Click to jump to signature section
Source: https://rurfifv.wixstudio.com/my-site | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The URL 'rurfifv.wixstudio.com' does not match the legitimate domain 'microsoft.com'., The domain 'wixstudio.com' is a platform for creating websites, which can be used by anyone, including potential phishers., The subdomain 'rurfifv' is unrelated to Microsoft and appears random, which is suspicious., The presence of input fields for 'Email' and 'Password' on a non-Microsoft domain increases the risk of phishing. DOM: 0.0.pages.csv |
Source: https://rurfifv.wixstudio.com/my-site | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The URL 'rurfifv.wixstudio.com' does not match the legitimate domain 'microsoft.com'., The domain 'wixstudio.com' is a platform for creating websites, which is not directly associated with Microsoft., The subdomain 'rurfifv' is unrelated to Microsoft and appears random, which is suspicious., The presence of input fields for 'Email' and 'Password' on a non-Microsoft domain increases the risk of phishing. DOM: 0.2.pages.csv |
Source: Yara match | File source: 0.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.1.pages.csv, type: HTML |
Source: Yara match | File source: 0.0.pages.csv, type: HTML |
Source: Yara match | File source: dropped/chromecache_171, type: DROPPED |
Source: Yara match | File source: 0.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.1.pages.csv, type: HTML |
Source: Yara match | File source: 0.0.pages.csv, type: HTML |
Source: Yara match | File source: dropped/chromecache_171, type: DROPPED |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: Title: Home | My Site does not match URL |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: No <meta name="author".. found |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: No <meta name="author".. found |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: No <meta name="author".. found |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: No <meta name="copyright".. found |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: No <meta name="copyright".. found |
Source: https://rurfifv.wixstudio.com/my-site | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 142.250.185.164:443 -> 192.168.2.6:49703 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.144.206.118:443 -> 192.168.2.6:49707 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.144.206.118:443 -> 192.168.2.6:49706 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.49.229.81:443 -> 192.168.2.6:49712 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.49.229.81:443 -> 192.168.2.6:49708 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.49.229.81:443 -> 192.168.2.6:49709 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 3.167.227.129:443 -> 192.168.2.6:49710 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 3.167.227.129:443 -> 192.168.2.6:49711 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.144.206.118:443 -> 192.168.2.6:49718 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.199.63.76:443 -> 192.168.2.6:49720 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.149.206.255:443 -> 192.168.2.6:49719 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 151.101.130.217:443 -> 192.168.2.6:49726 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 3.167.227.32:443 -> 192.168.2.6:49727 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 3.167.227.32:443 -> 192.168.2.6:49733 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.49.229.81:443 -> 192.168.2.6:49753 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.49.229.81:443 -> 192.168.2.6:49752 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.149.87.45:443 -> 192.168.2.6:49783 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.149.87.45:443 -> 192.168.2.6:49788 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.207.104.172:443 -> 192.168.2.6:55180 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.207.104.172:443 -> 192.168.2.6:55175 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.207.104.172:443 -> 192.168.2.6:55176 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.207.104.172:443 -> 192.168.2.6:55177 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.207.104.172:443 -> 192.168.2.6:55178 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.207.104.172:443 -> 192.168.2.6:55179 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.149.206.255:443 -> 192.168.2.6:55181 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.199.63.76:443 -> 192.168.2.6:55185 version: TLS 1.2 |
Source: global traffic | TCP traffic: 192.168.2.6:55151 -> 1.1.1.1:53 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.42.65.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.77.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.215 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.215 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /my-site HTTP/1.1Host: rurfifv.wixstudio.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /my-site/_api/v1/access-tokens HTTP/1.1Host: rurfifv.wixstudio.comConnection: keep-aliveclient-binding: c1a7e93e-fc9f-4a96-9a97-ebb445aebe37sec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://rurfifv.wixstudio.com/my-siteAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: server-session-bind=c1a7e93e-fc9f-4a96-9a97-ebb445aebe37; ssr-caching=cache#desc=hit#varnish=hit#dc#desc=virginia-pub_g; XSRF-TOKEN=1742257214|x3AB73XmNI48 |
Source: global traffic | HTTP traffic detected: GET /media/f7bc5a_68c8c3d4528d47a08b77778e36499cb6~mv2.jpg/v1/fill/w_160,h_84,al_c,q_80,usm_0.66_1.00_0.01,blur_3,enc_avif,quality_auto/f7bc5a_68c8c3d4528d47a08b77778e36499cb6~mv2.jpg HTTP/1.1Host: static.wixstatic.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://rurfifv.wixstudio.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /fonts/v2/f73e760d-c6b3-4659-9a8c-9ce1d76c1173/madefor-text.var.original.woff2 HTTP/1.1Host: static.parastorage.comConnection: keep-aliveOrigin: https://rurfifv.wixstudio.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://rurfifv.wixstudio.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pages/pages/thunderbolt?beckyExperiments=.DatePickerPortal%2C.LoginBarEnableLoggingInStateInSSR%2C.TextInputAutoFillFix%2C.buttonUdp%2C.calculateCollapsibleTextLineHeightByFont%2C.cssInBlocks%2C.dataBindingInMasterResponsive%2C.dropAppsClientSpecMapByApplicationId%2C.encodeUris%2C.fetchBlocksDevCenterWidgetIds%2C.fiveGridLineStudioSkins%2C.fixHasPinnedChildrenRepeaterCalc%2C.getSiteOverrideFromAllInflationChain%2C.imageEncodingAVIF%2C.overflowXClipInMobile%2C.prefetchPageResourcesVeloApi%2C.removeAllStatesBlocksFix%2C.shouldUseResponsiveImages%2C.sliderGalleryWAAPI%2C.updateRichTextSemanticClassNamesOnCorvid%2C.useInternalBlocksRefType%2C.useSvgLoaderFeature&blocksBuilderManifestGeneratorVersion=1.129.0&contentType=application%2Fjson&deviceType=Desktop&dfCk=6&dfVersion=1.4500.0&disableStaticPagesUrlHierarchy=false&editorName=Studio&experiments=dm_bgScrubToMotionFixer%2Cdm_deleteLayoutOverridesForRefComponents%2Cdm_migrateOldHoverBoxToNewFixer%2Cdm_removeTpaChildren%2Cspecs.thunderbolt.use_data_fixed_pages_upstream&externalBaseUrl=https%3A%2F%2Frurfifv.wixstudio.com%2Fmy-site&fileId=c9461a0f.bundle.min&formFactor=desktop&freemiumBanner=true&hasTPAWorkerOnSite=false&isHttps=true&isInSeo=false&isMultilingualEnabled=false&isResponsive=true&isTrackClicksAnalyticsEnabled=false&isUrlMigrated=true&isWixCodeOnPage=false&isWixCodeOnSite=false&language=en&languageResolutionMethod=QueryParam&metaSiteId=221ecf3d-725d-4ae0-b0ac-b0233cec0d3d&module=thunderbolt-features&oneDocEnabled=true&originalLanguage=en&pageId=f7bc5a_9d20c14830645468504696601d12f371_3.json&quickActionsMenuEnabled=false®istryLibrariesTopology=%5B%7B%22artifactId%22%3A%22editor-elements%22%2C%22namespace%22%3A%22wixui%22%2C%22url%22%3A%22https%3A%2F%2Fstatic.parastorage.com%2Fservices%2Feditor-elements%2F1.13479.0%22%7D%2C%7B%22artifactId%22%3A%22editor-elements%22%2C%22namespace%22%3A%22dsgnsys%22%2C%22url%22%3A%22https%3A%2F%2Fstatic.parastorage.com%2Fservices%2Feditor-elements%2F1.13479.0%22%7D%5D&remoteWidgetStructureBuilderVersion=1.251.0&siteId=764af87f-7048-457d-b8ff-a1e5f9e286c6&siteRevision=3&staticHTMLComponentUrl=https%3A%2F%2Frurfifv-wixstudio-com.filesusr.com%2F&useSandboxInHTMLComp=true&viewMode=desktop HTTP/1.1Host: siteassets.parastorage.comConnection: keep-aliveOrigin: https://rurfifv.wixstudio.comsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36s |