Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcon

Overview

General Information

Sample URL:https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&ln
Analysis ID:1635971
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

AI detected landing page (webpage, office document or email)
AI detected suspicious Javascript
Creates files inside the system directory
Deletes files inside the Windows folder
Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code
Suricata IDS alerts with low severity for network traffic
URL contains potential PII (phishing indication)

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5580 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 4912 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1904,i,12928209957432010173,5565500243814302611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2192 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6712 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --no-pre-read-main-dll --field-trial-handle=1904,i,12928209957432010173,5565500243814302611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=4196 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6608 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcon" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-12T09:14:21.695114+010028032742Potentially Bad Traffic192.168.2.1649692104.26.12.205443TCP

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconJoe Sandbox AI: Page contains button: 'Request review' Source: '1.6.pages.csv'
Source: 0.5..script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: blob:https://businessaccounts-suite.com/5905b557-1... This script demonstrates high-risk behavior by using the `eval()` function to execute dynamic code received from an untrusted source. The use of `eval()` allows for the execution of arbitrary JavaScript, which poses a significant security risk. Additionally, the lack of origin verification and the absence of a message source indicate that this script is vulnerable to cross-origin attacks and could be used to execute malicious code on the client-side.
Source: 0.64.d.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: ... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code. The script uses techniques like `eval`, `Function` constructor, and string manipulation to execute remote or dynamic code, which poses a significant security risk. Additionally, the script collects user data and sends it to an external server, potentially exposing sensitive information. The heavy obfuscation of the code further increases the suspicion of malicious intent. Overall, this script demonstrates a high level of risk and should be treated with caution.
Source: https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" fill="none"><path fill="#B20F03" d="M16 3a13 13 0 1 0 13 13A13.015 13.015 0 0 0 16 3m0 24a11 11 0 1 1 11-11 11.01 11.01 0 0 1-11 11"/><path fill="#B20F03" d="M17.038 18.615H14.87L14.563 9.5h2....
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconSample URL: PII: m.alarcon@servihabitat.com&fname
Source: https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: https://businessaccounts-suite.com/?user_email=m.alarcon%40servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: https://businessaccounts-suite.com/?user_email=m.alarcon%40servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: https://businessaccounts-suite.com/?user_email=m.alarcon%40servihabitat.com&fname=Mireia&lname=AlarconHTTP Parser: No favicon
Source: chrome.exeMemory has grown: Private usage: 12MB later: 31MB
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:51598 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:51598 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:51598 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:62299 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:51598 -> 1.1.1.1:53
Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.16:49692 -> 104.26.12.205:443
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 216.58.206.67
Source: unknownTCP traffic detected without corresponding DNS query: 216.58.206.67
Source: unknownTCP traffic detected without corresponding DNS query: 216.58.206.67
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 216.58.206.67
Source: unknownTCP traffic detected without corresponding DNS query: 216.58.206.67
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.199.214.10
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802 HTTP/1.1Host: mailtrack.ioConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802 HTTP/1.1Host: mailtrack.ioConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js?onload=EFpGI0&render=explicit HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveOrigin: https://businessaccounts-suite.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/ HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91f1d720fb482eba&lang=auto HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/cmg/1 HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/590929148:1741763460:S2119J96PMtOmYVyjyjOqwMICBKsnWeGq5m99lNBPIw/91f1d720fb482eba/txslnfZZc9MeTMFkJQrj85Xn_Jar3b5FaVuYrEPDVmM-1741767291-1.1.1.1-yE1SRcrKh8rMS8TxhsfntwHpGjo9NnPLnxWLbvlrmUOH9DgiHlMPzOFCh.yTM8YR HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/pat/91f1d720fb482eba/1741767296732/528cf64308b4b15d00f88ad865fbb969325037cee7765b5d078fa81e3d708896/-0zAtE4JwsRaDmp HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/d/91f1d720fb482eba/1741767296737/4_hvirRxLZPh4IO HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/d/91f1d720fb482eba/1741767296737/4_hvirRxLZPh4IO HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cdn-cgi/challenge-platform/h/g/flow/ov1/590929148:1741763460:S2119J96PMtOmYVyjyjOqwMICBKsnWeGq5m99lNBPIw/91f1d720fb482eba/txslnfZZc9MeTMFkJQrj85Xn_Jar3b5FaVuYrEPDVmM-1741767291-1.1.1.1-yE1SRcrKh8rMS8TxhsfntwHpGjo9NnPLnxWLbvlrmUOH9DgiHlMPzOFCh.yTM8YR HTTP/1.1Host: challenges.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /jquery-3.6.0.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v3/yx/r/8MYI4yJfgT8.js?_nc_eui2=AeEPV2PxaGgsxqWmMC4_wY0D0osIfQl7OSDSiwh9CXs5IF1ngIM3G9EDRD91EkFUFuRHm5Ro4jQOlsxn3uC3C5Zx HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://businessaccounts-suite.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /gh/moonito-net/lib/analytics.min.js HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/yb/r/CnOoIyhtLSO.svg?_nc_eui2=AeGMrivVF1zRqeE-AAIL-SMStf_JPOr9hBa1_8k86v2EFp4gTbIu5CBrJOfLeeGjFWo8psMJF8CUbx97ACNJxv8O HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /plugins/feedback.php?app_id=184484190795&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df6e1840eb1efabd62%26domain%3D%26is_canvas%3Dfalse%26origin%3Dfile%253A%252F%252F%252Ffc5b77b8c83862843%26relation%3Dparent.parent&container_width=1122&height=100&href=https%3A%2F%2Fdevelopers.facebook.com%2Fdocs%2Fplugins%2Fcomments%23configurator&locale=en_US&numposts=1&sdk=joey&version=v21.0&width=550 HTTP/1.1Host: www.facebook.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v3/yE/r/_ZFqu_8EhPu.png HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://businessaccounts-suite.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/362659141_1731314093983753_6097994235157533006_n.jpg?stp=cp0_dst-jpg_s50x50_tt6&_nc_cat=100&ccb=1-7&_nc_sid=4a1148&_nc_eui2=AeGk9T7TNDTxlLWmL06KjAGEJbLYcNXdFOYlsthw1d0U5v88qih-fh4rRG-tcmRCUqjSshUE9Oxb6v4puF7PtIf3&_nc_ohc=I-xQ6vEwkXIQ7kNvgFShbSa&_nc_zt=24&_nc_ht=scontent.fhan2-4.fna&_nc_gid=AUmZuTpTC1pNBKcgf8JHsJN&oh=00_AYD7Hy8OixEJO9hmKIO8TEOwzV-a3X1W1VsJcGexwSK_Dw&oe=674B6756 HTTP/1.1Host: scontent.fhan2-4.fna.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wlgiMX3.png HTTP/1.1Host: i.imgur.comConnection: keep-aliveOrigin: https://businessaccounts-suite.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /l5OVwkV.png HTTP/1.1Host: i.imgur.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/yb/r/CnOoIyhtLSO.svg?_nc_eui2=AeGMrivVF1zRqeE-AAIL-SMStf_JPOr9hBa1_8k86v2EFp4gTbIu5CBrJOfLeeGjFWo8psMJF8CUbx97ACNJxv8O HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /wlgiMX3.png HTTP/1.1Host: i.imgur.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /l5OVwkV.png HTTP/1.1Host: i.imgur.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v3/yx/r/8MYI4yJfgT8.js?_nc_eui2=AeEPV2PxaGgsxqWmMC4_wY0D0osIfQl7OSDSiwh9CXs5IF1ngIM3G9EDRD91EkFUFuRHm5Ro4jQOlsxn3uC3C5Zx HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://businessaccounts-suite.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/362659141_1731314093983753_6097994235157533006_n.jpg?stp=cp0_dst-jpg_s50x50_tt6&_nc_cat=100&ccb=1-7&_nc_sid=4a1148&_nc_eui2=AeGk9T7TNDTxlLWmL06KjAGEJbLYcNXdFOYlsthw1d0U5v88qih-fh4rRG-tcmRCUqjSshUE9Oxb6v4puF7PtIf3&_nc_ohc=I-xQ6vEwkXIQ7kNvgFShbSa&_nc_zt=24&_nc_ht=scontent.fhan2-4.fna&_nc_gid=AUmZuTpTC1pNBKcgf8JHsJN&oh=00_AYD7Hy8OixEJO9hmKIO8TEOwzV-a3X1W1VsJcGexwSK_Dw&oe=674B6756 HTTP/1.1Host: scontent.fhan2-4.fna.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /plugins/feedback.php?app_id=184484190795&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df6e1840eb1efabd62%26domain%3D%26is_canvas%3Dfalse%26origin%3Dfile%253A%252F%252F%252Ffc5b77b8c83862843%26relation%3Dparent.parent&container_width=1122&height=100&href=https%3A%2F%2Fdevelopers.facebook.com%2Fdocs%2Fplugins%2Fcomments%23configurator&locale=en_US&numposts=1&sdk=joey&version=v21.0&width=550 HTTP/1.1Host: www.facebook.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v5/yH/l/0,cross/_D-NAgmmH2z.css HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v5/yo/l/0,cross/UEyOkPpBGje.css HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4/y_/r/sj8PHQXneay.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4i7M54/yt/l/en_US/KmhHRHSLWq8.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4/yF/r/p55HfXW__mM.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4ibHs4/yk/l/en_US/xzYe9P3w2ME.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v3/yE/r/_ZFqu_8EhPu.png HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://businessaccounts-suite.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: imageReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /plugins/feedback.php?app_id=184484190795&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df6e1840eb1efabd62%26domain%3D%26is_canvas%3Dfalse%26origin%3Dfile%253A%252F%252F%252Ffc5b77b8c83862843%26relation%3Dparent.parent&container_width=1122&height=100&href=https%3A%2F%2Fdevelopers.facebook.com%2Fdocs%2Fplugins%2Fcomments%23configurator&locale=en_US&numposts=1&sdk=joey&version=v21.0&width=550 HTTP/1.1Host: www.facebook.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4/yB/r/LFbWcTsZPf7.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4/yi/r/tyfRax5Ez4L.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4iPwL4/yD/l/en_US/5CmUEkNrgz2.js HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveOrigin: https://www.facebook.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYHYdbj_1RHXIpIin-c-0Tfna5rHJiORHQpkBd7aLzI0dw&oe=67D7286D HTTP/1.1Host: scontent-lax3-1.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYF8xCJw2HZZ8CQVgRtPFV9JQq1DwiDp9gu0eLp4Yk_37Q&oe=67F8ADF5 HTTP/1.1Host: scontent-lax3-2.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /plugins/feedback.php?app_id=184484190795&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df6e1840eb1efabd62%26domain%3D%26is_canvas%3Dfalse%26origin%3Dfile%253A%252F%252F%252Ffc5b77b8c83862843%26relation%3Dparent.parent&container_width=1122&height=100&href=https%3A%2F%2Fdevelopers.facebook.com%2Fdocs%2Fplugins%2Fcomments%23configurator&locale=en_US&numposts=1&sdk=joey&version=v21.0&width=550 HTTP/1.1Host: www.facebook.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: https://businessaccounts-suite.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4/y3/r/JZUNEvdo8io.png HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://static.xx.fbcdn.net/rsrc.php/v5/yo/l/0,cross/UEyOkPpBGje.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v1/yi/r/odA9sNLrE86.jpg HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYEwRmmWau_31IMUXqSDPqCzRpjmvhRxefAc96ttzJzpQg&oe=67D7286D HTTP/1.1Host: scontent-lax3-1.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYF0X8W76G5HNJ8icxwqCU8Pah9RhPgrgj_U-NTJe0rBgQ&oe=67F8ADF5 HTTP/1.1Host: scontent-lax3-2.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYF8xCJw2HZZ8CQVgRtPFV9JQq1DwiDp9gu0eLp4Yk_37Q&oe=67F8ADF5 HTTP/1.1Host: scontent-lax3-2.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYHYdbj_1RHXIpIin-c-0Tfna5rHJiORHQpkBd7aLzI0dw&oe=67D7286D HTTP/1.1Host: scontent-lax3-1.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYEwRmmWau_31IMUXqSDPqCzRpjmvhRxefAc96ttzJzpQg&oe=67D7286D HTTP/1.1Host: scontent-lax3-1.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYF0X8W76G5HNJ8icxwqCU8Pah9RhPgrgj_U-NTJe0rBgQ&oe=67F8ADF5 HTTP/1.1Host: scontent-lax3-2.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v1/yi/r/odA9sNLrE86.jpg HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /rsrc.php/v4/y3/r/JZUNEvdo8io.png HTTP/1.1Host: static.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYE_W9TKikohVw-BCayOqSyR1SJX4Q59SprzsCWEB1CT4Q&oe=67D7286D HTTP/1.1Host: scontent-lax3-1.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYGt0exrZRQpBkNEwLuEoZOVK9VvlLQLWF76Eyw12Eb7Jw&oe=67F8ADF5 HTTP/1.1Host: scontent-lax3-2.xx.fbcdn.netConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.facebook.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYE_W9TKikohVw-BCayOqSyR1SJX4Q59SprzsCWEB1CT4Q&oe=67D7286D HTTP/1.1Host: scontent-lax3-1.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYGt0exrZRQpBkNEwLuEoZOVK9VvlLQLWF76Eyw12Eb7Jw&oe=67F8ADF5 HTTP/1.1Host: scontent-lax3-2.xx.fbcdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: mailtrack.io
Source: global trafficDNS traffic detected: DNS query: businessaccounts-suite.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: static.xx.fbcdn.net
Source: global trafficDNS traffic detected: DNS query: code.jquery.com
Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global trafficDNS traffic detected: DNS query: scontent.fhan2-4.fna.fbcdn.net
Source: global trafficDNS traffic detected: DNS query: www.facebook.com
Source: global trafficDNS traffic detected: DNS query: i.imgur.com
Source: global trafficDNS traffic detected: DNS query: moonito.net
Source: global trafficDNS traffic detected: DNS query: scontent-lax3-2.xx.fbcdn.net
Source: global trafficDNS traffic detected: DNS query: scontent-lax3-1.xx.fbcdn.net
Source: unknownHTTP traffic detected: POST /report/v4?s=fu7KMBXrCw4HTgvauIckDv5%2B1sc%2FDbfcHwkYxoAbun1vzjT%2FijEShdpqJQplb5UmeL48jK2fAEib0JG8yPkjr%2BCn8czdQV7IyQl9%2Fw1AtdaHQHJ9DFLZNET%2FL26EORSWGXLQMJYuuibk9n51Nw%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 392Content-Type: application/reports+jsonOrigin: https://businessaccounts-suite.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundVary: Accept-Encodingx-fatal-request: static.xx.fbcdn.netPragma: no-cacheCache-Control: private, no-cache, no-store, must-revalidateExpires: Sat, 01 Jan 2000 00:00:00 GMTtiming-allow-origin: *reporting-endpoints: permissions_policy="https://www.xx.facebook.com/ajax/browser_error_reports/"report-to: {"max_age":21600,"endpoints":[{"url":"https:\/\/www.xx.facebook.com\/ajax\/browser_error_reports\/"}],"group":"permissions_policy"}content-security-policy: default-src blob: 'self';script-src *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* blob: data: 'self' https://*.google-analytics.com *.google.com;style-src 'unsafe-inline';connect-src *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* wss://*.whatsapp.com:* wss://*.fbcdn.net attachment.fbsbx.com ws://localhost:* blob: *.cdninstagram.com 'self' https://*.google-analytics.com;font-src data: blob: 'self';img-src data: blob: 'self' https://*.google-analytics.com;media-src data: blob: 'self';child-src data: blob: 'self';frame-src data: blob: 'self';manifest-src data: blob: 'self';object-src data: blob: 'self';worker-src data: blob: 'self';block-all-mixed-content;upgrade-insecure-requests;require-trusted-types-for 'script';document-policy: force-load-at-top
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenAccess-Control-Allow-Origin: *Content-Type: text/plainServer: proxygen-bolt
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundVary: Accept-Encodingx-fatal-request: static.xx.fbcdn.netPragma: no-cacheCache-Control: private, no-cache, no-store, must-revalidateExpires: Sat, 01 Jan 2000 00:00:00 GMTtiming-allow-origin: *reporting-endpoints: permissions_policy="https://www.xx.facebook.com/ajax/browser_error_reports/"report-to: {"max_age":21600,"endpoints":[{"url":"https:\/\/www.xx.facebook.com\/ajax\/browser_error_reports\/"}],"group":"permissions_policy"}content-security-policy: default-src blob: 'self';script-src *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* blob: data: 'self' https://*.google-analytics.com *.google.com;style-src 'unsafe-inline';connect-src *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* wss://*.whatsapp.com:* wss://*.fbcdn.net attachment.fbsbx.com ws://localhost:* blob: *.cdninstagram.com 'self' https://*.google-analytics.com;font-src data: blob: 'self';img-src data: blob: 'self' https://*.google-analytics.com;media-src data: blob: 'self';child-src data: blob: 'self';frame-src data: blob: 'self';manifest-src data: blob: 'self';object-src data: blob: 'self';worker-src data: blob: 'self';block-all-mixed-content;upgrade-insecure-requests;require-trusted-types-for 'script';document-policy: force-load-at-top
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundVary: Accept-Encodingx-fatal-request: static.xx.fbcdn.netPragma: no-cacheCache-Control: private, no-cache, no-store, must-revalidateExpires: Sat, 01 Jan 2000 00:00:00 GMTtiming-allow-origin: *reporting-endpoints: permissions_policy="https://www.xx.facebook.com/ajax/browser_error_reports/"report-to: {"max_age":21600,"endpoints":[{"url":"https:\/\/www.xx.facebook.com\/ajax\/browser_error_reports\/"}],"group":"permissions_policy"}content-security-policy: default-src blob: 'self';script-src *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* blob: data: 'self' https://*.google-analytics.com *.google.com;style-src 'unsafe-inline';connect-src *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* wss://*.whatsapp.com:* wss://*.fbcdn.net attachment.fbsbx.com ws://localhost:* blob: *.cdninstagram.com 'self' https://*.google-analytics.com;font-src data: blob: 'self';img-src data: blob: 'self' https://*.google-analytics.com;media-src data: blob: 'self';child-src data: blob: 'self';frame-src data: blob: 'self';manifest-src data: blob: 'self';object-src data: blob: 'self';worker-src data: blob: 'self';block-all-mixed-content;upgrade-insecure-requests;require-trusted-types-for 'script';document-policy: force-load-at-top
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenAccess-Control-Allow-Origin: *Content-Type: text/plainServer: proxygen-bolt
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundVary: Accept-Encodingx-fatal-request: static.xx.fbcdn.netPragma: no-cacheCache-Control: private, no-cache, no-store, must-revalidateExpires: Sat, 01 Jan 2000 00:00:00 GMTtiming-allow-origin: *reporting-endpoints: permissions_policy="https://www.xx.facebook.com/ajax/browser_error_reports/"report-to: {"max_age":21600,"endpoints":[{"url":"https:\/\/www.xx.facebook.com\/ajax\/browser_error_reports\/"}],"group":"permissions_policy"}content-security-policy: default-src blob: 'self';script-src *.facebook.com *.fbcdn.net *.facebook.net 127.0.0.1:* blob: data: 'self' https://*.google-analytics.com *.google.com;style-src 'unsafe-inline';connect-src *.facebook.com facebook.com *.fbcdn.net *.facebook.net wss://*.facebook.com:* wss://*.whatsapp.com:* wss://*.fbcdn.net attachment.fbsbx.com ws://localhost:* blob: *.cdninstagram.com 'self' https://*.google-analytics.com;font-src data: blob: 'self';img-src data: blob: 'self' https://*.google-analytics.com;media-src data: blob: 'self';child-src data: blob: 'self';frame-src data: blob: 'self';manifest-src data: blob: 'self';object-src data: blob: 'self';worker-src data: blob: 'self';block-all-mixed-content;upgrade-insecure-requests;require-trusted-types-for 'script';document-policy: force-load-at-top
Source: unknownNetwork traffic detected: HTTP traffic on port 62326 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62349 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62303 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62378 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62384 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62341 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62315
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62316
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62317
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62318
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62319
Source: unknownNetwork traffic detected: HTTP traffic on port 62358 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62311
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62314
Source: unknownNetwork traffic detected: HTTP traffic on port 62335 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62308 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62321 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62381 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62367 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62329 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62346 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62326
Source: unknownNetwork traffic detected: HTTP traffic on port 62315 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62327
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62328
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62329
Source: unknownNetwork traffic detected: HTTP traffic on port 62370 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62332 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62320
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62321
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62322
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62323
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62324
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62325
Source: unknownNetwork traffic detected: HTTP traffic on port 62301 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62376 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62382 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51600 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62320 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51600
Source: unknownNetwork traffic detected: HTTP traffic on port 62328 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62343 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62314 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62338
Source: unknownNetwork traffic detected: HTTP traffic on port 62340 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62339
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62330
Source: unknownNetwork traffic detected: HTTP traffic on port 62356 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62331
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62332
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62334
Source: unknownNetwork traffic detected: HTTP traffic on port 62373 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62335
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62336
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62350
Source: unknownNetwork traffic detected: HTTP traffic on port 62323 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62348 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62365 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62362 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62348
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62349
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62340
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62341
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62342
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62343
Source: unknownNetwork traffic detected: HTTP traffic on port 62359 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 62317 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62344
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62345
Source: unknownNetwork traffic detected: HTTP traffic on port 62334 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62346
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62347
Source: unknownNetwork traffic detected: HTTP traffic on port 62351 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62374 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62345 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62322 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62380 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62359
Source: unknownNetwork traffic detected: HTTP traffic on port 62339 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62351
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62352
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62355
Source: unknownNetwork traffic detected: HTTP traffic on port 62316 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62331 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62356
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62357
Source: unknownNetwork traffic detected: HTTP traffic on port 62371 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62358
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62304 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62377 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62370
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62371
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62372
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62342 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62325 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62363 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62357 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62362
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62363
Source: unknownNetwork traffic detected: HTTP traffic on port 62311 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62365
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62366
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62367
Source: unknownNetwork traffic detected: HTTP traffic on port 62319 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62336 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62369
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62380
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62381
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62382
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62383
Source: unknownNetwork traffic detected: HTTP traffic on port 62305 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62366 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62324 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62347 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62373
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62374
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62375
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62376
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62377
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62378
Source: unknownNetwork traffic detected: HTTP traffic on port 62350 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62318 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62352 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62302 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62375 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62369 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62383 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62327 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62344 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62338 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62304
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62305
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62308
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62384
Source: unknownNetwork traffic detected: HTTP traffic on port 62330 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62301
Source: unknownNetwork traffic detected: HTTP traffic on port 62355 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 62372 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62302
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62303
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir5580_1180505272
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir5580_1180505272
Source: classification engineClassification label: mal48.win@31/0@46/268
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1904,i,12928209957432010173,5565500243814302611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2192 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcon"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1904,i,12928209957432010173,5565500243814302611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2192 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --no-pre-read-main-dll --field-trial-handle=1904,i,12928209957432010173,5565500243814302611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=4196 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --no-pre-read-main-dll --field-trial-handle=1904,i,12928209957432010173,5565500243814302611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=4196 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcon0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e8020%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91f1d720fb482eba&lang=auto0%Avira URL Cloudsafe
https://a.nel.cloudflare.com/report/v4?s=fu7KMBXrCw4HTgvauIckDv5%2B1sc%2FDbfcHwkYxoAbun1vzjT%2FijEShdpqJQplb5UmeL48jK2fAEib0JG8yPkjr%2BCn8czdQV7IyQl9%2Fw1AtdaHQHJ9DFLZNET%2FL26EORSWGXLQMJYuuibk9n51Nw%3D%3D0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/590929148:1741763460:S2119J96PMtOmYVyjyjOqwMICBKsnWeGq5m99lNBPIw/91f1d720fb482eba/txslnfZZc9MeTMFkJQrj85Xn_Jar3b5FaVuYrEPDVmM-1741767291-1.1.1.1-yE1SRcrKh8rMS8TxhsfntwHpGjo9NnPLnxWLbvlrmUOH9DgiHlMPzOFCh.yTM8YR0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/91f1d720fb482eba/1741767296737/4_hvirRxLZPh4IO0%Avira URL Cloudsafe
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/91f1d720fb482eba/1741767296732/528cf64308b4b15d00f88ad865fbb969325037cee7765b5d078fa81e3d708896/-0zAtE4JwsRaDmp0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v3/yx/r/8MYI4yJfgT8.js?_nc_eui2=AeEPV2PxaGgsxqWmMC4_wY0D0osIfQl7OSDSiwh9CXs5IF1ngIM3G9EDRD91EkFUFuRHm5Ro4jQOlsxn3uC3C5Zx0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v3/yE/r/_ZFqu_8EhPu.png0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v4/yB/r/LFbWcTsZPf7.js0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v4ibHs4/yk/l/en_US/xzYe9P3w2ME.js0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v4i7M54/yt/l/en_US/KmhHRHSLWq8.js0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v4/yi/r/tyfRax5Ez4L.js0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v5/yo/l/0,cross/UEyOkPpBGje.css0%Avira URL Cloudsafe
https://static.xx.fbcdn.net/rsrc.php/v4/y_/r/sj8PHQXneay.js0%Avira URL Cloudsafe
https://www.facebook.com/ajax/browser_error_reports/?device_level=unknown&brsid=7480833738340994617&cpp=C3&cv=10208150830%Avira URL Cloudsafe
https://scontent-lax3-1.xx.fbcdn.net/v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYE_W9TKikohVw-BCayOqSyR1SJX4Q59SprzsCWEB1CT4Q&oe=67D7286D0%Avira URL Cloudsafe
https://scontent-lax3-2.xx.fbcdn.net/v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYF0X8W76G5HNJ8icxwqCU8Pah9RhPgrgj_U-NTJe0rBgQ&oe=67F8ADF50%Avira URL Cloudsafe
https://scontent-lax3-2.xx.fbcdn.net/v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYF8xCJw2HZZ8CQVgRtPFV9JQq1DwiDp9gu0eLp4Yk_37Q&oe=67F8ADF50%Avira URL Cloudsafe
https://a.nel.cloudflare.com/report/v4?s=WGLryLVaooIAgynrym88wT6lI%2FtABiA36rE77umy%2FeosBlbKYcor3kGXypPvOnY6z7Ly9IoF8PhPH6gU9RUjNlf1EAP7L13jEpm3DdSXzgXoTXfH%2FfQL8P29UsswTQ%3D%3D0%Avira URL Cloudsafe
https://scontent-lax3-1.xx.fbcdn.net/v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYEwRmmWau_31IMUXqSDPqCzRpjmvhRxefAc96ttzJzpQg&oe=67D7286D0%Avira URL Cloudsafe
https://scontent-lax3-1.xx.fbcdn.net/v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYHYdbj_1RHXIpIin-c-0Tfna5rHJiORHQpkBd7aLzI0dw&oe=67D7286D0%Avira URL Cloudsafe
https://a.nel.cloudflare.com/report/v4?s=gOdS54gpS3YlneTikGK1fC1YUz8Wii2HAdgUCqnup3aq9yqPZVuFd0kjrHYIr8PSz6oNqecdxk0ydVydInjN%2BwMCI0h4vmCBoNFbRCDiriR1YTF5nYj%2BogJgzCt%2BhCQmvgVcIscge6Uoj5pv2Q%3D%3D0%Avira URL Cloudsafe
https://a.nel.cloudflare.com/report/v4?s=rgw5gaxyWQpFjshRmMkDusR0qlBw32rWiBJpKhydhBnSqweTAa7MhwFFwtjTA1w%2BIXkgMEOSq3SoYgq7oGgiYM7AL%2BJkub2CDDdoJJEc4NCJPqp9pQ2RcLCMcQeEzyiy9OnVS3ArwvJKk%2BeWjA%3D%3D0%Avira URL Cloudsafe
https://scontent-lax3-2.xx.fbcdn.net/v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYGt0exrZRQpBkNEwLuEoZOVK9VvlLQLWF76Eyw12Eb7Jw&oe=67F8ADF50%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
jsdelivr.map.fastly.net
151.101.129.229
truefalse
    high
    star-mini.c10r.facebook.com
    157.240.252.35
    truefalse
      high
      mailtrack.io
      34.249.33.26
      truefalse
        high
        a.nel.cloudflare.com
        35.190.80.1
        truefalse
          high
          scontent.fhan2-4.fna.fbcdn.net
          42.114.77.145
          truefalse
            high
            moonito.net
            104.21.48.1
            truefalse
              high
              scontent-lax3-2.xx.fbcdn.net
              157.240.11.22
              truefalse
                unknown
                scontent.xx.fbcdn.net
                157.240.252.13
                truefalse
                  high
                  scontent-lax3-1.xx.fbcdn.net
                  31.13.70.7
                  truefalse
                    unknown
                    code.jquery.com
                    151.101.130.137
                    truefalse
                      high
                      challenges.cloudflare.com
                      104.18.94.41
                      truefalse
                        high
                        www.google.com
                        216.58.212.164
                        truefalse
                          high
                          businessaccounts-suite.com
                          172.67.166.105
                          truetrue
                            unknown
                            ipv4.imgur.map.fastly.net
                            199.232.192.193
                            truefalse
                              high
                              www.facebook.com
                              unknown
                              unknownfalse
                                high
                                cdn.jsdelivr.net
                                unknown
                                unknownfalse
                                  high
                                  static.xx.fbcdn.net
                                  unknown
                                  unknownfalse
                                    high
                                    i.imgur.com
                                    unknown
                                    unknownfalse
                                      high
                                      NameMaliciousAntivirus DetectionReputation
                                      https://www.facebook.com/ajax/browser_error_reports/?device_level=unknown&brsid=7480833738340994617&cpp=C3&cv=1020815083false
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://a.nel.cloudflare.com/report/v4?s=fu7KMBXrCw4HTgvauIckDv5%2B1sc%2FDbfcHwkYxoAbun1vzjT%2FijEShdpqJQplb5UmeL48jK2fAEib0JG8yPkjr%2BCn8czdQV7IyQl9%2Fw1AtdaHQHJ9DFLZNET%2FL26EORSWGXLQMJYuuibk9n51Nw%3D%3Dfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/590929148:1741763460:S2119J96PMtOmYVyjyjOqwMICBKsnWeGq5m99lNBPIw/91f1d720fb482eba/txslnfZZc9MeTMFkJQrj85Xn_Jar3b5FaVuYrEPDVmM-1741767291-1.1.1.1-yE1SRcrKh8rMS8TxhsfntwHpGjo9NnPLnxWLbvlrmUOH9DgiHlMPzOFCh.yTM8YRfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://code.jquery.com/jquery-3.6.0.min.jsfalse
                                        high
                                        https://static.xx.fbcdn.net/rsrc.php/v4/yB/r/LFbWcTsZPf7.jsfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://scontent-lax3-1.xx.fbcdn.net/v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYEwRmmWau_31IMUXqSDPqCzRpjmvhRxefAc96ttzJzpQg&oe=67D7286Dfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://scontent-lax3-2.xx.fbcdn.net/v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=A9jkARclUo1JNeP6cSSe28e&oh=00_AYF0X8W76G5HNJ8icxwqCU8Pah9RhPgrgj_U-NTJe0rBgQ&oe=67F8ADF5false
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://scontent-lax3-2.xx.fbcdn.net/v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYF8xCJw2HZZ8CQVgRtPFV9JQq1DwiDp9gu0eLp4Yk_37Q&oe=67F8ADF5false
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://static.xx.fbcdn.net/rsrc.php/v4i7M54/yt/l/en_US/KmhHRHSLWq8.jsfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://scontent-lax3-1.xx.fbcdn.net/v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AxtB-N42CVVmdKBDZccrk4J&oh=00_AYHYdbj_1RHXIpIin-c-0Tfna5rHJiORHQpkBd7aLzI0dw&oe=67D7286Dfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://static.xx.fbcdn.net/rsrc.php/v1/yi/r/odA9sNLrE86.jpgfalse
                                          high
                                          https://i.imgur.com/l5OVwkV.pngfalse
                                            high
                                            https://static.xx.fbcdn.net/rsrc.php/v4/yF/r/p55HfXW__mM.jsfalse
                                              high
                                              https://static.xx.fbcdn.net/rsrc.php/v3/yE/r/_ZFqu_8EhPu.pngfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://www.facebook.com/plugins/feedback.php?app_id=184484190795&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df6e1840eb1efabd62%26domain%3D%26is_canvas%3Dfalse%26origin%3Dfile%253A%252F%252F%252Ffc5b77b8c83862843%26relation%3Dparent.parent&container_width=1122&height=100&href=https%3A%2F%2Fdevelopers.facebook.com%2Fdocs%2Fplugins%2Fcomments%23configurator&locale=en_US&numposts=1&sdk=joey&version=v21.0&width=550false
                                                high
                                                https://static.xx.fbcdn.net/rsrc.php/v4/y3/r/JZUNEvdo8io.pngfalse
                                                  high
                                                  https://a.nel.cloudflare.com/report/v4?s=WGLryLVaooIAgynrym88wT6lI%2FtABiA36rE77umy%2FeosBlbKYcor3kGXypPvOnY6z7Ly9IoF8PhPH6gU9RUjNlf1EAP7L13jEpm3DdSXzgXoTXfH%2FfQL8P29UsswTQ%3D%3Dfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/91f1d720fb482eba/1741767296737/4_hvirRxLZPh4IOfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://static.xx.fbcdn.net/rsrc.php/v3/yx/r/8MYI4yJfgT8.js?_nc_eui2=AeEPV2PxaGgsxqWmMC4_wY0D0osIfQl7OSDSiwh9CXs5IF1ngIM3G9EDRD91EkFUFuRHm5Ro4jQOlsxn3uC3C5Zxfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://static.xx.fbcdn.net/rsrc.php/yb/r/CnOoIyhtLSO.svg?_nc_eui2=AeGMrivVF1zRqeE-AAIL-SMStf_JPOr9hBa1_8k86v2EFp4gTbIu5CBrJOfLeeGjFWo8psMJF8CUbx97ACNJxv8Ofalse
                                                    high
                                                    https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802false
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://a.nel.cloudflare.com/report/v4?s=rgw5gaxyWQpFjshRmMkDusR0qlBw32rWiBJpKhydhBnSqweTAa7MhwFFwtjTA1w%2BIXkgMEOSq3SoYgq7oGgiYM7AL%2BJkub2CDDdoJJEc4NCJPqp9pQ2RcLCMcQeEzyiy9OnVS3ArwvJKk%2BeWjA%3D%3Dfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://static.xx.fbcdn.net/rsrc.php/v4/y_/r/sj8PHQXneay.jsfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://static.xx.fbcdn.net/rsrc.php/v4iPwL4/yD/l/en_US/5CmUEkNrgz2.jsfalse
                                                      high
                                                      https://static.xx.fbcdn.net/rsrc.php/v5/yH/l/0,cross/_D-NAgmmH2z.cssfalse
                                                        high
                                                        https://scontent.fhan2-4.fna.fbcdn.net/v/t39.30808-1/362659141_1731314093983753_6097994235157533006_n.jpg?stp=cp0_dst-jpg_s50x50_tt6&_nc_cat=100&ccb=1-7&_nc_sid=4a1148&_nc_eui2=AeGk9T7TNDTxlLWmL06KjAGEJbLYcNXdFOYlsthw1d0U5v88qih-fh4rRG-tcmRCUqjSshUE9Oxb6v4puF7PtIf3&_nc_ohc=I-xQ6vEwkXIQ7kNvgFShbSa&_nc_zt=24&_nc_ht=scontent.fhan2-4.fna&_nc_gid=AUmZuTpTC1pNBKcgf8JHsJN&oh=00_AYD7Hy8OixEJO9hmKIO8TEOwzV-a3X1W1VsJcGexwSK_Dw&oe=674B6756false
                                                          high
                                                          https://businessaccounts-suite.com/?user_email=m.alarcon%40servihabitat.com&fname=Mireia&lname=Alarconfalse
                                                            unknown
                                                            https://scontent-lax3-1.xx.fbcdn.net/v/t39.30808-1/246003289_4364012840312831_5150192035847648142_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=110&ccb=1-7&_nc_sid=fe756c&_nc_ohc=cdo9XJlT4-0Q7kNvgFwHDhx&_nc_oc=AdjYX4MKAKzuhrvxVFhVMtvwBuFIdPkd26D7aocGrTiF_CfcBkuzvSH8XYzzGGAD4PM&_nc_zt=24&_nc_ht=scontent-lax3-1.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYE_W9TKikohVw-BCayOqSyR1SJX4Q59SprzsCWEB1CT4Q&oe=67D7286Dfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1false
                                                              high
                                                              https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/83hmy/0x4AAAAAAADnOjc0PNeA8qVm/light/fbE/new/normal/auto/false
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=91f1d720fb482eba&lang=autofalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://cdn.jsdelivr.net/gh/moonito-net/lib/analytics.min.jsfalse
                                                                high
                                                                https://scontent-lax3-2.xx.fbcdn.net/v/t1.6435-1/184507376_546774716729178_4755840928860760293_n.jpg?stp=cp0_dst-jpg_s48x48_tt6&_nc_cat=100&ccb=1-7&_nc_sid=fe756c&_nc_ohc=1GziCSHhYIkQ7kNvgGCCk4n&_nc_oc=AdhCyuCmVoln3qN_s63XX700ewNuutD-clPjsJKs66aW67yUIKSS_aoVzOxU_dkYqJY&_nc_zt=24&_nc_ht=scontent-lax3-2.xx&edm=AJqh0Q8EAAAA&_nc_gid=AVNBflge0mG5W5A32pbE05b&oh=00_AYGt0exrZRQpBkNEwLuEoZOVK9VvlLQLWF76Eyw12Eb7Jw&oe=67F8ADF5false
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://static.xx.fbcdn.net/rsrc.php/v5/yo/l/0,cross/UEyOkPpBGje.cssfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://static.xx.fbcdn.net/rsrc.php/v4ibHs4/yk/l/en_US/xzYe9P3w2ME.jsfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://businessaccounts-suite.com/#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcontrue
                                                                  unknown
                                                                  https://i.imgur.com/wlgiMX3.pngfalse
                                                                    high
                                                                    https://static.xx.fbcdn.net/rsrc.php/v4/yi/r/tyfRax5Ez4L.jsfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/91f1d720fb482eba/1741767296732/528cf64308b4b15d00f88ad865fbb969325037cee7765b5d078fa81e3d708896/-0zAtE4JwsRaDmpfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://a.nel.cloudflare.com/report/v4?s=gOdS54gpS3YlneTikGK1fC1YUz8Wii2HAdgUCqnup3aq9yqPZVuFd0kjrHYIr8PSz6oNqecdxk0ydVydInjN%2BwMCI0h4vmCBoNFbRCDiriR1YTF5nYj%2BogJgzCt%2BhCQmvgVcIscge6Uoj5pv2Q%3D%3Dfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    • No. of IPs < 25%
                                                                    • 25% < No. of IPs < 50%
                                                                    • 50% < No. of IPs < 75%
                                                                    • 75% < No. of IPs
                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                    34.249.33.26
                                                                    mailtrack.ioUnited States
                                                                    16509AMAZON-02USfalse
                                                                    104.21.48.1
                                                                    moonito.netUnited States
                                                                    13335CLOUDFLARENETUSfalse
                                                                    216.58.212.164
                                                                    www.google.comUnited States
                                                                    15169GOOGLEUSfalse
                                                                    151.101.129.229
                                                                    jsdelivr.map.fastly.netUnited States
                                                                    54113FASTLYUSfalse
                                                                    104.18.94.41
                                                                    challenges.cloudflare.comUnited States
                                                                    13335CLOUDFLARENETUSfalse
                                                                    42.114.77.145
                                                                    scontent.fhan2-4.fna.fbcdn.netViet Nam
                                                                    18403FPT-AS-APTheCorporationforFinancingPromotingTechnolofalse
                                                                    199.232.196.193
                                                                    unknownUnited States
                                                                    54113FASTLYUSfalse
                                                                    157.240.11.22
                                                                    scontent-lax3-2.xx.fbcdn.netUnited States
                                                                    32934FACEBOOKUSfalse
                                                                    151.101.130.137
                                                                    code.jquery.comUnited States
                                                                    54113FASTLYUSfalse
                                                                    157.240.0.6
                                                                    unknownUnited States
                                                                    32934FACEBOOKUSfalse
                                                                    172.217.23.99
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    142.250.185.142
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    142.251.40.174
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    142.250.186.131
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    35.190.80.1
                                                                    a.nel.cloudflare.comUnited States
                                                                    15169GOOGLEUSfalse
                                                                    157.240.252.13
                                                                    scontent.xx.fbcdn.netUnited States
                                                                    32934FACEBOOKUSfalse
                                                                    157.240.252.35
                                                                    star-mini.c10r.facebook.comUnited States
                                                                    32934FACEBOOKUSfalse
                                                                    142.250.185.67
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    142.250.186.78
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    1.1.1.1
                                                                    unknownAustralia
                                                                    13335CLOUDFLARENETUSfalse
                                                                    199.232.192.193
                                                                    ipv4.imgur.map.fastly.netUnited States
                                                                    54113FASTLYUSfalse
                                                                    74.125.71.84
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    104.18.95.41
                                                                    unknownUnited States
                                                                    13335CLOUDFLARENETUSfalse
                                                                    142.250.185.138
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    157.240.251.9
                                                                    unknownUnited States
                                                                    32934FACEBOOKUSfalse
                                                                    31.13.70.7
                                                                    scontent-lax3-1.xx.fbcdn.netIreland
                                                                    32934FACEBOOKUSfalse
                                                                    142.250.184.238
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    142.250.184.234
                                                                    unknownUnited States
                                                                    15169GOOGLEUSfalse
                                                                    172.67.166.105
                                                                    businessaccounts-suite.comUnited States
                                                                    13335CLOUDFLARENETUStrue
                                                                    IP
                                                                    192.168.2.16
                                                                    Joe Sandbox version:42.0.0 Malachite
                                                                    Analysis ID:1635971
                                                                    Start date and time:2025-03-12 09:13:56 +01:00
                                                                    Joe Sandbox product:CloudBasic
                                                                    Overall analysis duration:
                                                                    Hypervisor based Inspection enabled:false
                                                                    Report type:full
                                                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                    Sample URL:https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcon
                                                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                    Number of analysed new started processes analysed:16
                                                                    Number of new started drivers analysed:0
                                                                    Number of existing processes analysed:0
                                                                    Number of existing drivers analysed:0
                                                                    Number of injected processes analysed:0
                                                                    Technologies:
                                                                    • EGA enabled
                                                                    Analysis Mode:stream
                                                                    Analysis stop reason:Timeout
                                                                    Detection:MAL
                                                                    Classification:mal48.win@31/0@46/268
                                                                    • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                                                                    • Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.185.142, 142.250.184.238, 74.125.71.84, 142.250.186.78, 199.232.214.172, 216.58.206.78, 172.217.18.14, 52.149.20.212
                                                                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
                                                                    • Not all processes where analyzed, report is missing behavior information
                                                                    • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                    • VT rate limit hit for: https://mailtrack.io/l/602b7f5905dfb2b7053f69bb1ad3f5e5fe2093ad?url=https%3A%2F%2Fbusinessaccounts-suite.com&u=12237839&signature=92845e946510e802#user_email=m.alarcon@servihabitat.com&fname=Mireia&lname=Alarcon
                                                                    No created / dropped files found
                                                                    No static file info