Windows Analysis Report Lancasterco ACH.pdf

Overview

General Information

Sample Name: Lancasterco ACH.pdf
Analysis ID: 491125
MD5: 451a5c0b8c06e886cc6efafad1f82a61
SHA1: 70cd2a072bace392f0e7f6272bea7a823d32565d
SHA256: e3a79f3177849335cefa8b520a94b086627e38502c8fa079a941319df68f8b4a
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish7
Potential document exploit detected (unknown TCP traffic)
Found iframes
No HTML title found
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
HTML body contains low number of good links
Potential document exploit detected (performs HTTP gets)
IP address seen in connection with other malware

Classification

Phishing:

barindex
Yara detected HtmlPhish7
Source: Yara match File source: 96078.0.pages.csv, type: HTML
Found iframes
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: Iframe src: https://c.salesforce.com/login-messages/promos.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: Iframe src: https://login.salesforce.com/login/sessionserver212.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: Iframe src: https://c.salesforce.com/login-messages/promos.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: Iframe src: https://login.salesforce.com/login/sessionserver212.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP Parser: Iframe src: https://c.salesforce.com/login-messages/promos.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP Parser: Iframe src: https://login.salesforce.com/login/sessionserver212.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP Parser: Iframe src: https://c.salesforce.com/login-messages/promos.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP Parser: Iframe src: https://login.salesforce.com/login/sessionserver212.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP Parser: Iframe src: https://c.salesforce.com/login-messages/promos.html
Source: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP Parser: Iframe src: https://login.salesforce.com/login/sessionserver212.html
No HTML title found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: HTML title missing
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: HTML title missing
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP Parser: HTML title missing
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP Parser: HTML title missing
Source: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP Parser: HTML title missing
HTML body contains low number of good links
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: Number of links: 1
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: Number of links: 1
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP Parser: Number of links: 1
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP Parser: Number of links: 1
Source: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP Parser: Number of links: 1
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: No <meta name="author".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: No <meta name="author".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP Parser: No <meta name="author".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP Parser: No <meta name="author".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP Parser: No <meta name="author".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: No <meta name="copyright".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP Parser: No <meta name="copyright".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP Parser: No <meta name="copyright".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP Parser: No <meta name="copyright".. found
Source: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\6096_187113444\LICENSE.txt Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown HTTPS traffic detected: 50.31.81.143:443 -> 192.168.2.3:49900 version: TLS 1.2
Source: unknown HTTPS traffic detected: 50.31.81.143:443 -> 192.168.2.3:49901 version: TLS 1.2

Software Vulnerabilities:

barindex
Potential document exploit detected (unknown TCP traffic)
Source: global traffic TCP traffic: 192.168.2.3:49833 -> 50.31.81.143:443
Potential document exploit detected (performs DNS queries)
Source: global traffic DNS query: name: academicspecialties.com
Potential document exploit detected (performs HTTP gets)
Source: global traffic TCP traffic: 192.168.2.3:49833 -> 50.31.81.143:443

Networking:

barindex
JA3 SSL client fingerprint seen in connection with other malware
Source: Joe Sandbox View JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
IP address seen in connection with other malware
Source: Joe Sandbox View IP Address: 104.20.185.68 104.20.185.68
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49863
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49862
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49861
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49860
Source: unknown Network traffic detected: HTTP traffic on port 49926 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49949 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49875 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50061
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50063
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50062
Source: unknown Network traffic detected: HTTP traffic on port 50045 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50125 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49859
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49857
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49976
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49854
Source: unknown Network traffic detected: HTTP traffic on port 49841 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49975
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49853
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49974
Source: unknown Network traffic detected: HTTP traffic on port 50085 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49950 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49973
Source: unknown Network traffic detected: HTTP traffic on port 49996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50039 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49850
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50065
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50064
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50069
Source: unknown Network traffic detected: HTTP traffic on port 49915 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49943 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49886 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49846
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49845
Source: unknown Network traffic detected: HTTP traffic on port 49869 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49844
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49843
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49842
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49841
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49840
Source: unknown Network traffic detected: HTTP traffic on port 50015 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50040 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49834 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49933 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50085
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49959
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49836
Source: unknown Network traffic detected: HTTP traffic on port 49921 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49834
Source: unknown Network traffic detected: HTTP traffic on port 49887 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49833
Source: unknown Network traffic detected: HTTP traffic on port 50062 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49950
Source: unknown Network traffic detected: HTTP traffic on port 49927 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50087
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50086
Source: unknown Network traffic detected: HTTP traffic on port 49870 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50089
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50088
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49853 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50090
Source: unknown Network traffic detected: HTTP traffic on port 49938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50023 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49949
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49948
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49945
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49943
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50018
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50017
Source: unknown Network traffic detected: HTTP traffic on port 50061 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49922 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50019
Source: unknown Network traffic detected: HTTP traffic on port 49945 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49974 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50017 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49836 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50012
Source: unknown Network traffic detected: HTTP traffic on port 50090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50137
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50015
Source: unknown Network traffic detected: HTTP traffic on port 49939 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50140
Source: unknown Network traffic detected: HTTP traffic on port 49845 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49868 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49885 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49897
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49896
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49895
Source: unknown Network traffic detected: HTTP traffic on port 49862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49894
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50020
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50023
Source: unknown Network traffic detected: HTTP traffic on port 49897 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49879 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49911 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49889
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49888
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49887
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49886
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50039
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49885
Source: unknown Network traffic detected: HTTP traffic on port 49863 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49884
Source: unknown Network traffic detected: HTTP traffic on port 50038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49840 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49880
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50038
Source: unknown Network traffic detected: HTTP traffic on port 49896 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50041
Source: unknown Network traffic detected: HTTP traffic on port 50137 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50040
Source: unknown Network traffic detected: HTTP traffic on port 50066 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50089 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49879
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49878
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49877
Source: unknown Network traffic detected: HTTP traffic on port 49973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49875
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49874
Source: unknown Network traffic detected: HTTP traffic on port 49923 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49872
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49993
Source: unknown Network traffic detected: HTTP traffic on port 50016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49992
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49870
Source: unknown Network traffic detected: HTTP traffic on port 49917 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50045
Source: unknown Network traffic detected: HTTP traffic on port 49874 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49880 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49934 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49846 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49869
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49868
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49867
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49866
Source: unknown Network traffic detected: HTTP traffic on port 50042 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49878 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49912 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49935 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49906 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49900 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49889 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49866 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49975 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49872 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49861 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49901 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50088 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49924 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49844 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49918 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49850 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49992 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50020 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50003
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50124
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50002
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50123
Source: unknown Network traffic detected: HTTP traffic on port 49895 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50125
Source: unknown Network traffic detected: HTTP traffic on port 49913 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50065 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49867 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49842 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49859 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49894 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50003 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49833 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49939
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49938
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49937
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49936
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49935
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49934
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49933
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49932
Source: unknown Network traffic detected: HTTP traffic on port 50087 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49931
Source: unknown Network traffic detected: HTTP traffic on port 49925 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50064 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50123 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49919 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49936 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49929
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49928
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49927
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49926
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49925
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49924
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49923
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49922
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49921
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49920
Source: unknown Network traffic detected: HTTP traffic on port 50086 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50063 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49976 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50124 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50019 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49877 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49854 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49914 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49908 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49919
Source: unknown Network traffic detected: HTTP traffic on port 49937 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49918
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49917
Source: unknown Network traffic detected: HTTP traffic on port 49860 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49916
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49915
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49914
Source: unknown Network traffic detected: HTTP traffic on port 50140 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49913
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49912
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49911
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 49948 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50041 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49843 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49931 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49959 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50002 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49909
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49908
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49906
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49993 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49903
Source: unknown Network traffic detected: HTTP traffic on port 49903 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49901
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49900
Source: unknown Network traffic detected: HTTP traffic on port 50069 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49888 -> 443
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 27 Sep 2021 06:48:50 GMTServer: ApacheLink: <https://www.academicspecialties.com/wp-json/>; rel="https://api.w.org/"Expires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidatePragma: no-cacheSet-Cookie: PHPSESSID=d3d71538f587b37181bae5121f2f0984; path=/Vary: Accept-EncodingConnection: closeTransfer-Encoding: chunkedContent-Type: text/html; charset=UTF-8
Source: Ruleset Data.27.dr String found in binary or memory: www.facebook.com equals www.facebook.com (Facebook)
Source: Ruleset Data.27.dr String found in binary or memory: www.facebook.com/ajax/ads/ equals www.facebook.com (Facebook)
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://cipa.jp/exif/1.0/
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://cipa.jp/exif/1.0/)4FWA
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://cipa.jp/exif/1.0/)5)
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://iptc.org/std/Iptc4xmpExt/2008-02-29/
Source: 5effe8c8d0ac83de_0.27.dr String found in binary or memory: http://momentjs.com/guides/#/warnings/define-locale/
Source: 5effe8c8d0ac83de_0.27.dr String found in binary or memory: http://momentjs.com/guides/#/warnings/dst-shifted/
Source: 5effe8c8d0ac83de_0.27.dr String found in binary or memory: http://momentjs.com/guides/#/warnings/js-date/
Source: 5effe8c8d0ac83de_0.27.dr String found in binary or memory: http://momentjs.com/guides/#/warnings/min-max/
Source: 5effe8c8d0ac83de_0.27.dr String found in binary or memory: http://momentjs.com/guides/#/warnings/zone/
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://ns.useplus.org/ldf/xmp/1.0/
Source: AcroRd32.exe, 00000003.00000000.423107055.000000000C1F0000.00000004.00000001.sdmp String found in binary or memory: http://www.adobe.co
Source: AcroRd32.exe, 00000003.00000000.423107055.000000000C1F0000.00000004.00000001.sdmp String found in binary or memory: http://www.adobe.wgbGg
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/extension/
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/field#
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/id/
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/id/9FPA
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/property#
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/schema#
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfa/ns/type#
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfe/ns/id/
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfe/ns/id/LA
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.aiim.org/pdfe/ns/id/eA
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.npes.org/pdfx/ns/id/
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.npes.org/pdfx/ns/id/oF
Source: AcroRd32.exe, 00000003.00000000.423280195.000000000C287000.00000004.00000001.sdmp String found in binary or memory: http://www.npes.org/pdfx/ns/id/pF
Source: AcroRd32.exe, 00000003.00000000.416794147.0000000008AC8000.00000004.00000001.sdmp String found in binary or memory: http://www.quicktime.com.Acrobat
Source: b9c75506a902b848_0.27.dr String found in binary or memory: http://www.sfdcstatic.com
Source: AcroRd32.exe, 00000003.00000000.423107055.000000000C1F0000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/
Source: AcroRd32.exe, 00000003.00000000.417033096.0000000008F10000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
Source: AcroRd32.exe, 00000003.00000000.423107055.000000000C1F0000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/4
Source: AcroRd32.exe, 00000003.00000000.417033096.0000000008F10000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/Q
Source: AcroRd32.exe, 00000003.00000000.423107055.000000000C1F0000.00000004.00000001.sdmp String found in binary or memory: https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/bx
Source: 7c1fa4b4cd26e559_0.27.dr String found in binary or memory: https://a.sfdcstatic.com/enterprise/salesforce/prod/6140/v14/oneTrust/scripttemplates/6.14.0/otBanne
Source: 2c1c3f577491ced9_0.27.dr String found in binary or memory: https://a.sfdcstatic.com/enterprise/salesforce/prod/6140/v14/oneTrust/scripttemplates/otSDKStub.js
Source: 2c1c3f577491ced9_0.27.dr String found in binary or memory: https://a.sfdcstatic.com/enterprise/salesforce/prod/6140/v14/oneTrust/scripttemplates/otSDKStub.jsaD
Source: History.27.dr String found in binary or memory: https://academicspecialties.com/donna.sinclair
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, manifest.json0.27.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://accounts.google.com
Source: AcroRd32.exe, 00000003.00000000.407456503.000000000A9CA000.00000004.00000001.sdmp String found in binary or memory: https://api.echosign.com
Source: AcroRd32.exe, 00000003.00000000.407456503.000000000A9CA000.00000004.00000001.sdmp String found in binary or memory: https://api.echosign.com1
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, manifest.json0.27.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://apis.google.com
Source: e6fe6c6372db60ee_0.27.dr String found in binary or memory: https://beyondcore.com
Source: 000003.log4.27.dr String found in binary or memory: https://c.salesforce.com
Source: Current Session.27.dr String found in binary or memory: https://c.salesforce.com$
Source: 000003.log0.27.dr String found in binary or memory: https://c.salesforce.com/
Source: History.27.dr String found in binary or memory: https://c.salesforce.com/login-messages/promos.html
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.27.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://content-autofill.googleapis.com
Source: manifest.json0.27.dr String found in binary or memory: https://content.googleapis.com
Source: 7c1fa4b4cd26e559_0.27.dr String found in binary or memory: https://cookiepedia.co.uk/host/.app.onetrust.com?_ga=2.157675898.1572084395.1556120090-1266459230.15
Source: Reporting and NEL.29.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/static-on-bigtable
Source: 55e35d2a-499b-447f-bdda-099d3b41be65.tmp.29.dr, 87e46709-02f2-40ab-a8bd-b759d3a4f54e.tmp.29.dr, 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://dns.google
Source: History.27.dr String found in binary or memory: https://eu6.lightning.force.com/services/walkthrough?path=%2Fone%2Fone.app%23%2Fhome&tour=visualize-
Source: History.27.dr String found in binary or memory: https://eu6.lightning.force.com/services/walkthrough?path=%2Fone%2Fone.app%23%2FsObject%2FOpportunit
Source: Favicons.27.dr String found in binary or memory: https://eu6.lightning.force.com/setup/dataImport.app
Source: History.27.dr String found in binary or memory: https://eu6.lightning.force.com/setup/dataImport.appLogin
Source: Favicons.27.dr String found in binary or memory: https://eu6.lightning.force.com/setup/dataImport.appv
Source: manifest.json0.27.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.27.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.27.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.27.dr String found in binary or memory: https://hangouts.google.com/
Source: e6fe6c6372db60ee_0.27.dr String found in binary or memory: https://hosted-scratch.herokuapp.com/trial
Source: AcroRd32.exe, 00000003.00000000.417033096.0000000008F10000.00000004.00000001.sdmp String found in binary or memory: https://ims-na1.adobelogin.com
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com#
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com$
Source: Network Action Predictor.27.dr String found in binary or memory: https://login.salesforce.com/
Source: Favicons-journal.27.dr, Current Session.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx
Source: History Provider Cache.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx2
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfxLogi
Source: Favicons-journal.27.dr, Current Session.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx
Source: History Provider Cache.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx2
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxLogi
Source: Favicons.27.dr, Current Session.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfxL
Source: Favicons.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfxz
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage
Source: Favicons.27.dr String found in binary or memory: https://login.salesforce.com/favicon.ico
Source: 94fddef1b0339217_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/LoginHint208.js
Source: 94fddef1b0339217_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/LoginHint208.jsaD
Source: ddd1cbf077568839_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/SessionServer212.js
Source: ddd1cbf077568839_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/SessionServer212.jsaD
Source: 5081f25ed54cb224_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/SfdcSessionBase208.js
Source: 5081f25ed54cb224_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/SfdcSessionBase208.jsa
Source: 5081f25ed54cb224_0.27.dr String found in binary or memory: https://login.salesforce.com/jslibrary/SfdcSessionBase208.jsaD
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com/login/sessionserver212.html
Source: 59e378a60cad8646_0.27.dr String found in binary or memory: https://login.salesforce.com/marketing/survey/survey1/1386
Source: 59e378a60cad8646_0.27.dr String found in binary or memory: https://login.salesforce.com/marketing/survey/survey1/1386aD
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=collaborate-on-deals-sfx#/sObject/Opportunity/home
Source: History Provider Cache.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=collaborate-on-deals-sfx#/sObject/Opportunity/home2
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=collaborate-on-deals-sfx#/sObject/Opportunity/homeL
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=collaborate-on-deals-sfx#/sObject/Opportunity/homeLogi
Source: Favicons-journal.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=collaborate-on-deals-sfx#/sObject/Opportunity/homee
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=manage-your-pipeline-sfx#/sObject/Opportunity/home
Source: History Provider Cache.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=manage-your-pipeline-sfx#/sObject/Opportunity/home2
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=manage-your-pipeline-sfx#/sObject/Opportunity/homeLogi
Source: Favicons-journal.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=manage-your-pipeline-sfx#/sObject/Opportunity/homee
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=visualize-your-business-sfx#/home
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=visualize-your-business-sfx#/homeLogin
Source: Favicons.27.dr String found in binary or memory: https://login.salesforce.com/one/one.app?tour=visualize-your-business-sfx#/homeh
Source: History.27.dr String found in binary or memory: https://login.salesforce.com/s.gif
Source: Current Session.27.dr String found in binary or memory: https://login.salesforce.comh
Source: 5effe8c8d0ac83de_0.27.dr String found in binary or memory: https://momentjs.com/timezone/docs/#/use-it/browser/
Source: Current Session.27.dr String found in binary or memory: https://na68.salesforce.com
Source: History.27.dr String found in binary or memory: https://na68.salesforce.com/services/walkthrough?path=%2Fone%2Fone.app%23%2Fhome&tour=visualize-your
Source: History.27.dr String found in binary or memory: https://na68.salesforce.com/services/walkthrough?path=%2Fone%2Fone.app%23%2FsObject%2FOpportunity%2F
Source: Current Session.27.dr String found in binary or memory: https://na68.salesforce.com/ui/setup/dataimporter/DataImporterLandingPage
Source: History.27.dr String found in binary or memory: https://na68.salesforce.com/ui/setup/dataimporter/DataImporterLandingPageLogin
Source: Favicons.27.dr String found in binary or memory: https://na68.salesforce.com/ui/setup/dataimporter/DataImporterLandingPagei
Source: Current Session.27.dr String found in binary or memory: https://na68.salesforce.com/ui/setup/dataimporter/DataImporterLandingPage~(
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.27.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://play.google.com
Source: e6fe6c6372db60ee_0.27.dr String found in binary or memory: https://quip.com
Source: 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://r5---sn-1gieen7e.gvt1.com
Source: 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://redirector.gvt1.com
Source: e6fe6c6372db60ee_0.27.dr String found in binary or memory: https://salesforce.com
Source: 00886dd6f2065849_0.27.dr, bc7c51ee3e045af3_0.27.dr String found in binary or memory: https://salesforce.com/
Source: 87d623e4c97a1d1a_0.27.dr String found in binary or memory: https://salesforce.com/$9
Source: bc7c51ee3e045af3_0.27.dr String found in binary or memory: https://salesforce.com/1
Source: 93bbeae5ab81f683_0.27.dr String found in binary or memory: https://salesforce.com/2
Source: 76ee4096122e6e7d_0.27.dr String found in binary or memory: https://salesforce.com/2fpQ
Source: a4c32e3173c56e42_0.27.dr String found in binary or memory: https://salesforce.com/D
Source: 3246e51d8c77b25d_0.27.dr String found in binary or memory: https://salesforce.com/J_
Source: 59e378a60cad8646_0.27.dr String found in binary or memory: https://salesforce.com/R3bQ
Source: 94fddef1b0339217_0.27.dr String found in binary or memory: https://salesforce.com/Y_
Source: b3a3e0621c6f8243_0.27.dr String found in binary or memory: https://salesforce.com/m
Source: ba5945cf2871a133_0.27.dr String found in binary or memory: https://salesforce.com/v
Source: manifest.json.27.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://ssl.gstatic.com
Source: 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://stats.g.doubleclick.net
Source: messages.json49.27.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json49.27.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://www.google-analytics.com
Source: 93bbeae5ab81f683_0.27.dr String found in binary or memory: https://www.google-analytics.com/analytics.js
Source: 3246e51d8c77b25d_0.27.dr String found in binary or memory: https://www.google-analytics.com/plugins/ua/linkid.js
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, manifest.json0.27.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://www.google.com
Source: manifest.json.27.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.27.dr String found in binary or memory: https://www.google.com;
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.27.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.27.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.27.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.27.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.27.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.27.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://www.googletagmanager.com
Source: bc7c51ee3e045af3_0.27.dr String found in binary or memory: https://www.googletagmanager.com/gtm.js?id=GTM-WRXS6TH
Source: 532b4740-e53c-493a-87da-15be85b1102b.tmp.29.dr, 5a2868fd-cd65-4553-a937-6893afced262.tmp.29.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.27.dr String found in binary or memory: https://www.gstatic.com;
Source: 68b096d014f15c08_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/scriptloader.bundle.31934febe74df094cec9.js
Source: 68b096d014f15c08_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/scriptloader.bundle.31934febe74df094cec9.jsa
Source: bb35eb61b1c75735_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/utils.bundle.31934febe74df094cec9.js
Source: bb35eb61b1c75735_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/utils.bundle.31934febe74df094cec9.jsa
Source: bb35eb61b1c75735_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/utils.bundle.31934febe74df094cec9.jsaD
Source: 76ee4096122e6e7d_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/vendors~scriptloader.bundle.31934febe74df094
Source: 4b3205fb417f84c0_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/vendors~scriptloader~utils.bundle.31934febe7
Source: a4c32e3173c56e42_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/vendors~utils~webpack-script-manifest-SfdcWw
Source: timesi.ttf.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/vendors~webpack-script-manifest-SfdcWwwBaseC
Source: 87d623e4c97a1d1a_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/webpack-script-manifest-commonlyUsed-js.bund
Source: ba5945cf2871a133_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/webpack-script-manifest-commonlyUsed-js~webp
Source: 31e52f4afc5fe51f_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.bundles/sfdc-www/bundles/webpack-script-manifest-config-js.bundle.319
Source: 354ec97347741daf_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.clientlibs/clientlibs/granite/jquery.min.8e23e5ad8c1b5c588cca8d71df0a
Source: 93e4048c01583079_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.clientlibs/clientlibs/granite/jquery/granite.min.e67470fde615e2d442e0
Source: b012c3ddd10ba66c_0.27.dr String found in binary or memory: https://www.salesforce.com/etc.clientlibs/clientlibs/granite/utils.min.308082b4c347f4fec37ffef277d39
Source: daf071074f583402_0.27.dr String found in binary or memory: https://www.salesforce.com/etc/clientlibs/granite/lodash/modern.min.3a0ad4c7614495b1cae264dfcb9b9813
Source: ec73f250b8d2251b_0.27.dr String found in binary or memory: https://www.salesforce.com/etc/clientlibs/sfdc-aem-master/clientlibs_analytics_login_bottom.min.166e
Source: b9c75506a902b848_0.27.dr String found in binary or memory: https://www.salesforce.com/etc/clientlibs/sfdc-aem-master/clientlibs_analytics_login_top.min.5a21823
Source: b215239729a62c6e_0.27.dr String found in binary or memory: https://www.salesforce.com/etc/clientlibs/sfdc-aem-master/clientlibs_www_tags.min.49c634c0df8e725801
Source: unknown HTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknown DNS traffic detected: queries for: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/ HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/normalize.css HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/app.css HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/WalkthroughCoreUIAura.css HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/OneDesktop.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/libs_Europe-Dublin.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/ckeditor.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/aura_prod.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/app.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/WalkthroughOneDesktop.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/CordaPopChart.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/CanvasRendering.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/sfx_trials_v2.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/case_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/salesforce-logo-sfxHeader.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/app.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/file_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/dashboard_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/report_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/account_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/event_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/groups_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/note_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/draggable.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/logo3.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /img/salesforce-logo-sfxHeader.png HTTP/1.1Host: www.academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/app.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/logo2.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/logo1.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/user_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/contact_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/feed_60.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/T.txt HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/home_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/opportunity_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/lead_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/task_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/landmark_spinner_1589EE.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/news_60.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/resize.txt HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/embedly-powered-small-light.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/default_120.png HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/T.txt HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/sfx_trials_v2.html HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/home_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/opportunity_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/lead_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/task_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/file_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/note_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/account_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/contact_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/dashboard_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/report_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /services/walkthrough?path=%2Fone%2Fone.app%23%2FsObject%2FOpportunity%2Fhome&tour=manage-your-pipeline-sfx HTTP/1.1Host: eu6.lightning.force.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/feed_60.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/groups_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/event_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /services/walkthrough?path=%2Fone%2Fone.app%23%2FsObject%2FOpportunity%2Fhome&tour=manage-your-pipeline-sfx HTTP/1.1Host: na68.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/user_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /one/one.app?tour=manage-your-pipeline-sfx HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA
Source: global traffic HTTP traffic detected: GET /?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfx HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://login.salesforce.com/one/one.app?tour=manage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/case_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /css/sfdc_210.css HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /jslibrary/SfdcSessionBase208.js HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /jslibrary/LoginHint208.js HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/landmark_spinner_1589EE.html HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /s.gif HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /jslibrary/baselogin.js HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /marketing/survey/survey1/1386 HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /marketing/survey/survey4/1386 HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /img/logo214.svg HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /img/clear.png HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /login/sessionserver212.html HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /login/assets/fonts/SalesforceSans/SalesforceSans-Regular.woff2 HTTP/1.1Host: login.salesforce.comConnection: keep-aliveOrigin: https://login.salesforce.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://login.salesforce.com/css/sfdc_210.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /jslibrary/SessionServer212.js HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/login/sessionserver212.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/news_60.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /img/icon/capslock_blue.png HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n; session=1632757736265
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/resize.txt HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/embedly-powered-small-light.html HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /cookieconsentpub/v1/geo/location HTTP/1.1Host: geolocation.onetrust.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://c.salesforce.com/login-messages/promos.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /gtm.js?id=GTM-WRXS6TH HTTP/1.1Host: www.googletagmanager.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://c.salesforce.com/login-messages/promos.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/default_120.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/logo1.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/draggable.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /analytics.js HTTP/1.1Host: www.google-analytics.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://c.salesforce.com/login-messages/promos.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/logo3.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/index_files/logo2.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: academicspecialties.com
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dmanage-your-pipeline-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n; session=1632757736265; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757736868%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A1%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1
Source: global traffic HTTP traffic detected: GET /services/walkthrough?path=%2Fone%2Fone.app%23%2FsObject%2FOpportunity%2Fhome&tour=collaborate-on-deals-sfx HTTP/1.1Host: eu6.lightning.force.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CookieConsentPolicy=0:0; BrowserId=-4i00B9eEeyEpC1ql1PF-w; BrowserId_sec=-4i00B9eEeyEpC1ql1PF-w
Source: global traffic HTTP traffic detected: GET /services/walkthrough?path=%2Fone%2Fone.app%23%2FsObject%2FOpportunity%2Fhome&tour=collaborate-on-deals-sfx HTTP/1.1Host: na68.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CookieConsentPolicy=0:0; BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757736868%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A1%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1
Source: global traffic HTTP traffic detected: GET /one/one.app?tour=collaborate-on-deals-sfx HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n; session=1632757736265; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757736868%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A1%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1
Source: global traffic HTTP traffic detected: GET /?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfx HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://login.salesforce.com/one/one.app?tour=collaborate-on-deals-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; QCQQ=aRZNOovql5n; session=1632757736265; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757736868%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A1%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1
Source: global traffic HTTP traffic detected: GET /marketing/survey/survey4/1386 HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dcollaborate-on-deals-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; session=1632757736265; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757736868%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A1%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; QCQQ=aWtK8aZOEf1
Source: global traffic HTTP traffic detected: GET /l/%7B%22mode%22%3A%22PROD%22%2C%22app%22%3A%22one%3Aone%22%7D/app.manifest HTTP/1.1Host: academicspecialties.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheSec-Fetch-Dest: emptySec-Fetch-Site: same-originSec-Fetch-Mode: no-corsUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cookieconsentpub/v1/geo/location HTTP/1.1Host: geolocation.onetrust.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://c.salesforce.com/login-messages/promos.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /services/walkthrough?path=%2Fone%2Fone.app%23%2Fhome&tour=visualize-your-business-sfx HTTP/1.1Host: eu6.lightning.force.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CookieConsentPolicy=0:0; BrowserId=-4i00B9eEeyEpC1ql1PF-w; BrowserId_sec=-4i00B9eEeyEpC1ql1PF-w
Source: global traffic HTTP traffic detected: GET /services/walkthrough?path=%2Fone%2Fone.app%23%2Fhome&tour=visualize-your-business-sfx HTTP/1.1Host: na68.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CookieConsentPolicy=0:0; BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757741582%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A2%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D
Source: global traffic HTTP traffic detected: GET /one/one.app?tour=visualize-your-business-sfx HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; session=1632757736265; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; QCQQ=aWtK8aZOEf1; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757741582%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A2%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D
Source: global traffic HTTP traffic detected: GET /?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfx HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://login.salesforce.com/one/one.app?tour=visualize-your-business-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; session=1632757736265; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; QCQQ=aWtK8aZOEf1; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757741582%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A2%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D
Source: global traffic HTTP traffic detected: GET /marketing/survey/survey4/1386 HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fone%2Fone.app%3Ftour%3Dvisualize-your-business-sfxAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; session=1632757736265; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757741582%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A2%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; QCQQ=QdgsbG8ieRd
Source: global traffic HTTP traffic detected: GET /cookieconsentpub/v1/geo/location HTTP/1.1Host: geolocation.onetrust.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://c.salesforce.com/login-messages/promos.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /setup/dataImport.app HTTP/1.1Host: eu6.lightning.force.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CookieConsentPolicy=0:0; BrowserId=-4i00B9eEeyEpC1ql1PF-w; BrowserId_sec=-4i00B9eEeyEpC1ql1PF-w
Source: global traffic HTTP traffic detected: GET /ui/setup/dataimporter/DataImporterLandingPage HTTP/1.1Host: na68.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CookieConsentPolicy=0:0; BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757745507%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A3%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D
Source: global traffic HTTP traffic detected: GET /?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPage HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://na68.salesforce.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; session=1632757736265; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; QCQQ=QdgsbG8ieRd; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757745507%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A3%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D
Source: global traffic HTTP traffic detected: GET /marketing/survey/survey4/1386 HTTP/1.1Host: login.salesforce.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://login.salesforce.com/?ec=302&startURL=%2Fui%2Fsetup%2Fdataimporter%2FDataImporterLandingPageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BrowserId=_AAvjR9eEeyALDdjQctwsA; BrowserId_sec=_AAvjR9eEeyALDdjQctwsA; CookieConsentPolicy=0:0; session=1632757736265; _ga=GA1.2.1520051098.1632757739; _gid=GA1.2.475211006.1632757739; _dc_gtm_UA-140200881-1=1; webact=%7B%22l_vdays%22%3A-1%2C%22l_visit%22%3A0%2C%22session%22%3A1632757745507%2C%22l_search%22%3A%22%22%2C%22l_dtype%22%3A%22%22%2C%22l_page%22%3A%22SFDC%3Aus%3Alogin%22%2C%22counter%22%3A0%2C%22pv%22%3A3%2C%22f_visit%22%3A1632757736868%2C%22seg%22%3A%22non-customer%3Aus%22%7D; QCQQ=BEAjRMTVBNk
Source: global traffic HTTP traffic detected: GET /cookieconsentpub/v1/geo/location HTTP/1.1Host: geolocation.onetrust.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://c.salesforce.com/login-messages/promos.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/AOL/index.html HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/AOL/index_files/jquery-1.js HTTP/1.1Host: academicspecialties.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/AOL/index.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknown HTTPS traffic detected: 50.31.81.143:443 -> 192.168.2.3:49900 version: TLS 1.2
Source: unknown HTTPS traffic detected: 50.31.81.143:443 -> 192.168.2.3:49901 version: TLS 1.2
Source: unknown Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe' 'C:\Users\user\Desktop\Lancasterco ACH.pdf'
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe' --type=renderer /prefetch:1 'C:\Users\user\Desktop\Lancasterco ACH.pdf'
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --backgroundcolor=16514043
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=4954877018297627744 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4954877018297627744 --renderer-client-id=2 --mojo-platform-channel-handle=1680 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=gpu-process --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --lang=en-US --gpu-preferences=KAAAAAAAAACAAwABAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --service-request-channel-token=15208834074062776787 --mojo-platform-channel-handle=1716 --allow-no-sandbox-job --ignored=' --type=renderer ' /prefetch:2
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=10669955719412199126 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10669955719412199126 --renderer-client-id=4 --mojo-platform-channel-handle=1948 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=1783107525517420690 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1783107525517420690 --renderer-client-id=5 --mojo-platform-channel-handle=1964 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=15708677220669339044 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15708677220669339044 --renderer-client-id=6 --mojo-platform-channel-handle=1684 --allow-no-sandbox-job /prefetch:1
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation -- 'https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1640,13240203582171384239,7486404495160465890,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1664 /prefetch:8
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe' --type=renderer /prefetch:1 'C:\Users\user\Desktop\Lancasterco ACH.pdf' Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --backgroundcolor=16514043 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation -- 'https://academicspecialties.com/donna.sinclair@lancasterco.com_ACHremittance_Open_DocuSignPortal/Docusign%20Global%20Standard%20For%20E%20signature/Docusign%20Global%20Standard%20For%20E%20signature/Profit-maximization/Profit-maximization-2018/' Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=4954877018297627744 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4954877018297627744 --renderer-client-id=2 --mojo-platform-channel-handle=1680 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=gpu-process --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --lang=en-US --gpu-preferences=KAAAAAAAAACAAwABAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --service-request-channel-token=15208834074062776787 --mojo-platform-channel-handle=1716 --allow-no-sandbox-job --ignored=' --type=renderer ' /prefetch:2 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=10669955719412199126 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10669955719412199126 --renderer-client-id=4 --mojo-platform-channel-handle=1948 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=1783107525517420690 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1783107525517420690 --renderer-client-id=5 --mojo-platform-channel-handle=1964 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process created: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe' --type=renderer --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --touch-events=enabled --field-trial-handle=1692,14879723834213895979,17034890756822317782,131072 --disable-features=VizDisplayCompositor --disable-gpu-compositing --service-pipe-token=15708677220669339044 --lang=en-US --disable-pack-loading --log-file='C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log' --log-severity=disable --product-version='ReaderServices/19.12.20035 Chrome/80.0.0.0' --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15708677220669339044 --renderer-client-id=6 --mojo-platform-channel-handle=1684 --allow-no-sandbox-job /prefetch:1 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1640,13240203582171384239,7486404495160465890,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1664 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File created: C:\Users\user\AppData\Local\Temp\acrord32_sbx\A9Rm46i8j_1pottyb_4y4.tmp Jump to behavior
Source: classification engine Classification label: mal48.phis.winPDF@58/302@21/16
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe File opened: C:\Windows\SysWOW64\Msftedit.dll Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: Lancasterco ACH.pdf Initial sample: PDF keyword /JS count = 0
Source: Lancasterco ACH.pdf Initial sample: PDF keyword /JavaScript count = 0
Source: Lancasterco ACH.pdf Initial sample: PDF keyword /EmbeddedFile count = 0
Source: Lancasterco ACH.pdf Initial sample: PDF keyword stream count = 25
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\6096_187113444\LICENSE.txt Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: AcroRd32.exe, 00000003.00000000.398936501.000000000C2E3000.00000004.00000001.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: AcroRd32.exe, 00000003.00000000.389192557.0000000005410000.00000002.00020000.sdmp Binary or memory string: Program Manager
Source: AcroRd32.exe, 00000003.00000000.389192557.0000000005410000.00000002.00020000.sdmp Binary or memory string: Shell_TrayWnd
Source: AcroRd32.exe, 00000003.00000000.389192557.0000000005410000.00000002.00020000.sdmp Binary or memory string: Progman
Source: AcroRd32.exe, 00000003.00000000.389192557.0000000005410000.00000002.00020000.sdmp Binary or memory string: Progmanlock
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs