Windows Analysis Report
http://womenofgoodworks-my.sharepoint.com/:b:/g/personal/tia_womenofgoodworks_org/EVICmRtg-CVNtsngkb8KQlgBH2LYVfumjH5s-SFbeQjN_Q

Overview

General Information

Sample URL: http://womenofgoodworks-my.sharepoint.com/:b:/g/personal/tia_womenofgoodworks_org/EVICmRtg-CVNtsngkb8KQlgBH2LYVfumjH5s-SFbeQjN_Q
Analysis ID: 1431136
Infos:

Detection

HTMLPhisher
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish10
Phishing site detected (based on image similarity)
Phishing site detected (based on logo match)
Drops files with a non-matching file extension (content does not match file extension)
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden URLs or javascript code
HTML title does not match URL
Invalid T&C link found
Phishing site detected (based on OCR NLP Model)
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

Phishing

barindex
Source: Yara match File source: 3.10.pages.csv, type: HTML
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV Matcher: Found strong image similarity, brand: MICROSOFT
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV Matcher: Template: microsoft matched
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: Number of links: 0
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://czsbl.u6t2.com/CZsbl/ HTTP Parser: Base64 decoded: <!DOCTYPE html><html lang="en"><head> <script src="https://code.jquery.com/jquery-3.6.0.min.js"></script> <script src="https://challenges.cloudflare.com/turnstile/v0/api.js?render=explicit"></script> <meta http-equiv="X-UA-Compatible" c...
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: Title: zKNFmqCUEA does not match URL
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: Invalid link: Terms of use
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: Invalid link: Privacy & cookies
Source: Chrome DOM: 0.5 ML Model on OCR Text: Matched 84.5% probability on "Sourdough Transfer.pdf Info 1/1 A Secured has been shared with you. Eu received 3 for r review This message was sent to wu to protect sensitive information. Ref: RFP Update- "
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: <input type="password" .../> found
Source: https://czsbl.u6t2.com/CZsbl/ HTTP Parser: No favicon
Source: https://czsbl.u6t2.com/CZsbl/ HTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normal HTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normal HTTP Parser: No favicon
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: No favicon
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: No <meta name="author".. found
Source: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49775 version: TLS 1.0
Source: unknown HTTPS traffic detected: 23.61.210.98:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.61.210.98:443 -> 192.168.2.5:49725 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49775 version: TLS 1.0
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown TCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /personal/tia_womenofgoodworks_org/_layouts/15/guestaccess.aspx?share=EVICmRtg-CVNtsngkb8KQlgBH2LYVfumjH5s-SFbeQjN_Q HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/tia_womenofgoodworks_org/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%2FSourdough%20Transfer%2Epdf&parent=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments&ga=1 HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/tia_womenofgoodworks_org/_api/v2.1/graphql HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://womenofgoodworks-my.sharepoint.com/personal/tia_womenofgoodworks_org/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%2FSourdough%20Transfer%2Epdf&parent=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/tia_womenofgoodworks_org/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /personal/tia_womenofgoodworks_org/_api/web/GetListUsingPath(DecodedUrl=@a1)/RenderListDataAsStream?@a1=%27%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%27&TryNewExperienceSingle=TRUE HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%5D&defaultBrotli=true&authenticateFast=true&wwData=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099649,3]&spStartApplicationWebBundle=true&enableIntegrities=true HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveCache-Control: max-age=0Accept: */*Service-Worker: scriptSec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: serviceworkerReferer: https://womenofgoodworks-my.sharepoint.com/personal/tia_womenofgoodworks_org/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%2FSourdough%20Transfer%2Epdf&parent=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments&ga=1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: GET /transform/thumbnail?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Fwomenofgoodworks-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!nv0NYqL8VUy3nHDPf8T_JPcFSytCdeVGuoTJbeLAlGs1UkGYSCz3Q4_6QHS1v96_%2Fitems%2F01BTTHLB2SAKMRWYHYEVG3NSPASG7QUQSY%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvd29tZW5vZmdvb2R3b3Jrcy1teS5zaGFyZXBvaW50LmNvbUAxYmY5OWFiZS0wOTE5LTRkMWEtYThkMy04ZjExNjNiZjhmZWMiLCJjYWNoZWtleSI6IjBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJlbmRwb2ludHVybCI6IkdFak03TFNWNklvQW9yVEtVQmZpZU1mRzFhdzc5QlQ5dXpvMHJKdmQ4c1U9IiwiZW5kcG9pbnR1cmxMZW5ndGgiOiIxMjYiLCJleHAiOiIxNzEzOTgxNjAwIiwiaXBhZGRyIjoiMTU0LjE2LjEwNS4zNiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJuYmYiOiIxNzEzOTYwMDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJvSllOM2l0WC8wZUhOaXRDblg4dHh3Iiwic2l0ZWlkIjoiTmpJd1pHWmtPV1V0Wm1OaE1pMDBZelUxTFdJM09XTXROekJqWmpkbVl6Um1aakkwIiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9._VUZxeii-ehvfvEJVWbcas0lwdh2GsuUyhh5iUy9tpw&cTag=%22c%3A%7B1B990252-F860-4D25-B6C9-E091BF0A4258%7D%2C1%22&encodeFailures=1&width=1280&height=859&srcWidth=&srcHeight= HTTP/1.1Host: southcentralus1-mediap.svc.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://womenofgoodworks-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/thumbnail?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Fwomenofgoodworks-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!nv0NYqL8VUy3nHDPf8T_JPcFSytCdeVGuoTJbeLAlGs1UkGYSCz3Q4_6QHS1v96_%2Fitems%2F01BTTHLB2SAKMRWYHYEVG3NSPASG7QUQSY%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvd29tZW5vZmdvb2R3b3Jrcy1teS5zaGFyZXBvaW50LmNvbUAxYmY5OWFiZS0wOTE5LTRkMWEtYThkMy04ZjExNjNiZjhmZWMiLCJjYWNoZWtleSI6IjBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJlbmRwb2ludHVybCI6IkdFak03TFNWNklvQW9yVEtVQmZpZU1mRzFhdzc5QlQ5dXpvMHJKdmQ4c1U9IiwiZW5kcG9pbnR1cmxMZW5ndGgiOiIxMjYiLCJleHAiOiIxNzEzOTgxNjAwIiwiaXBhZGRyIjoiMTU0LjE2LjEwNS4zNiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJuYmYiOiIxNzEzOTYwMDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJvSllOM2l0WC8wZUhOaXRDblg4dHh3Iiwic2l0ZWlkIjoiTmpJd1pHWmtPV1V0Wm1OaE1pMDBZelUxTFdJM09XTXROekJqWmpkbVl6Um1aakkwIiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9._VUZxeii-ehvfvEJVWbcas0lwdh2GsuUyhh5iUy9tpw&cTag=%22c%3A%7B1B990252-F860-4D25-B6C9-E091BF0A4258%7D%2C1%22&encodeFailures=1&width=1280&height=859&srcWidth=&srcHeight= HTTP/1.1Host: southcentralus1-mediap.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_layouts/15/odspserviceworkerproxy.aspx?swManifestName=odbmspdfwebworker&debug=false&bypass=false HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: workerReferer: https://womenofgoodworks-my.sharepoint.com/personal/tia_womenofgoodworks_org/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%2FSourdough%20Transfer%2Epdf&parent=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=27ab627a-db53-4042-baab-67b95b54eaaa
Source: global traffic HTTP traffic detected: GET /transform/passthrough?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Fwomenofgoodworks-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!nv0NYqL8VUy3nHDPf8T_JPcFSytCdeVGuoTJbeLAlGs1UkGYSCz3Q4_6QHS1v96_%2Fitems%2F01BTTHLB2SAKMRWYHYEVG3NSPASG7QUQSY%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvd29tZW5vZmdvb2R3b3Jrcy1teS5zaGFyZXBvaW50LmNvbUAxYmY5OWFiZS0wOTE5LTRkMWEtYThkMy04ZjExNjNiZjhmZWMiLCJjYWNoZWtleSI6IjBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJlbmRwb2ludHVybCI6IkdFak03TFNWNklvQW9yVEtVQmZpZU1mRzFhdzc5QlQ5dXpvMHJKdmQ4c1U9IiwiZW5kcG9pbnR1cmxMZW5ndGgiOiIxMjYiLCJleHAiOiIxNzEzOTgxNjAwIiwiaXBhZGRyIjoiMTU0LjE2LjEwNS4zNiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJuYmYiOiIxNzEzOTYwMDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJvSllOM2l0WC8wZUhOaXRDblg4dHh3Iiwic2l0ZWlkIjoiTmpJd1pHWmtPV1V0Wm1OaE1pMDBZelUxTFdJM09XTXROekJqWmpkbVl6Um1aakkwIiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9._VUZxeii-ehvfvEJVWbcas0lwdh2GsuUyhh5iUy9tpw&cTag=%22c%3A%7B1B990252-F860-4D25-B6C9-E091BF0A4258%7D%2C1%22 HTTP/1.1Host: southcentralus1-mediap.svc.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://womenofgoodworks-my.sharepoint.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://womenofgoodworks-my.sharepoint.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /transform/passthrough?provider=spo&inputFormat=pdf&cs=fFNQTw&docid=https%3A%2F%2Fwomenofgoodworks-my.sharepoint.com%3A443%2F_api%2Fv2.0%2Fdrives%2Fb!nv0NYqL8VUy3nHDPf8T_JPcFSytCdeVGuoTJbeLAlGs1UkGYSCz3Q4_6QHS1v96_%2Fitems%2F01BTTHLB2SAKMRWYHYEVG3NSPASG7QUQSY%3Fversion%3DPublished&access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvd29tZW5vZmdvb2R3b3Jrcy1teS5zaGFyZXBvaW50LmNvbUAxYmY5OWFiZS0wOTE5LTRkMWEtYThkMy04ZjExNjNiZjhmZWMiLCJjYWNoZWtleSI6IjBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJlbmRwb2ludHVybCI6IkdFak03TFNWNklvQW9yVEtVQmZpZU1mRzFhdzc5QlQ5dXpvMHJKdmQ4c1U9IiwiZW5kcG9pbnR1cmxMZW5ndGgiOiIxMjYiLCJleHAiOiIxNzEzOTgxNjAwIiwiaXBhZGRyIjoiMTU0LjE2LjEwNS4zNiIsImlzbG9vcGJhY2siOiJUcnVlIiwiaXNzIjoiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwIiwiaXN1c2VyIjoidHJ1ZSIsIm5hbWVpZCI6IjAjLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMiLCJuYmYiOiIxNzEzOTYwMDAwIiwibmlpIjoibWljcm9zb2Z0LnNoYXJlcG9pbnQiLCJzaGFyaW5naWQiOiJvSllOM2l0WC8wZUhOaXRDblg4dHh3Iiwic2l0ZWlkIjoiTmpJd1pHWmtPV1V0Wm1OaE1pMDBZelUxTFdJM09XTXROekJqWmpkbVl6Um1aakkwIiwic25pZCI6IjYiLCJzdHAiOiJ0IiwidHQiOiIwIiwidmVyIjoiaGFzaGVkcHJvb2Z0b2tlbiJ9._VUZxeii-ehvfvEJVWbcas0lwdh2GsuUyhh5iUy9tpw&cTag=%22c%3A%7B1B990252-F860-4D25-B6C9-E091BF0A4258%7D%2C1%22 HTTP/1.1Host: southcentralus1-mediap.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /CZsbl/ HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /turnstile/v0/api.js?render=explicit HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://czsbl.u6t2.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /jquery-3.6.0.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://czsbl.u6t2.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /turnstile/v0/b/471dc2adc340/api.js?render=explicit HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://czsbl.u6t2.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normal HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://czsbl.u6t2.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drive/apps?select=*%2Cpromoted%2CbuiltIn&%24expand=actions HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Accept: application/jsonAccept-Language: en-USsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://womenofgoodworks-my.sharepoint.com/personal/tia_womenofgoodworks_org/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%2FSourdough%20Transfer%2Epdf&parent=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brCookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=27ab627a-db53-4042-baab-67b95b54eaaa; ai_session=+oDpQIVNFi24rkdNZXqPQA|1713968392962|1713968392962; MSFPC=GUID=748cab5aa7614944b3712b039770ea6b&HASH=748c&LV=202404&V=4&LU=1713968397213
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8796bb7b69bd0a01 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normalAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normalAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/CZsbl/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IkN1KzkyL0p3SGtGTjdVNkpXRS9Ga2c9PSIsInZhbHVlIjoiRU5hTHBva0xxNXBkSEowV0VzNE1RalpYN3dPbm5abjRHeHM2NUE4V1lQaUxmS2pDRmtOOTUwVjFYYkM3ZE1Ib2RnNW9rYlIrYzhjdjVPZ3djekV5NkExdG05L2k5OFgzVjZaVTNRdTlMSmlMWjlneTdWNHM2NGRzTkJsZVVyRHUiLCJtYWMiOiJiNDNmZWI0ODEzZTk2YzcwMzYxYWVmODMwYzhjMWQxNmM1MzYxOTA1YjBmZTMwMGY1M2I3NzRjYzJjYjBlYmUwIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IkFpNXpBYzhWZTlRQ1JXRktnSjcyVWc9PSIsInZhbHVlIjoick4yZFZPTXdpbzdFNFB6bEZJdnZYdnJPbEkzQzg2R3hmT3FVd05QMmpyQ0FQRVgrVWNUb2RWVjFmUkJCa3VTcElTS0dtZUl2anhQYURBV25EVUdRYVFJMFE4czVJL0ZROVVvV2lPQ3dwamJTWUNrNTcvSERuWVFiZTNld2g4OFciLCJtYWMiOiJmNTBiNjc4MWUzNGVmYTFlNzE4OGQwYzcxMTM2MDk4MGYyNmQ4NzJkYTk5ZDgxYTYwMGUwYTUxMWNiMzg0NWY4IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/i/8796bb7b69bd0a01/1713968411013/dWW_KoVFGItUc2y HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normalAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1861305697:1713964439:p2TaqAyl3mUXFv1rsjZy1mIotaN0k16YCz0QaxN-SlI/8796bb7b69bd0a01/bad3a93d9126c9a HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/i/8796bb7b69bd0a01/1713968411013/dWW_KoVFGItUc2y HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/pat/8796bb7b69bd0a01/1713968411015/269239a2670575c5c98b25553cf0d185d5306d29edaff774b8c0a780fe3f9019/nTxmas6eZ7vOXlR HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2jplv/0x4AAAAAAAXpm61N4rmLO1YU/auto/normalAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1861305697:1713964439:p2TaqAyl3mUXFv1rsjZy1mIotaN0k16YCz0QaxN-SlI/8796bb7b69bd0a01/bad3a93d9126c9a HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/tia_womenofgoodworks_org/_layouts/15/AccessDenied.aspx?correlation=762a22a1%2D1051%2D5000%2D501a%2D55968b522902 HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=; MicrosoftApplicationsTelemetryDeviceId=27ab627a-db53-4042-baab-67b95b54eaaa; ai_session=+oDpQIVNFi24rkdNZXqPQA|1713968392962|1713968392962; MSFPC=GUID=748cab5aa7614944b3712b039770ea6b&HASH=748c&LV=202404&V=4&LU=1713968397213
Source: global traffic HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/b/flow/ov1/1861305697:1713964439:p2TaqAyl3mUXFv1rsjZy1mIotaN0k16YCz0QaxN-SlI/8796bb7b69bd0a01/bad3a93d9126c9a HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /CZsbl/ HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://czsbl.u6t2.com/CZsbl/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6InNONjBXc2Z4cVNVMVVyNlhESDZxdkE9PSIsInZhbHVlIjoiT2VibmZLRW5vVURmQXMwZFRKQll0TnNMQlhiOVhabUtNUU5sMHRwbGUvT0JiWk5VSnlXd0piZ25DL3I0c1I1QnJIczNnTFl0eGNUOHRUSmViQUYwQ2NCL2tCTkF1enpiYVNYa2grZlF0aWV0aWYreDFCSnBpNXZyd3RIMWVRdFEiLCJtYWMiOiJlYzMyZmVmZjA2MzJiNWUwZDcwZmViODA5YmU1MzcyMjUwYWYyZjkxNmZkNmU4MjJmNjBlZTk0YjFkMTVjYmExIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6ImwvSTRHNmZneisxVm80YVhLcWU5cXc9PSIsInZhbHVlIjoiQ0RKZkw3TFFNc3pUNllqL3VEV2dXTmxuVTk0TjFYcERCRitZSXdZcTQ1TEkydVA0eFlaNlJDazlKQm1CRDZtUVV1UEw0QUN0dXM4QkdEWnE1OGlQYkVIWVI1Wmk2REFnYW9mQU5VZlJ1OVFTQjhFQWRqVzU4NW9QZmdvd2pTay8iLCJtYWMiOiIxYTZhZGEyYzNiZWUwZGVlNGY0NGQ4NTAwMzM0MmY3Y2RlNzgyZWVkMmIyYTM3YmFmY2IzZTdmMjhiMjg5MTM2IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /lnL1ADFrGd59QKm3vzd1YWJag HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6InNONjBXc2Z4cVNVMVVyNlhESDZxdkE9PSIsInZhbHVlIjoiT2VibmZLRW5vVURmQXMwZFRKQll0TnNMQlhiOVhabUtNUU5sMHRwbGUvT0JiWk5VSnlXd0piZ25DL3I0c1I1QnJIczNnTFl0eGNUOHRUSmViQUYwQ2NCL2tCTkF1enpiYVNYa2grZlF0aWV0aWYreDFCSnBpNXZyd3RIMWVRdFEiLCJtYWMiOiJlYzMyZmVmZjA2MzJiNWUwZDcwZmViODA5YmU1MzcyMjUwYWYyZjkxNmZkNmU4MjJmNjBlZTk0YjFkMTVjYmExIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6ImwvSTRHNmZneisxVm80YVhLcWU5cXc9PSIsInZhbHVlIjoiQ0RKZkw3TFFNc3pUNllqL3VEV2dXTmxuVTk0TjFYcERCRitZSXdZcTQ1TEkydVA0eFlaNlJDazlKQm1CRDZtUVV1UEw0QUN0dXM4QkdEWnE1OGlQYkVIWVI1Wmk2REFnYW9mQU5VZlJ1OVFTQjhFQWRqVzU4NW9QZmdvd2pTay8iLCJtYWMiOiIxYTZhZGEyYzNiZWUwZGVlNGY0NGQ4NTAwMzM0MmY3Y2RlNzgyZWVkMmIyYTM3YmFmY2IzZTdmMjhiMjg5MTM2IiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /CZsbl/?X HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://czsbl.u6t2.com/CZsbl/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhpRjF1bVh4eFJoYkJ0UWMxNUxGU0E9PSIsInZhbHVlIjoiYWgwWnpWK0tVZGIzbDNiSzlIN3BJMSs4d0N5dmJSaVgrWk1DTEFxVlF1bHhCVStpM2RodW4ycUxveHZJNzNnZUU2ZW5KcXlTYm9HZlFEV1IyZW51byt4U1ltN2M5K1diTkxMajB4clFWMmdoTmhzaFNBaTRXalArVzBQZXJVWFgiLCJtYWMiOiJiN2NmMWZhNGFhZTc2NDQ0YTUxMGY2MWIwOThlMDdkMTViODNmZWU0NTEwOThjOTg0NTgyNzNiZDk4MjAwNzI3IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IlFCTHpnTFU2MFFOa1R4TFJMczh3Tmc9PSIsInZhbHVlIjoidlNQZ0pLYkwvNFJaRGoxa2VuSm9jR2lIOU1lYUcxSVc4WllnK3hKRzkvd1lDRkZ5b0IzUU1oQkJwSzhKU1NMcXYyM0h1Y2pGQnovR2ZtKzR6K3c3ZzJlYTl1dDFkVTU0dkNpZmtKc0szMk9Lcmh6TktzYWhhSjE2TEZad3ZMMloiLCJtYWMiOiJiNzI1MGRmNTEwNDc0ZjkxZWFlYWY2NmVmNTViM2RlZDhiNGE0NzY3NjFiMzdhYjNkNWMyNTk4ZTk5ZjQ0M2YxIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEV HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://czsbl.u6t2.com/CZsbl/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImNnVkdiWCtJaE9EcTFRZmNDMGhOMVE9PSIsInZhbHVlIjoiV2t1M3UrYWJtN3lZN3dub2FJU3doUk8vMG9jNDFXUWIzbEtSUnFvK1ArLzNFTitHREk2eUV4VURVbFhMOStjMXhmd1V6QUNOczRidWRXc3JxSG5lMGV0c00wMXVwYlZ5TG02cG01bjVoWDNaUFN2N0lMMmZoblRUN0Y4OEVKZWMiLCJtYWMiOiI0MmU1YTk2MWQ1ODY2YTI0MjdjYTk3MTNkNDQ3MWY0YzNjN2E3NTdkNmQzNzNjMmY1MDUzMWFkMjQ2YjhlNGU3IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjJYNE1TN0pKcHhLK052NmRnYVlSaHc9PSIsInZhbHVlIjoiZEhncHJsU0FOTllFNlJtSTFEQzJReFAwcUZadVJ6ekt4QmNWSGsrYkN6TDdIVmdReTJzSXY3N25qckRrWjBFanp4UWhuUVdPdWxoZThBMkRIeDhjQmV4dDJDdHhFQUxwaTlaRjB3L0lkSXRmcDAyeHV3SWs4VU81bHV6WmVxdzIiLCJtYWMiOiI5ZTBhYzAyZDk4NjlmNGU3NzUwYmVhMDVmY2MxN2M0Nzk1OGYzNTE4MTkwNzI2ZDVmM2JiZDM2YjhjYzVhYTNjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /12RJoZAAExsTcduUy0Kk6720 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /xyAOss4rsyXz7ef26 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /12LOaeimzGQ56H5tnqr50 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://czsbl.u6t2.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /rsEDt1HPzKQYVai12u1qTyuv40 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://czsbl.u6t2.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /904LgoJ5KeJufg7677wsuuGst60 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://czsbl.u6t2.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /23z0aXNCIqiZaabg5aUZC2Zxy70 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://czsbl.u6t2.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /recaptcha/api.js HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://czsbl.u6t2.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /4.6.0/socket.io.min.js HTTP/1.1Host: cdn.socket.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://czsbl.u6t2.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /89JT02sgijw3WGpY2McaI12LAbzSFo2HSIab80 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://czsbl.u6t2.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /cd8K2aqTNqPZUAMJ0iwtXbpMi34i1SHHzP0HzZtmn100 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://czsbl.u6t2.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /web8socket/socket.io/?type=User&appnum=1&EIO=4&transport=websocket HTTP/1.1Host: czsbl.u6t2.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://czsbl.u6t2.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3DSec-WebSocket-Key: YwdvLJ26Qnjin28BkL+QbA==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
Source: global traffic HTTP traffic detected: GET /56dUFxlW8wz4or3LUKENImbHbbgha3VIYFgipaaTZ89109 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ijLrbfEQAHoKsinBPBLDTrlp4OfYIsqqrE0lojYxKcHufBn2vXfPqSHRiyz230 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /klc2AiR3fOL4Jcf9iOZHild4BgvaIMs8w2o7x56k9GPr6zyOgeYzyHX8bNSpo1ovFuv220 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /klc2AiR3fOL4Jcf9iOZHild4BgvaIMs8w2o7x56k9GPr6zyOgeYzyHX8bNSpo1ovFuv220 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6ImlZWkNwMk56VUEzbCt5c1Q4bERVa1E9PSIsInZhbHVlIjoiOWtPS3ppc1lNc0dnRTRvU3g2cFp1bk9jMEZ3cFdYSUFQbEhNQWhlc2ZSY1ZLU3VBaCt4VjVoazJMbXRXWVlwQklQb1FRTFduazlYTXZqYzRPUVNlOEFvYzJGWHZnVzlmOWtSUXdxM3hCalI0SWszOXEvMEp0eVd6L3preDh3UDQiLCJtYWMiOiI1YTc0OWJjYmZiM2FjMzEyYTEwNDI2ZTA5YzczZDkwMjY0YWU5NTAzZDc0N2E3MjkyYjhkMjUyZmZiZjFmMDFmIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InZoYjhsR0Y5QkFkQURHSTBjd3JBVHc9PSIsInZhbHVlIjoiUVZNYXpMbzl0TTl4UTk1YVRZdmtKMjVCeVQ2S1YyNnZaeTdBVkhqOWtEZUE1eUNZSXVNbVYyS2txdkxwK3lCZHlOazlxOGV1QW11MlBBRHV2VHlDMm5VTmZwLzZTN0RaQXFvcmZyWXovVnZCa2Z3RVIydFlDWncrRlVJK1lkV2YiLCJtYWMiOiI1ZDg2NzQwY2E4NGM5Yzk4NjI3MjJkM2U2MmQyOTNmZGE0NWEyZmFhNmRkMzI4NzFkZDQ5ZjhiMjRiZmIyNjFjIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /yrzT4p7JydX9Lrsh7oS4jjKiPwg7Dso9oumdbJs0N6aSugb HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ijLrbfEQAHoKsinBPBLDTrlp4OfYIsqqrE0lojYxKcHufBn2vXfPqSHRiyz230 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /wxUx9FixzntxRoj6do4LrjvxopUDSbuB7mRHC512130 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /oppUWYPOd7JPhBLOxzzVmnISiQSlAUKPTIy8i5Hxe45140 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /mnm4vruKHKkEurgQWK6Q7ORzjijNJvLUwxcc86wBJc778141 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ija8xVP4p8GnPOdGWYE2YuCwxU47hTcbu3YmtWAEjxyE9B3459578170 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /yzsTUkiyH423ExrUl2WYHdwhe23ChUTe7um4rsdse9yPbus7f89GyIVTD2VGZab176 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /rstGErhIWGcDgBfrMElaHY97ij3jtjey5A2K2HHvQDyqdYoF76dr4Ivef200 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ghNffVSYhE1jFlvICiW9EtY4y7KxyfxoV6Q9Y3ve0JUJWef210 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /qrFNVVPdJjA2x1NUQEZdV4bAUyhlR456ejKo2oClMHAtaPxbZP12kniSa02OEOVQHMEYqeOytef234 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /wxUx9FixzntxRoj6do4LrjvxopUDSbuB7mRHC512130 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /oppUWYPOd7JPhBLOxzzVmnISiQSlAUKPTIy8i5Hxe45140 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /uv8lFjjRyTPmCckyFue7QDzAI2AlcnVjn4a45utYceDmTvSaYWrXqaEUptpugh252 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://czsbl.u6t2.com/78881468714208173jgCVlmuMXURDZQSODUWSKXWGEOBASWRJAZIYADVKTKWISH?fcqsOKgpcaVhnatDlRIRChEVZhVdHTkGRWLQLRVLVSKBRCKHUARJXWMMMFTFZAUDCBAEVAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /yzsTUkiyH423ExrUl2WYHdwhe23ChUTe7um4rsdse9yPbus7f89GyIVTD2VGZab176 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ija8xVP4p8GnPOdGWYE2YuCwxU47hTcbu3YmtWAEjxyE9B3459578170 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /mnm4vruKHKkEurgQWK6Q7ORzjijNJvLUwxcc86wBJc778141 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /rstGErhIWGcDgBfrMElaHY97ij3jtjey5A2K2HHvQDyqdYoF76dr4Ivef200 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /qrFNVVPdJjA2x1NUQEZdV4bAUyhlR456ejKo2oClMHAtaPxbZP12kniSa02OEOVQHMEYqeOytef234 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /ghNffVSYhE1jFlvICiW9EtY4y7KxyfxoV6Q9Y3ve0JUJWef210 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /uv8lFjjRyTPmCckyFue7QDzAI2AlcnVjn4a45utYceDmTvSaYWrXqaEUptpugh252 HTTP/1.1Host: czsbl.u6t2.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3D
Source: global traffic HTTP traffic detected: GET /web8socket/socket.io/?type=User&appnum=1&EIO=4&transport=websocket HTTP/1.1Host: czsbl.u6t2.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://czsbl.u6t2.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3DSec-WebSocket-Key: ReDK+qHQrIvwwdAEnVvk1Q==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
Source: global traffic HTTP traffic detected: GET /web8socket/socket.io/?type=User&appnum=1&EIO=4&transport=websocket HTTP/1.1Host: czsbl.u6t2.comConnection: UpgradePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Upgrade: websocketOrigin: https://czsbl.u6t2.comSec-WebSocket-Version: 13Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlhURFBuMHRmQklLSWM1anJnOVpQOHc9PSIsInZhbHVlIjoiNUFTV3VvcHVudFkvQ2orV3lKc2M0Nmh3NFJ6WlNCdVpmbGxsSW9ObDNSd01Jd1JpZVVDUmRhMnFCSjkyUGIvZCt6QTFLTzdDYS9NVm5lc01qeVNUQ3g5S01IU0R1LzRJakJZTHY1YStwTEJvSjNxUjNOTkY1YWltVjdkU2xOaUQiLCJtYWMiOiJiMDhlOTM4YTFjOTlmOWFiOTRjMTM2YzNjNWNjMmY0MmY1ZWE0ZGZhZmEzNWRiYmYxMzMxOTNlNGUxNDk4Mjg1IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IjlPaG9Fb2taRjE3NUR3cmV0T2pocWc9PSIsInZhbHVlIjoiMXBmQ0VSYlN3Q0FxTVRtUStLNUI3WHlMVjBGRHQ1R21WbVhTSE5ic0lpbytJcWZXUnlEanNRT0dYbDFUbkhTU1IrcjgzSElmVFdGWTVaQUdzNEFFNXQ3Q0ZtSHRYSlQ0ZUlvSFVsU1RmK3BHaW9hOFVaQ2JBTTA5cG4zanBXWEwiLCJtYWMiOiI2ZjE2MjYxN2Q2MDZhNTc5NmYyYzkzZGM0YTIzYTZlZGM3NTU3ZTdhYjMwZjM1YzRkYmJlMjUzZmZkN2EwOWFiIiwidGFnIjoiIn0%3DSec-WebSocket-Key: nwi6qYBKY7PkAFINlGTuAw==Sec-WebSocket-Extensions: permessage-deflate; client_max_window_bits
Source: global traffic HTTP traffic detected: GET /:b:/g/personal/tia_womenofgoodworks_org/EVICmRtg-CVNtsngkb8KQlgBH2LYVfumjH5s-SFbeQjN_Q HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: womenofgoodworks-my.sharepoint.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: spo.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: southcentralus1-mediap.svc.ms
Source: global traffic DNS traffic detected: DNS query: czsbl.u6t2.com
Source: global traffic DNS traffic detected: DNS query: code.jquery.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: cdn.socket.io
Source: unknown HTTP traffic detected: POST /personal/tia_womenofgoodworks_org/_api/v2.1/graphql HTTP/1.1Host: womenofgoodworks-my.sharepoint.comConnection: keep-aliveContent-Length: 507sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"accept: application/json;odata=verboseContent-Type: application/json;odata=verboseX-ServiceWorker-Strategy: CacheFirstsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Origin: https://womenofgoodworks-my.sharepoint.comSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://womenofgoodworks-my.sharepoint.com/personal/tia_womenofgoodworks_org/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments%2FSourdough%20Transfer%2Epdf&parent=%2Fpersonal%2Ftia%5Fwomenofgoodworks%5Forg%2FDocuments&ga=1Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: FedAuth=77u/PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz48U1A+VjEzLDBoLmZ8bWVtYmVyc2hpcHx1cm4lM2FzcG8lM2Fhbm9uIzU3OGMwMjcwMTMzMTg2NjI5MjVkMmExZTYyMjcxZGI0NTcyNzMxYTEzYTNmMzQyN2FiZGMxZTIzOWE1YjIzYWMsMCMuZnxtZW1iZXJzaGlwfHVybiUzYXNwbyUzYWFub24jNTc4YzAyNzAxMzMxODY2MjkyNWQyYTFlNjIyNzFkYjQ1NzI3MzFhMTNhM2YzNDI3YWJkYzFlMjM5YTViMjNhYywxMzM1ODQ0MjI0MTAwMDAwMDAsMCwxMzM1ODUyODM0MTQ5OTM2ODQsMC4wLjAuMCwyNTgsMWJmOTlhYmUtMDkxOS00ZDFhLWE4ZDMtOGYxMTYzYmY4ZmVjLCwsNjMyYTIyYTEtZTA5Ni01MDAwLTUwMWEtNTkzZjc1NDZiM2M3LDYzMmEyMmExLWUwOTYtNTAwMC01MDFhLTU5M2Y3NTQ2YjNjNyxvSllOM2l0WC8wZUhOaXRDblg4dHh3LDAsMCwwLCwsLDI2NTA0Njc3NDM5OTk5OTk5OTksMCwsLCwsLCwwLCwxOTM3ODMsRGFEQWZqUVFtcHlPWHgyUnJLX1c1bHZvTFo0LFFmRXdTZjMwWTVVNXRqQzk5NmJCQ3o0NGU4OThlSCtYdjVHZVFQTkVONmdJcjJvM0NRS2hFaUNpYmhyc1Z2blhKdERCcGdvd3I3cTdDajRHT2piY0xFNkdzUTFSanZNazdabFI2TWdjV1o3M1oxcUV4K2ljS2gyWWIyWTZaajBJa1gvcW5UampPaUF4cDIreWZ4aitsVG40Ty9RZ1prSlNPT1dPWXEvNC94dUFSekZnY0xaOGNpMUFwQ2ZKQWQwV0hicWpKcTlmbkVCTEI2VDVIdzV5NEJQcmpHdEUzRzNTREpuMnNjelVLRVFwaWhvVGEvNllxczhYbVphNUluOVordzRJelNyVVpKcUF5cVBEL1JwQ1JFMWhHM1VPUzBjRUc5ZmUyM3NJNGdQY1Jiby9FSlovV25DUkhPS3M3RnprSjlCRGhmOWorUlpkWWdPWkFKSHlWZz09PC9TUD4=
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 24 Apr 2024 14:20:10 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeCache-Control: max-age=14400Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TfKDdqtR%2FWRiYgagaQt%2B5leDrroE6FfSSe0BTHUG1E9LY0s%2BTcNNfTIfLo1G3D94fAdgpmWXcCdAWckoQaAAcGhzB%2FfavORS%2FPFBtSowKcIoEFPLoBIgIRc7Xz%2FeXw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Vary: Accept-Encodingalt-svc: h3=":443"; ma=86400CF-Cache-Status: EXPIREDServer: cloudflareCF-RAY: 8796bb8559902939-LAX
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 24 Apr 2024 14:20:27 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=0Tl%2Fx2HrCvW7mBQWogs5Yqh3OWUb6g1DJPglVxmHd2AcaiwhMuBkRp6ynjutsAnTUQeX760OkwZKMf85GkPrTkpiFons5jyIOdJt3x9rm0n9ApLtKk%2F6Fi8%2BABEN1g%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}alt-svc: h3=":443"; ma=86400Server: cloudflareCF-RAY: 8796bbed9c7c2f1d-LAX
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 24 Apr 2024 14:20:34 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XfgKdC93%2FZCOJy8ohLYNGjwh2orbejMeiHbE1vpY0GhJXcC1XrViRtr2TI9fxjJ63im7czYjKDtA%2BtW8XgnXyWAdre%2BO6hSsKF%2BIHorFLDFhjnqyLDhyPOznmH5IuA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}alt-svc: h3=":443"; ma=86400Server: cloudflareCF-RAY: 8796bc1a5a882f6b-LAX
Source: chromecache_710.2.dr, chromecache_347.2.dr String found in binary or memory: http://scripts.sil.org/OFLThis
Source: chromecache_586.2.dr, chromecache_510.2.dr, chromecache_354.2.dr, chromecache_751.2.dr, chromecache_654.2.dr, chromecache_640.2.dr, chromecache_388.2.dr, chromecache_760.2.dr String found in binary or memory: http://www.contoso.com
Source: chromecache_413.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php
Source: chromecache_575.2.dr, chromecache_544.2.dr String found in binary or memory: https://1drv.com/
Source: chromecache_597.2.dr, chromecache_608.2.dr, chromecache_765.2.dr, chromecache_416.2.dr String found in binary or memory: https://200.hc.com/the-harpercollins-200/moby-dick/
Source: chromecache_575.2.dr, chromecache_544.2.dr String found in binary or memory: https://centralus1-mediad.svc.ms
Source: chromecache_399.2.dr String found in binary or memory: https://cloud.google.com/contact
Source: chromecache_399.2.dr String found in binary or memory: https://cloud.google.com/recaptcha-enterprise/billing-information
Source: chromecache_387.2.dr String found in binary or memory: https://czsbl.u6t2.com/CZsbl/)
Source: chromecache_399.2.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
Source: chromecache_399.2.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#localhost_support
Source: chromecache_399.2.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
Source: chromecache_766.2.dr, chromecache_725.2.dr String found in binary or memory: https://facebook.github.io/react/docs/more-about-refs.html#the-ref-callback-attribute
Source: chromecache_474.2.dr String found in binary or memory: https://lists.live.com/
Source: chromecache_575.2.dr, chromecache_544.2.dr String found in binary or memory: https://livefilestore.com/
Source: chromecache_625.2.dr String found in binary or memory: https://login.windows.net
Source: chromecache_575.2.dr, chromecache_544.2.dr String found in binary or memory: https://media.cloudapp.net
Source: chromecache_575.2.dr, chromecache_544.2.dr String found in binary or memory: https://northcentralus1-medias.svc.ms
Source: chromecache_502.2.dr String found in binary or memory: https://odspwebdevdeploy.blob.core.windows.net
Source: chromecache_502.2.dr String found in binary or memory: https://onedrive.live.com/?gologin=1
Source: chromecache_631.2.dr, chromecache_362.2.dr, chromecache_564.2.dr String found in binary or memory: https://outlook.office.com/search
Source: chromecache_399.2.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: chromecache_705.2.dr, chromecache_362.2.dr, chromecache_544.2.dr, chromecache_564.2.dr, chromecache_422.2.dr, chromecache_546.2.dr String found in binary or memory: https://portal.office.com/
Source: chromecache_380.2.dr String found in binary or memory: https://reactjs.org/link/react-polyfills
Source: chromecache_399.2.dr String found in binary or memory: https://recaptcha.net
Source: chromecache_721.2.dr, chromecache_625.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/fabric-cdn-prod_20230815.002/assets
Source: chromecache_384.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-12.003/
Source: chromecache_384.2.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2024-04-12.003/spwebworker.js
Source: chromecache_502.2.dr String found in binary or memory: https://res.cdn.office.net/teams-js/2.0.0/js/MicrosoftTeams.min.js
Source: chromecache_502.2.dr String found in binary or memory: https://securebroker.sharepointonline.com
Source: chromecache_705.2.dr, chromecache_575.2.dr String found in binary or memory: https://shellppe.msocdn.com
Source: chromecache_705.2.dr, chromecache_575.2.dr String found in binary or memory: https://shellprod.msocdn.com
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-bold.w
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-regula
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-semili
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semilight.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-regular.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semibold.wof
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semilight.wo
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-bold.wof
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-light.wo
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-regular.
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semibold
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semiligh
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semilight.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff2
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-light.woff
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-regular.wo
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semibold.w
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semilight.
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-bold.wof
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-light.wo
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-regular.
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semibold
Source: chromecache_533.2.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semiligh
Source: chromecache_592.2.dr String found in binary or memory: https://substrate.office.com
Source: chromecache_399.2.dr String found in binary or memory: https://support.google.com/recaptcha
Source: chromecache_399.2.dr String found in binary or memory: https://support.google.com/recaptcha#6262736
Source: chromecache_399.2.dr String found in binary or memory: https://support.google.com/recaptcha/#6175971
Source: chromecache_399.2.dr String found in binary or memory: https://support.google.com/recaptcha/?hl=en#6223828
Source: chromecache_435.2.dr String found in binary or memory: https://support.office.com/en-us/article/Manage-lists-and-libraries-with-many-items-b8588dae-9387-48
Source: chromecache_399.2.dr String found in binary or memory: https://www.apache.org/licenses/
Source: chromecache_595.2.dr, chromecache_399.2.dr String found in binary or memory: https://www.google.com/recaptcha/api2/
Source: chromecache_399.2.dr String found in binary or memory: https://www.gstatic.c..?/recaptcha/releases/QoukH5jSO3sKFzVEA7Vc8VgC/recaptcha__.
Source: chromecache_595.2.dr String found in binary or memory: https://www.gstatic.com/recaptcha/releases/QoukH5jSO3sKFzVEA7Vc8VgC/recaptcha__en.js
Source: chromecache_597.2.dr, chromecache_608.2.dr, chromecache_765.2.dr, chromecache_416.2.dr String found in binary or memory: https://www.littlebrown.com/titles/j-d-salinger/the-catcher-in-the-rye/9780316769488/
Source: chromecache_502.2.dr String found in binary or memory: https://www.office.com/login?prompt=select_account&ru=%2Flaunch%2F$
Source: chromecache_502.2.dr String found in binary or memory: https://www.office.com/login?ru=%2Flaunch%2F$
Source: chromecache_597.2.dr, chromecache_608.2.dr, chromecache_765.2.dr, chromecache_416.2.dr String found in binary or memory: https://www.peachpit.com/store/dont-make-me-think-revisited-a-common-sense-approach-9780321965516
Source: chromecache_597.2.dr, chromecache_608.2.dr, chromecache_765.2.dr, chromecache_416.2.dr String found in binary or memory: https://www.penguinrandomhouse.com/books/196330/great-tales-and-poems-of-edgar-allan-poe-by-edgar-al
Source: chromecache_765.2.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Great-Gatsby/F-Scott-Fitzgerald/9781982146702#:~007E;007E
Source: chromecache_608.2.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Great-Gatsby/F-Scott-Fitzgerald/9781982146702#:~007E;:tex
Source: chromecache_597.2.dr, chromecache_416.2.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Great-Gatsby/F-Scott-Fitzgerald/9781982146702#:~:text=The
Source: chromecache_597.2.dr, chromecache_765.2.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Sun-Also-Rises/Ernest-Hemingway/9781982199524#:~007E;007E
Source: chromecache_608.2.dr, chromecache_416.2.dr String found in binary or memory: https://www.simonandschuster.com/books/The-Sun-Also-Rises/Ernest-Hemingway/9781982199524#:~:text=The
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50216
Source: unknown Network traffic detected: HTTP traffic on port 50168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50218
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50217
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50219
Source: unknown Network traffic detected: HTTP traffic on port 50139 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50056
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50057
Source: unknown Network traffic detected: HTTP traffic on port 50202 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50211
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50214
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50213
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50071 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50182
Source: unknown Network traffic detected: HTTP traffic on port 50211 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50234 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50106
Source: unknown Network traffic detected: HTTP traffic on port 50194 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50085 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50229
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50228
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50100
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50221
Source: unknown Network traffic detected: HTTP traffic on port 50056 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50220
Source: unknown Network traffic detected: HTTP traffic on port 50243 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50104
Source: unknown Network traffic detected: HTTP traffic on port 50205 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50240 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50216 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50070
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50191
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50190
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50193
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50071
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50192
Source: unknown Network traffic detected: HTTP traffic on port 50162 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50195
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50194
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50197 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 49790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50117
Source: unknown Network traffic detected: HTTP traffic on port 50204 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50040 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50172 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50197
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50230
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50075
Source: unknown Network traffic detected: HTTP traffic on port 50057 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50232
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50198
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50231
Source: unknown Network traffic detected: HTTP traffic on port 50246 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50234
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50112
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50233
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50236
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50235
Source: unknown Network traffic detected: HTTP traffic on port 50099 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50081
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50083
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50082
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50085
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 50198 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 50100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50213 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50232 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49953
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50129
Source: unknown Network traffic detected: HTTP traffic on port 49927 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50192 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50241
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49790
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50240
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50089
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50243
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50207 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50246
Source: unknown Network traffic detected: HTTP traffic on port 50241 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50092
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50095
Source: unknown Network traffic detected: HTTP traffic on port 50235 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49948
Source: unknown Network traffic detected: HTTP traffic on port 50082 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 50218 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50139
Source: unknown Network traffic detected: HTTP traffic on port 50170 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50193 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49940
Source: unknown Network traffic detected: HTTP traffic on port 50229 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50099
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50132
Source: unknown Network traffic detected: HTTP traffic on port 50112 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50221 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50206 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50075 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50158 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50106 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50129 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50140
Source: unknown Network traffic detected: HTTP traffic on port 50081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50230 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50169 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 50117 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 49919 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50190 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770
Source: unknown Network traffic detected: HTTP traffic on port 50070 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50264
Source: unknown Network traffic detected: HTTP traffic on port 50095 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50201 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50264 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49927
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 50233 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50191 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49953 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50158
Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50182 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50217 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49940 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49919
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50162
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50040
Source: unknown Network traffic detected: HTTP traffic on port 50163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50236 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50140 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50089 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50083 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49948 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50205
Source: unknown Network traffic detected: HTTP traffic on port 50228 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50203 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50204
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50207
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50206
Source: unknown Network traffic detected: HTTP traffic on port 50171 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50163
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50168
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50201
Source: unknown Network traffic detected: HTTP traffic on port 50220 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50203
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50169
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50202
Source: unknown Network traffic detected: HTTP traffic on port 50132 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50171
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50170
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50172
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50214 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50231 -> 443
Source: unknown HTTPS traffic detected: 23.61.210.98:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.61.210.98:443 -> 192.168.2.5:49725 version: TLS 1.2
Source: classification engine Classification label: mal56.phis.win@20/887@40/14
Source: chromecache_387.2.dr Initial sample: https://czsbl.u6t2.com/czsbl/
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=2032,i,13255375107478904871,18216689530066848237,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://womenofgoodworks-my.sharepoint.com/:b:/g/personal/tia_womenofgoodworks_org/EVICmRtg-CVNtsngkb8KQlgBH2LYVfumjH5s-SFbeQjN_Q"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=2032,i,13255375107478904871,18216689530066848237,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 554 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 387
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 387 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: chromecache_696.2.dr Binary or memory string: ",ConnectVirtualMachine:"
Source: chromecache_696.2.dr Binary or memory string: ",DisconnectVirtualMachine:"
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs