Windows Analysis Report http://eprocurement.corona.com.co/eprocurement2/#/login/

Overview

General Information

Sample URL: http://eprocurement.corona.com.co/eprocurement2/#/login/
Analysis ID: 468973
Infos:

Most interesting Screenshot:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
HTML body contains low number of good links
Found iframes
None HTTPS page querying sensitive user data (password, username or email)
No HTML title found

Classification

Phishing:

barindex
HTML body contains low number of good links
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Number of links: 0
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Number of links: 0
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Number of links: 0
Found iframes
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Iframe src: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfV28YUAAAAAEkBQPmRvpzmlv9FyzeW-77R00r1&co=aHR0cDovL2Vwcm9jdXJlbWVudC5jb3JvbmEuY29tLmNvOjgw&hl=en&v=Eyd0Dt8h04h7r-D86uAD1JP-&size=normal&cb=qgk7owpuiqey
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Iframe src: https://www.google.com/recaptcha/api2/bframe?hl=en&v=Eyd0Dt8h04h7r-D86uAD1JP-&k=6LfV28YUAAAAAEkBQPmRvpzmlv9FyzeW-77R00r1&cb=610xzjr4baok
None HTTPS page querying sensitive user data (password, username or email)
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Has password / email / username input fields
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Has password / email / username input fields
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: Has password / email / username input fields
No HTML title found
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: HTML title missing
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: HTML title missing
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: HTML title missing
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: No <meta name="author".. found
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: No <meta name="author".. found
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: No <meta name="author".. found
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: No <meta name="copyright".. found
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: No <meta name="copyright".. found
Source: http://eprocurement.corona.com.co/eprocurement2/#/login HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Source: Traffic Snort IDS: 1200 ATTACK-RESPONSES Invalid URL 200.32.81.196:80 -> 192.168.2.5:49707
Source: Traffic Snort IDS: 1564 WEB-MISC login.htm access 192.168.2.5:49715 -> 200.32.81.196:80
Source: unknown DNS traffic detected: queries for: eprocurement.corona.com.co
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: global traffic HTTP traffic detected: GET /eprocurement2/ HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/bootstrap/dist/css/bootstrap.css HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/styles/main.css HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/fonts/walkway/walkwaysemibold_regular_macroman/stylesheet.css HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/fonts/walkway/walkwayultrabold_regular_macroman/stylesheet.css HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/ng-grid/ng-grid.min.css HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/styles/ng-table.css HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular/angular.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-resource/angular-resource.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-route/angular-route.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-cookies/angular-cookies.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-animate/angular-animate.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-bootstrap/ui-bootstrap.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-bootstrap/ui-bootstrap-tpls.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-sanitize/angular-sanitize.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/angular-recaptcha/angular-recaptcha.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/jquery/dist/jquery.min.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/bower_components/ng-grid/ng-grid-2.0.11.min.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/ng-table.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/table2excel.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/app.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/services/loginServ.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/services/lenguajeServ.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/services/docsHomeSrv.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/services/exportExcel.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/services/comParams.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/services/portafolioSrv.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/prehomeCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/loginCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/forgotpasswCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/homeCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/lenguajeCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/menuTopCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/menuLatCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/portafolioCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/ordenesCompradorCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/ordenesProveedorCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/documentosCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/proyeccionesCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/cetificadosCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/pagosCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/facturasCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/controllers/configuracionCtrl.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/centroFilterDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/proveedoresFilterDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/productosFilterDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/onlyNumberInputDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/comentariosDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/sociedadesFilterDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/estadosFilterDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/documentosTiposDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/documentosClasesDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/sociedadesTodasFilterDir.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/scripts/directives/upload.js HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/views/login.html HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveAccept: application/json, text/plain, */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /eprocurement2/views/preMenutop.html HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveAccept: application/json, text/plain, */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ASP.NET_SessionId=jr1zvcir2xlp1ypg24bsl4cl
Source: global traffic HTTP traffic detected: GET /eprocurement2/images/main-bg.jpg HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Referer: http://eprocurement.corona.com.co/eprocurement2/styles/main.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ASP.NET_SessionId=jr1zvcir2xlp1ypg24bsl4cl
Source: global traffic HTTP traffic detected: GET /images/corona-logo.png HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Referer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ASP.NET_SessionId=jr1zvcir2xlp1ypg24bsl4cl
Source: global traffic HTTP traffic detected: GET /eprocurement2/fonts/walkway/walkwayultrabold_regular_macroman/Walkway_UltraBold-webfont.ttf HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveOrigin: http://eprocurement.corona.com.coUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/fonts/walkway/walkwayultrabold_regular_macroman/stylesheet.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ASP.NET_SessionId=jr1zvcir2xlp1ypg24bsl4cl
Source: global traffic HTTP traffic detected: GET /eprocurement2/fonts/walkway/walkwaysemibold_regular_macroman/Walkway_SemiBold-webfont.ttf HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveOrigin: http://eprocurement.corona.com.coUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Referer: http://eprocurement.corona.com.co/eprocurement2/fonts/walkway/walkwaysemibold_regular_macroman/stylesheet.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: ASP.NET_SessionId=jr1zvcir2xlp1ypg24bsl4cl
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlServer: Microsoft-IIS/10.0X-Powered-By: ASP.NETDate: Fri, 20 Aug 2021 16:10:18 GMTContent-Length: 1245Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 3c 21 2d 2d 0d 0a 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 2d 73 69 7a 65 3a 2e 37 65 6d 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 56 65 72 64 61 6e 61 2c 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 45 45 45 45 45 45 3b 7d 0d 0a 66 69 65 6c 64 73 65 74 7b 70 61 64 64 69 6e 67 3a 30 20 31 35 70 78 20 31 30 70 78 20 31 35 70 78 3b 7d 20 0d 0a 68 31 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 2e 34 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 7d 0d 0a 68 32 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 37 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 43 43 30 30 30 30 3b 7d 20 0d 0a 68 33 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 32 65 6d 3b 6d 61 72 67 69 6e 3a 31 30 70 78 20 30 20 30 20 30 3b 63 6f 6c 6f 72 3a 23 30 30 30 30 30 30 3b 7d 20 0d 0a 23 68 65 61 64 65 72 7b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 30 3b 70 61 64 64 69 6e 67 3a 36 70 78 20 32 25 20 36 70 78 20 32 25 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 74 72 65 62 75 63 68 65 74 20 4d 53 22 2c 20 56 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 0d 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 35 35 35 35 35 3b 7d 0d 0a 23 63 6f 6e 74 65 6e 74 7b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 32 25 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2e 63 6f 6e 74 65 6e 74 2d 63 6f 6e 74 61 69 6e 65 72 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 46 46 46 3b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 38 70 78 3b 70 61 64 64 69 6e 67 3a 31 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2d 2d 3e 0d 0a 3c 2f 73 74 79 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 64 69 76 20 69 64 3d 22 68 65 61 64 65 72 22 3e 3c 68 31 3e 53 65 72 76
Source: 6a3d4ada7613f246_0.0.dr, 0a59411ccc4b0ed8_0.0.dr, 2231ff1cdada9a2f_0.0.dr, db76fdbd76ef7ab6_0.0.dr String found in binary or memory: http://corona.com.co/
Source: cc000dca877bd219_0.0.dr String found in binary or memory: http://corona.com.co/#
Source: 50d8c327cc9b16c2_0.0.dr String found in binary or memory: http://corona.com.co/2
Source: afd52415c46f7d65_0.0.dr String found in binary or memory: http://corona.com.co/5
Source: 6faa21ce20b02be0_0.0.dr String found in binary or memory: http://corona.com.co/?0
Source: bdf4a0be2e2e2ef8_0.0.dr String found in binary or memory: http://corona.com.co/DUt
Source: 4bcaef12224d89ad_0.0.dr, 794ee617f6d43a80_0.0.dr String found in binary or memory: http://corona.com.co/F
Source: a1a37a7ddd282fac_0.0.dr String found in binary or memory: http://corona.com.co/V
Source: 2e383a7b77a2d0e8_0.0.dr String found in binary or memory: http://corona.com.co/l
Source: d41ce6fee838f23e_0.0.dr String found in binary or memory: http://corona.com.co/p
Source: 5bc449652d715a20_0.0.dr String found in binary or memory: http://corona.com.co/w
Source: b30fbbce0e39f2a4_0.0.dr String found in binary or memory: http://corona.com.co/y?o
Source: 43abd6a363bb0730_0.0.dr String found in binary or memory: http://corona.com.co/zB
Source: Current Session.0.dr String found in binary or memory: http://eprocurement.corona.com.co
Source: Current Session.0.dr String found in binary or memory: http://eprocurement.corona.com.co)
Source: Current Session.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/
Source: Current Session.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login
Source: Current Session.0.dr, History.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login/
Source: History-journal.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login//(
Source: History Provider Cache.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login/2
Source: History Provider Cache.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login/2:
Source: History-journal.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login/L
Source: Current Session.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login/W
Source: History Provider Cache.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/login20eprocurement.corona.com.co/eprocurement2/#/
Source: History.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/#/logineprocurement.corona.com.co/eprocurement2/#/lo
Source: 62ebf8d82348c6f3_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-animate/angular-animate.js
Source: bdf4a0be2e2e2ef8_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-bootstrap/ui-bootstrap-tpls
Source: 45c0301a22c48101_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-bootstrap/ui-bootstrap.js
Source: c3660637b286bd55_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-cookies/angular-cookies.js
Source: e057b92807791b95_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-recaptcha/angular-recaptcha
Source: bcaa69e9fbaa0624_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-resource/angular-resource.j
Source: b30fbbce0e39f2a4_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-route/angular-route.js
Source: a1a37a7ddd282fac_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular-sanitize/angular-sanitize.j
Source: 5bc449652d715a20_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/angular/angular.js
Source: 2e383a7b77a2d0e8_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/jquery/dist/jquery.min.js
Source: 09ba7bf61aa7cda7_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/bower_components/ng-grid/ng-grid-2.0.11.min.js
Source: b52452182c4a02ca_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/app.js
Source: 76498fcd216e4695_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/cetificadosCtrl.js
Source: aac23e88c61bf610_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/configuracionCtrl.js
Source: 62f529e6af85dda6_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/documentosCtrl.js
Source: 6faa21ce20b02be0_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/facturasCtrl.js
Source: afd52415c46f7d65_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/forgotpasswCtrl.js
Source: 349424b612e655ad_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/loginCtrl.js
Source: d41ce6fee838f23e_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/menuLatCtrl.js
Source: 41b187d3d01a4e16_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/menuTopCtrl.js
Source: aa32a02aa62c44a3_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/ordenesCompradorCtrl.js
Source: 357bfb670947fc90_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/ordenesProveedorCtrl.js
Source: 020fa3a58dd7fd12_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/pagosCtrl.js
Source: 797a9caff384add5_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/portafolioCtrl.js
Source: 2231ff1cdada9a2f_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/controllers/proyeccionesCtrl.js
Source: eb9c3dced5b8e090_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/centroFilterDir.js
Source: 50d8c327cc9b16c2_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/comentariosDir.js
Source: b4a8bcbb93a4e4e5_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/documentosClasesDir.js
Source: cc000dca877bd219_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/documentosTiposDir.js
Source: 794ee617f6d43a80_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/estadosFilterDir.js
Source: 4bcaef12224d89ad_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/ng-table.js
Source: f225801f932db86c_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/productosFilterDir.js
Source: 26f02519806f8a53_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/proveedoresFilterDir.js
Source: 6a3d4ada7613f246_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/sociedadesFilterDir.js
Source: e6315c838510da6f_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/sociedadesTodasFilterDir.js
Source: a2114d7688ef643a_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/table2excel.js
Source: 43abd6a363bb0730_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/directives/upload.js
Source: 928772b7a97899b7_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/services/docsHomeSrv.js
Source: db76fdbd76ef7ab6_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/services/exportExcel.js
Source: 0a59411ccc4b0ed8_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/services/lenguajeServ.js
Source: ea531e760732cc34_0.0.dr String found in binary or memory: http://eprocurement.corona.com.co/eprocurement2/scripts/services/portafolioSrv.js
Source: Current Session.0.dr String found in binary or memory: http://eprocurement.corona.com.coh
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, manifest.json0.0.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://accounts.google.com
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, manifest.json0.0.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://apis.google.com
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: Reporting and NEL.1.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#localhost_support
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
Source: 7a3371b3-dd91-4c08-a634-005ad4c74745.tmp.1.dr, a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, aca03f44-9320-42a9-9598-381e07d3be91.tmp.1.dr, 98088e5a-5553-43a3-b220-ad5b8627bfbd.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: 3732fd04034f266a_0.0.dr String found in binary or memory: https://google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://support.google.com/recaptcha
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://support.google.com/recaptcha/#6175971
Source: 000003.log5.0.dr, Current Session.0.dr, a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, manifest.json0.0.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://www.google.com
Source: Current Session.0.dr String found in binary or memory: https://www.google.com)
Source: manifest.json.0.dr, 000003.log0.0.dr String found in binary or memory: https://www.google.com/
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://www.google.com/log?format=json&hasfast=true
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://www.google.com/recaptcha/api2/
Source: Current Session.0.dr String found in binary or memory: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfV28YUAAAAAEkBQPmRvpzmlv9FyzeW-77R00r1&co=aHR0
Source: Current Session.0.dr String found in binary or memory: https://www.google.com/recaptcha/api2/bframe?hl=en&v=Eyd0Dt8h04h7r-D86uAD1JP-&k=6LfV28YUAAAAAEkBQPmR
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: Current Session.0.dr String found in binary or memory: https://www.google.comh
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: a02e7421-9bb0-4a4e-abca-3810081b5cc2.tmp.1.dr, 9d75e571-ad05-4ba1-8f5e-d3a62e7b4e22.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: 3732fd04034f266a_0.0.dr, bb8d2b09d1409be0_0.0.dr String found in binary or memory: https://www.gstatic.com/recaptcha/releases/Eyd0Dt8h04h7r-D86uAD1JP-/recaptcha__en.js
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://www.gstatic.com/recaptcha/releases/Eyd0Dt8h04h7r-D86uAD1JP-/recaptcha__en.jsa
Source: 07e369fc32ee1b10_0.0.dr String found in binary or memory: https://www.gstatic.com/recaptcha/releases/Eyd0Dt8h04h7r-D86uAD1JP-/recaptcha__en.jsaD
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown HTTP traffic detected: POST /eprocurement2/Servicios/Parametros.svc/ObtenerOpcionesLenguaje HTTP/1.1Host: eprocurement.corona.com.coConnection: keep-aliveContent-Length: 2Accept: application/json, text/plain, */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Content-Type: application/json;charset=UTF-8Origin: http://eprocurement.corona.com.coReferer: http://eprocurement.corona.com.co/eprocurement2/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Data Raw: 7b 7d Data Ascii: {}
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\f9a10666-e415-49da-b7ba-a2fbe888486f.tmp Jump to behavior
Source: classification engine Classification label: mal48.win@28/254@6/9
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'http://eprocurement.corona.com.co/eprocurement2/#/login/'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1568,7010085048450573434,11052940507831535884,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1692 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1568,7010085048450573434,11052940507831535884,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1692 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: QuotaManager.0.dr Binary or memory string: CREATE TABLE HostQuotaTable(host TEXT NOT NULL, type INTEGER NOT NULL, quota INTEGER DEFAULT 0, UNIQUE(host, type));
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-61205268-1114.pma Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs