Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'., The URL 'login.loraintoolsltd.xyz' does not match the legitimate domain for Microsoft., The domain 'loraintoolsltd.xyz' is not associated with Microsoft and appears unrelated., The use of a generic domain extension '.xyz' and an unrelated domain name is suspicious., The presence of 'login' in the subdomain could be an attempt to mimic a legitimate login page, which is a common phishing tactic. DOM: 4.5.pages.csv |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | Joe Sandbox AI: Score: 9 Reasons: The brand 'Bell Potter' is a known financial services company in Australia., The legitimate domain for Bell Potter is 'bellpotter.com.au'., The provided URL 'login.loraintoolsltd.xyz' does not match the legitimate domain., The domain 'loraintoolsltd.xyz' is unrelated to Bell Potter and uses an unusual domain extension '.xyz'., The presence of a login page with a password field on an unrelated domain is suspicious. DOM: 4.6.pages.csv |
Source: https://login.loraintoolsltd.xyz/common/login | Joe Sandbox AI: Score: 9 Reasons: The brand 'Bell Potter' is a known financial services company in Australia., The legitimate domain for Bell Potter is 'bellpotter.com.au'., The URL 'login.loraintoolsltd.xyz' does not match the legitimate domain of Bell Potter., The domain 'loraintoolsltd.xyz' is unrelated to Bell Potter and uses an unusual domain extension '.xyz', which is often used in phishing., The presence of a login page with a password field on an unrelated domain is suspicious. DOM: 5.7.pages.csv |
Source: Yara match | File source: 1.4.id.script.csv, type: HTML |
Source: Yara match | File source: 1.17.i.script.csv, type: HTML |
Source: Yara match | File source: 1.32.i.script.csv, type: HTML |
Source: Yara match | File source: 1.26.id.script.csv, type: HTML |
Source: Yara match | File source: 3.3.pages.csv, type: HTML |
Source: Yara match | File source: 4.4.pages.csv, type: HTML |
Source: Yara match | File source: 4.5.pages.csv, type: HTML |
Source: Yara match | File source: 4.6.pages.csv, type: HTML |
Source: Yara match | File source: 5.7.pages.csv, type: HTML |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0#jrofe@bellpotter.com.au | HTTP Parser: Number of links: 0 |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: Number of links: 0 |
Source: https://login.loraintoolsltd.xyz/common/login | HTTP Parser: Number of links: 1 |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0#jrofe@bellpotter.com.au | HTTP Parser: Title: Redirecting does not match URL |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://login.loraintoolsltd.xyz/common/login | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0#jrofe@bellpotter.com.au | HTTP Parser: No <meta name="author".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: No <meta name="author".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: No <meta name="author".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: No <meta name="author".. found |
Source: https://login.loraintoolsltd.xyz/common/login | HTTP Parser: No <meta name="author".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0#jrofe@bellpotter.com.au | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true#jrofe@bellpotter.com.au= | HTTP Parser: No <meta name="copyright".. found |
Source: https://login.loraintoolsltd.xyz/common/login | HTTP Parser: No <meta name="copyright".. found |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: login.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: login.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: www.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: www.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: live.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: live.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: login.loraintoolsltd.xyz |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | DNS query: login.loraintoolsltd.xyz |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /FgJIoRDm HTTP/1.1Host: login.loraintoolsltd.xyzConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: http://sahadayiz.com.tr/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/font-awesome/5.15.4/css/all.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://login.loraintoolsltd.xyz/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/api.js?onload=onloadTurnstileCallback HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.loraintoolsltd.xyz/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/g/672eb098a9f3/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.loraintoolsltd.xyz/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/fjr99/0x4AAAAAAA5pnBhoTgM91kpZ/auto/fbE/new/normal/auto/ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: iframeReferer: https://login.loraintoolsltd.xyz/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/g/672eb098a9f3/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=905d758c9c7f5e68&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/fjr99/0x4AAAAAAA5pnBhoTgM91kpZ/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/fjr99/0x4AAAAAAA5pnBhoTgM91kpZ/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: login.loraintoolsltd.xyzConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.loraintoolsltd.xyz/FgJIoRDmAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: b747-6a6f=475d0ffaef1bfbf6f1719ce11f86d39c4c8d769b461d7af3b038c27176b36278 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=905d758c9c7f5e68&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/431424420:1737523604:zQsNKK_EULmLK6t-Izi3ZT6_56oVUwerMj_ulv66oTg/905d758c9c7f5e68/xZy1J9QD_T__5I8odcDMzLJ0YRHiFDf_j_vkwqg7yz8-1737527047-1.1.1.1-hkYFqkAksropzwGMvswgkxmoSZn3vG.4JsNtaGh_XjxdJsgj9xNxQOaIcEobJFoI HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/d/905d758c9c7f5e68/1737527048859/h0R7LETiUR5EdkQ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/fjr99/0x4AAAAAAA5pnBhoTgM91kpZ/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/d/905d758c9c7f5e68/1737527048859/h0R7LETiUR5EdkQ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/pat/905d758c9c7f5e68/1737527048862/192915dd2a27315a544581a44a57df06334e835618996b50b5008f69205041ef/1C3Bys2O25GcXgM HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/fjr99/0x4AAAAAAA5pnBhoTgM91kpZ/auto/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/431424420:1737523604:zQsNKK_EULmLK6t-Izi3ZT6_56oVUwerMj_ulv66oTg/905d758c9c7f5e68/xZy1J9QD_T__5I8odcDMzLJ0YRHiFDf_j_vkwqg7yz8-1737527047-1.1.1.1-hkYFqkAksropzwGMvswgkxmoSZn3vG.4JsNtaGh_XjxdJsgj9xNxQOaIcEobJFoI HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/431424420:1737523604:zQsNKK_EULmLK6t-Izi3ZT6_56oVUwerMj_ulv66oTg/905d758c9c7f5e68/xZy1J9QD_T__5I8odcDMzLJ0YRHiFDf_j_vkwqg7yz8-1737527047-1.1.1.1-hkYFqkAksropzwGMvswgkxmoSZn3vG.4JsNtaGh_XjxdJsgj9xNxQOaIcEobJFoI HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /FgJIoRDm?o=pHg-Y4s HTTP/1.1Host: login.loraintoolsltd.xyzConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://login.loraintoolsltd.xyz/FgJIoRDmAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: b747-6a6f=475d0ffaef1bfbf6f1719ce11f86d39c4c8d769b461d7af3b038c27176b36278; x-ms-gateway-slice=estsfd |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Host: login.loraintoolsltd.xyzConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://login.loraintoolsltd.xyz/FgJIoRDmAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: b747-6a6f=475d0ffaef1bfbf6f1719ce11f86d39c4c8d769b461d7af3b038c27176b36278; x-ms-gateway-slice=estsfd |
Source: global traffic | HTTP traffic detected: GET /login HTTP/1.1Host: www.loraintoolsltd.xyzConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://login.loraintoolsltd.xyz/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: b747-6a6f=475d0ffaef1bfbf6f1719ce11f86d39c4c8d769b461d7af3b038c27176b36278 |
Source: global traffic | HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0 HTTP/1.1Host: login.loraintoolsltd.xyzConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://login.loraintoolsltd.xyz/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: b747-6a6f=475d0ffaef1bfbf6f1719ce11f86d39c4c8d769b461d7af3b038c27176b36278; x-ms-gateway-slice=estsfd; fpc=Al80S6UF-GNCmXSXQ1iGIMk; esctx=PAQABBwEAAABVrSpeuWamRam2jAF1XRQE-GZHmj-tS1JVm08kYhWca3pqgpHHkhFLR3ThjcD0DV0bSTyB19sec-iwddoTj8wsfHI0RVGAqvJ07qnFKmN53LqA_h6BMy7rt2RJuA9NHycG6SPzvwSgzTN8U_nx98Azc_RNZrdqWDY-ZUG-ZPBkMZ47KJPi8A9gU85rP_SugMAgAA; stsservicecookie=estsfd |
Source: global traffic | HTTP traffic detected: GET /common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=true HTTP/1.1Host: login.loraintoolsltd.xyzConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://login.loraintoolsltd.xyz/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638731238681787570.ODhhMjJmMDEtMGJkYi00Yjg3LWIwYzgtNjllZDFmZDZmY2EzNmFjNmExMWEtMzQzMi00YjNlLWEwNDItYWY4YzE4MmQzYTNh&ui_locales=en-US&mkt=en-US&client-request-id=cb1aab6e-d738-4b4a-ab4d-587742f5ae39&state=s95EoQB_AA265hU6LuUZwGO4l2xEUUXo0aL2Xd5yZK81ulpwoCuW4IfBjUJIeqNg8gQVwSymcBUGzHgwyvforyBXSwUlGtuKaxlyXt4HgJ1Dm5AuddfarFErPWQkz8tYxHkYQniDGyNSiKaw9fWVkS9ePdK1xSQkW1FYyT5ABBp8UTcFSD9urgbc5yA_Ddi1ODHmrMQqEOH1pnXH15_nbJETgs1F44qZ6Tlhg7T27fXVEIMYt3_dZgXQ9Fq2K_yPypROAEVAy20TMzkSCMbQgg&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: b747-6a6f=475d0ffaef1bfbf6f1719ce11f86d39c4c8d769b461d7af3b038c27176b36278; x-ms-gateway-slice=estsfd; fpc=Al80S6UF-GNCmXSXQ1iGIMk; esctx=PAQABBwEAAABVrSpeuWamRam2jAF1XRQE-GZHmj-tS1JVm08kYhWca3pqg |