLMOdU5slwJBGAh9SeGSJLtkug-m2paSks4tEdyL2cIljJWM-7QrmiMm13U5ChTZDxOMos8l4KY1wIt8E6YCaUhiPtpxcabKzKG9u1b5qs9qwL9ci2bKgHAZ85tUFxd5krbyDGSLeV_3uYMF0iLBOUxzdRZWMYDh6SHr5HLMHYyLIAz1pc56lqVlCjxpMuA3nC7ntCUp_ZTMB1Ri4bA78DePyJmPw7JQRRCXMxrxp-cCcaGJnEakbrK4r1tSx1mpZtJx2RiZ9at1v0taa4GamonYwEPE45Oww4Y22sSlPXKIzE_VFtLFhX2RlAL8v... HTTP Parser: Number of links: 0
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0 HTTP Parser: Title: Redirecting does not match URL
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: Title: Sign in to your account does not match URL
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: Title: Create account does not match URL
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: On click: OnBack(); return false;
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: On click: HOSTUI.evt_inlineBack_onclick();
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: On click: HOSTUI.evt_inlineBack_onclick();
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: <input type="password" .../> found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0 HTTP Parser: No favicon
Source: https://fpt.live.com/?session_id=c4c87b039cc74659b3188fb5a3c019f3&CustomerId=33e01921-4d64-4f8c-a055-5bdaffd5e33d&PageId=SU&mkt=EN-US HTTP Parser: No favicon
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: No <meta name="author".. found
Source: https://account.live.com/password/reset?wreply=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhdNPi-NkAAbwZjpbZwbcHRZZRhGcgwcR2yZvkyYdGKRt0iZtk6Zpm0kCGpo0TdI0efOvTdM9C97c26J40tueRBHEg-xBcJm9LHtR9hPIHkQUlj3a-QRentPv9jzPyVG9AkAFq6AfFrEKdvE-hZqmOauTZQI35mUcnxllqg6IMm6QDROfmyRJEvHdk9Pi_Se__va12vnh7Isfv3389r-PkPecNA2Ti2o1scx17KZ5xXfNGCZwkVZM6Fd_QpBnCPIngjw6SOo1Cm8QtQYAdRKgjQbAKrzPZzxt5qrPp8JS8NUxigoTaTWYeJgARqm2ZDCNbu6N4wiA2Wq-Smi0CobdvZ9IzrB947ndYGLXhrSd8qDjqleSq4JpptGy9-LgzrC5Th1wEzB2d9Y_B8cLGPt6CJP0q-Lz4jC0Am7ehkFgmWnlhllB6pqz1IWBGMPQilPXSi7p3dpGV5zOKXTgyO0eKXSF1WADzUxaXgF81oyC3hije45BKiQnMG3WLgsTetNZpH56tYiBPu9QnqYTzsJI1ig3l1sp26IDXFZbwGNYYtVIajUdj1pqc2TFMCNszou4eb8xwWCPLMOdU5slwJBGAh9SeGSJLtkug-m2paSks4tEdyL2cIljJWM-7QrmiMm13U5ChTZDxOMos8l4KY1wIt8E6YCaUhiPtpxcabKzKG9u1b5qs9qwL9ci2bKgHAZ85tUFxd5krbyDGSLeV_3uYMF0iLBOUxzdRZWMYDh6SHr5HLMHYyLIAz1pc56lqVlCjxpMuA3nC7ntCUp_ZTMB1Ri4bA78DePyJmPw7JQRRCXMxrxp-cCcaGJnEakbrK4r1tSx1mpZtJx2RiZ9at1v0taa4GamonYwEPE45Oww4Y22sSlPXKIzE_VFtLFhX2RlAL8v HTTP Parser: No <meta name="author".. found
Source: https://account.live.com/password/reset?wreply=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhdNPi-NkAAbwZjpbZwbcHRZZRhGcgwcR2yZvkyYdGKRt0iZtk6Zpm0kCGpo0TdI0efOvTdM9C97c26J40tueRBHEg-xBcJm9LHtR9hPIHkQUlj3a-QRentPv9jzPyVG9AkAFq6AfFrEKdvE-hZqmOauTZQI35mUcnxllqg6IMm6QDROfmyRJEvHdk9Pi_Se__va12vnh7Isfv3389r-PkPecNA2Ti2o1scx17KZ5xXfNGCZwkVZM6Fd_QpBnCPIngjw6SOo1Cm8QtQYAdRKgjQbAKrzPZzxt5qrPp8JS8NUxigoTaTWYeJgARqm2ZDCNbu6N4wiA2Wq-Smi0CobdvZ9IzrB947ndYGLXhrSd8qDjqleSq4JpptGy9-LgzrC5Th1wEzB2d9Y_B8cLGPt6CJP0q-Lz4jC0Am7ehkFgmWnlhllB6pqz1IWBGMPQilPXSi7p3dpGV5zOKXTgyO0eKXSF1WADzUxaXgF81oyC3hije45BKiQnMG3WLgsTetNZpH56tYiBPu9QnqYTzsJI1ig3l1sp26IDXFZbwGNYYtVIajUdj1pqc2TFMCNszou4eb8xwWCPLMOdU5slwJBGAh9SeGSJLtkug-m2paSks4tEdyL2cIljJWM-7QrmiMm13U5ChTZDxOMos8l4KY1wIt8E6YCaUhiPtpxcabKzKG9u1b5qs9qwL9ci2bKgHAZ85tUFxd5krbyDGSLeV_3uYMF0iLBOUxzdRZWMYDh6SHr5HLMHYyLIAz1pc56lqVlCjxpMuA3nC7ntCUp_ZTMB1Ri4bA78DePyJmPw7JQRRCXMxrxp-cCcaGJnEakbrK4r1tSx1mpZtJx2RiZ9at1v0taa4GamonYwEPE45Oww4Y22sSlPXKIzE_VFtLFhX2RlAL8v HTTP Parser: No <meta name="author".. found
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0 HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?client_id=80ccca67-54bd-44ab-8625-4b79c4dc7775&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DDzug0lI_IXDnhVCJ7NGNlLvocwRjW24aAqnJS1DJhb7X7INECHg-NTDvFftmtWfr2_dF8kZ_5hfbsu0IdVBtHBDn4VYB2kEH5l9s33_4qBYAQerow5gIkqIdK9T1oJ7-ozh3as2bRQNMp84qePi7C-2UxBXt7hzqPiTPJ4RIHRbdUGNcQEyZzzR0NCE5rSqwg7rjRQ45yvntL8U81M0BhyXAHaqyAxYKYgHZOKV3qVeeoVpnMwk6NXgvwByF1bP4KYmGLfEF5p6D8IDG0Xw5EIDO7kyd1gLS5nyn_sCIkeZYwsDQ9EpxpdfVCkNXKlgEn89LiHy2mvEiMcEbMHUENPXpwSMcem2cTZPFfqYv16_XeUheuY-PehCw7sK8uKADeu5IacXYF12qM4oIgpsMbCbv-Ti5FaP_fqvgoKPHV2o&response_mode=form_post&nonce=638495392267209921.MmMwMDcyYmMtNjNmYS00NTRlLTk1N2QtZjE1ZDAwMDhhN2ExZmY5ZDY2OGMtNTRhOC00NTIzLTg3ODgtM2FiYWRiY2UwZDVk&client-request-id=c4c87b03-9cc7-4659-b318-8fb5a3c019f3&redirect_uri=https%3A%2F%2Fsecurity.microsoft.com%2F&x-client-SKU=ID_NET461&x-client-ver=6.22.1.0&sso_reload=true HTTP Parser: No <meta name="copyright".. found
Source: https://account.live.com/password/reset?wreply=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhdNPi-NkAAbwZjpbZwbcHRZZRhGcgwcR2yZvkyYdGKRt0iZtk6Zpm0kCGpo0TdI0efOvTdM9C97c26J40tueRBHEg-xBcJm9LHtR9hPIHkQUlj3a-QRentPv9jzPyVG9AkAFq6AfFrEKdvE-hZqmOauTZQI35mUcnxllqg6IMm6QDROfmyRJEvHdk9Pi_Se__va12vnh7Isfv3389r-PkPecNA2Ti2o1scx17KZ5xXfNGCZwkVZM6Fd_QpBnCPIngjw6SOo1Cm8QtQYAdRKgjQbAKrzPZzxt5qrPp8JS8NUxigoTaTWYeJgARqm2ZDCNbu6N4wiA2Wq-Smi0CobdvZ9IzrB947ndYGLXhrSd8qDjqleSq4JpptGy9-LgzrC5Th1wEzB2d9Y_B8cLGPt6CJP0q-Lz4jC0Am7ehkFgmWnlhllB6pqz1IWBGMPQilPXSi7p3dpGV5zOKXTgyO0eKXSF1WADzUxaXgF81oyC3hije45BKiQnMG3WLgsTetNZpH56tYiBPu9QnqYTzsJI1ig3l1sp26IDXFZbwGNYYtVIajUdj1pqc2TFMCNszou4eb8xwWCPLMOdU5slwJBGAh9SeGSJLtkug-m2paSks4tEdyL2cIljJWM-7QrmiMm13U5ChTZDxOMos8l4KY1wIt8E6YCaUhiPtpxcabKzKG9u1b5qs9qwL9ci2bKgHAZ85tUFxd5krbyDGSLeV_3uYMF0iLBOUxzdRZWMYDh6SHr5HLMHYyLIAz1pc56lqVlCjxpMuA3nC7ntCUp_ZTMB1Ri4bA78DePyJmPw7JQRRCXMxrxp-cCcaGJnEakbrK4r1tSx1mpZtJx2RiZ9at1v0taa4GamonYwEPE45Oww4Y22sSlPXKIzE_VFtLFhX2RlAL8v... HTTP Parser: No <meta name="copyright".. found
Source: https://account.live.com/password/reset?wreply=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAhdNPi-NkAAbwZjpbZwbcHRZZRhGcgwcR2yZvkyYdGKRt0iZtk6Zpm0kCGpo0TdI0efOvTdM9C97c26J40tueRBHEg-xBcJm9LHtR9hPIHkQUlj3a-QRentPv9jzPyVG9AkAFq6AfFrEKdvE-hZqmOauTZQI35mUcnxllqg6IMm6QDROfmyRJEvHdk9Pi_Se__va12vnh7Isfv3389r-PkPecNA2Ti2o1scx17KZ5xXfNGCZwkVZM6Fd_QpBnCPIngjw6SOo1Cm8QtQYAdRKgjQbAKrzPZzxt5qrPp8JS8NUxigoTaTWYeJgARqm2ZDCNbu6N4wiA2Wq-Smi0CobdvZ9IzrB947ndYGLXhrSd8qDjqleSq4JpptGy9-LgzrC5Th1wEzB2d9Y_B8cLGPt6CJP0q-Lz4jC0Am7ehkFgmWnlhllB6pqz1IWBGMPQilPXSi7p3dpGV5zOKXTgyO0eKXSF1WADzUxaXgF81oyC3hije45BKiQnMG3WLgsTetNZpH56tYiBPu9QnqYTzsJI1ig3l1sp26IDXFZbwGNYYtVIajUdj1pqc2TFMCNszou4eb8xwWCPLMOdU5slwJBGAh9SeGSJLtkug-m2paSks4tEdyL2cIljJWM-7QrmiMm13U5ChTZDxOMos8l4KY1wIt8E6YCaUhiPtpxcabKzKG9u1b5qs9qwL9ci2bKgHAZ85tUFxd5krbyDGSLeV_3uYMF0iLBOUxzdRZWMYDh6SHr5HLMHYyLIAz1pc56lqVlCjxpMuA3nC7ntCUp_ZTMB1Ri4bA78DePyJmPw7JQRRCXMxrxp-cCcaGJnEakbrK4r1tSx1mpZtJx2RiZ9at1v0taa4GamonYwEPE45Oww4Y22sSlPXKIzE_VFtLFhX2RlAL8v... HTTP Parser: No <meta name="copyright".. found
Source: https://signup.live.com/signup?sru=https%3a%2f%2flogin.live.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3d39931C6663A5EF82%26opidt%3d1713942453%26uaid%3dc4c87b039cc74659b3188fb5a3c019f3%26contextid%3d11133D18AA8AB244%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=c4c87b039cc74659b3188fb5a3c019f3&suc=80ccca67-54bd-44ab-8625-4b79c4dc7775&lic=1 HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.6:49714 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 23.202.57.177
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_Ggyc2EJnCaHFrI6xkBPLcg2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/ConvergedLogin_PCore_jHSrlUosdD1xxbmcR_lMNA2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_l2bvdjfwt697xziuhxpwsg2.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_7f0a8c2a247460fad87f.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_eb638da25d4055fbbb57.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/asyncchunk/convergedlogin_presetpasswordsplitter_3c78f555810791db83a9.js HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/picker_account_aad_a8332c62695d74843a11daf39a74e552.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/picker_account_msa_3b879963b4f70829fd7a25cbc9519792.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/picker_account_aad_a8332c62695d74843a11daf39a74e552.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/images/picker_account_msa_3b879963b4f70829fd7a25cbc9519792.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/js/reset-password-signinname_en_G9nzWSnqBfHRIaMd4FEm5g2.js HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://account.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/chunks/oneds-analytics-js_54b1724af1b05e2ba3db_en.js HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://account.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/2_bc3d32a696895f78c19d.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /shared/5/images/2_bc3d32a696895f78c19d.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/favicon.ico?v=2 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://account.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/favicon.ico?v=2 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /converged_ux_v2_nBE5FSqn9KpH44ZlTc3VqQ2.css?v=1 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://signup.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jqueryshim_hlu0tTfjWJFWYNt1WZrVqg2.js?v=1 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://signup.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /knockout_3.3.0_X1BYS2jZMbi7hfUj8VuqFA2.js?v=1 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://signup.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /lwsignupstringscountrybirthdate_en-us_gdxUIqa3ijrOefuBnwhTKg2.js?v=1 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://signup.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /lightweightsignuppackage_9itStK--DdHYjkMJSN7X3A2.js?v=1 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://signup.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /datarequestpackage_h-_7C7UzwdefXJT9njDBTQ2.js HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://signup.live.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /oneds_MC5gQfpbTUjLu60sQCwU1w2.js?v=1 HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg HTTP/1.1Host: acctcdn.msauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg HTTP/1.1Host: acctcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg HTTP/1.1Host: acctcdn.msauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknown DNS traffic detected: queries for: www.google.com
Source: unknown HTTP traffic detected: POST /report/MSA-UX-All HTTP/1.1Host: csp.microsoft.comConnection: keep-aliveContent-Length: 790sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/csp-reportAccept: */*Origin: https://signup.live.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: reportReferer: https://signup.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_117.2.dr String found in binary or memory: https://fpt.live.com/
Source: chromecache_75.2.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_75.2.dr String found in binary or memory: https://login.windows-ppe.net
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49806 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49806
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49805
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.6:49711 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.202.57.177:443 -> 192.168.2.6:49714 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.64:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: classification engine Classification label: clean2.win@20/93@24/7
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2128,i,8466329584062212164,3061137521727942845,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://security.microsoft.com/quarantine?id=97a71014-954b-4feb-794d-08dc6372e303%5C98d07de9-cb26-b9f0-ba1e-09ca04ceb516&recipientAddress=%40ENC%40D9yt9c5hG3%2F4wJDKGc%2FbR3AuhdsaTWJ0Bg22uw1BWgTyTC%2BWm%2FZe7jBqtCP%2FpiaYXc1LB9Cngaxkq7SO1S5t4A%3D%3D"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2128,i,8466329584062212164,3061137521727942845,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Next
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Next
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs