Source: | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The legitimate domain for Microsoft is ''., The provided URL '' does not match the legitimate domain., The URL contains suspicious elements such as an unusual domain extension '.store' and unrelated words 'ptyquabrig' and 'betusisave'., The URL does not have any recognizable association with Microsoft., The presence of input fields for 'Email or phone' is common in phishing attempts targeting Microsoft accounts. DOM: 1.1.pages.csv |
Source: | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The URL '' does not match the legitimate domain ''., The domain '' is suspicious and not associated with Microsoft., The use of a random subdomain 'ptyquabrig' and an unusual domain extension '.store' are common phishing tactics., The email-like input field '' suggests a potential attempt to harvest credentials. DOM: 1.2.pages.csv |
Source: Yara match | File source:, type: HTML |
Source: Yara match | File source: 1.2..script.csv, type: HTML |
Source: Yara match | File source: 1.1.pages.csv, type: HTML |
Source: Yara match | File source: 1.2.pages.csv, type: HTML |
Source: Yara match | File source: 1.3.pages.csv, type: HTML |
Source: Yara match | File source: 1.0.pages.csv, type: HTML |
Source: | HTTP Parser: Invalid link: Terms of use |
Source: | HTTP Parser: Invalid link: Privacy & cookies |
Source: | HTTP Parser: Invalid link: Terms of use |
Source: | HTTP Parser: Invalid link: Privacy & cookies |
Source: | HTTP Parser: Invalid link: Terms of use |
Source: | HTTP Parser: Invalid link: Privacy & cookies |
Source: | HTTP Parser: Invalid link: Terms of use |
Source: | HTTP Parser: Invalid link: Privacy & cookies |
Source: | HTTP Parser: No <meta name="author".. found |
Source: | HTTP Parser: No <meta name="author".. found |
Source: | HTTP Parser: No <meta name="author".. found |
Source: | HTTP Parser: No <meta name="author".. found |
Source: | HTTP Parser: No <meta name="copyright".. found |
Source: | HTTP Parser: No <meta name="copyright".. found |
Source: | HTTP Parser: No <meta name="copyright".. found |
Source: | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | TCP traffic detected without corresponding DNS query: |
Source: unknown | TCP traffic detected without corresponding DNS query: |
Source: unknown | TCP traffic detected without corresponding DNS query: |
Source: unknown | TCP traffic detected without corresponding DNS query: |
Source: unknown | TCP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: unknown | UDP traffic detected without corresponding DNS query: |
Source: global traffic | HTTP traffic detected: GET /?email= HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /m/2b643487bbc7982ff271dda0c2c54c3b.htm HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/cxx/0HPYYKDVVKG4785FFJ5S1FIHZ HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/sm/G0UIGY28ZRM8SRS32KDFLYQHX HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/jx/CLTQYS7CTTF8W10B5MVWYWUB6 HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/mxl/mlg.svg?LGUCMIMV4B304VZH4QFEBU6IX HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/aty/FQ1T8UF43MSIZWSAU8MEXRL9J HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/mxl/sig_op.svg HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/ecpt/CRS543O1KSR7OFOSEPYRIQWG9 HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/bxg/9UACUTQO4MZ67R5JUO9IKYTL9 HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/jx/CLTQYS7CTTF8W10B5MVWYWUB6 HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/mxl/mlg.svg?LGUCMIMV4B304VZH4QFEBU6IX HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /?format=json HTTP/1.1Host: api.ipify.orgConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Accept: application/json, text/javascript, */*; q=0.01sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Origin: https://ptyquabrig.betusisave.storeSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /m/aty/FQ1T8UF43MSIZWSAU8MEXRL9J HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/mxl/sig_op.svg HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /?format=json HTTP/1.1Host: api.ipify.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /m/ecpt/CRS543O1KSR7OFOSEPYRIQWG9 HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/ic/4FX3FOEDO94SDQKL6Y781IMMK HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/script.php HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/ic/4FX3FOEDO94SDQKL6Y781IMMK HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/script.php HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/script.php HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/script.php HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: global traffic | HTTP traffic detected: GET /m/script.php HTTP/1.1Host: ptyquabrig.betusisave.storeConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=6fbc7fcaf203f0b9b388dc5996f3c23e; rt=2b643487bbc7982ff271dda0c2c54c3b.htm |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49744 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49742 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49741 |
Source: unknown | Network traffic detected: HTTP traffic on port 49779 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49781 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49780 |
Source: unknown | Network traffic detected: HTTP traffic on port 49836 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49746 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49781 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49776 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49739 |
Source: unknown | Network traffic detected: HTTP traffic on port 49759 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49753 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49779 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49778 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49777 |
Source: unknown | Network traffic detected: HTTP traffic on port 49675 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49776 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49775 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49774 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49771 |
Source: unknown | Network traffic detected: HTTP traffic on port 49742 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49767 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49749 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49780 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49752 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49777 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49767 |
Source: unknown | Network traffic detected: HTTP traffic on port 49756 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49739 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49758 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49761 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49760 |
Source: unknown | Network traffic detected: HTTP traffic on port 49741 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49748 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49760 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49745 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49751 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49759 |
Source: unknown | Network traffic detected: HTTP traffic on port 49778 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49836 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49758 |
Source: unknown | Network traffic detected: HTTP traffic on port 49774 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49755 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49756 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49755 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49754 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49753 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49752 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49751 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49750 |
Source: unknown | Network traffic detected: HTTP traffic on port 49761 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49747 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49744 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49775 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49750 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49749 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49748 |
Source: unknown | Network traffic detected: HTTP traffic on port 49754 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49747 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49746 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49745 |
Source: unknown | Network traffic detected: HTTP traffic on port 49771 -> 443 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2008,i,1092090699780099162,600696839747166947,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2008,i,1092090699780099162,600696839747166947,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |