Resultaat

Taak-URL: https://my.salviatech.com/

Verdacht niveau: Vermoedelijk gevaarlijk

Beschrijving: Deze pagina vraagt om verdachte acties zoals het kopiëren en uitvoeren van commando's in PowerShell, wat duidt op een mogelijk kwaadaardige intentie.

Statistieken

6 0 6 6 16 3

Screenshot

Screenshot Thumbnail

HTML data

Lengte Actie
13306

DOM data

Lengte Actie
13306

IP adressen

IP Adres Gerelateerd Domein Bron Type
[2606:4700::6811:180e] cdnjs.cloudflare.com Web Request
162.241.216.56 my.salviatech.com Web Request
[2606:4700:3036::6815:1b98] use.fontawesome.com Web Request
[2a00:1450:400e:811::2004] www.google.com Web Request
104.17.25.14 cdnjs.cloudflare.com NSLookup
2606:4700::6811:180e cdnjs.cloudflare.com NSLookup
104.17.24.14 cdnjs.cloudflare.com NSLookup
2606:4700::6811:190e cdnjs.cloudflare.com NSLookup
162.241.216.56 my.salviatech.com NSLookup
2606:4700:3037::ac43:8ef5 use.fontawesome.com NSLookup
172.67.142.245 use.fontawesome.com NSLookup
104.21.27.152 use.fontawesome.com NSLookup
2606:4700:3036::6815:1b98 use.fontawesome.com NSLookup
142.250.179.164 www.google.com NSLookup
172.217.23.196 www.google.com NSLookup
2a00:1450:400e:802::2004 www.google.com NSLookup

Verwijzingen

Requestid Verwijzing Bestemming

Downloads

Bestandsnaam SHA256 | URL
0 Bytes | 406 https://my.salviatech.com/
[email protected] dedcb23076be667a897f4a90bde0bc80c6a6a58cfe68433bde59546eb9b74eb5 18160 Bytes | 200 https://www.google.com/recaptcha/about/images/[email protected]
all.min.css a361e7885c36bacb3fd9cb068da207c3b9329962cac022d06e28923939f575e8 83981 Bytes | 200 https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
all.css 9f29f2bbb25602f4bdbd3122c317244f8fd9741106ffd5a412574b02ee794993 33407 Bytes | 200 https://use.fontawesome.com/releases/v5.0.0/css/all.css
fa-brands-400.woff2 45e39853c41558c4922ff1b0895547a99e378f136ec3d9d2f4df15cc269485fa 52648 Bytes | 200 https://use.fontawesome.com/releases/v5.0.0/webfonts/fa-brands-400.woff2
favicon.ico 0 Bytes | 406 https://my.salviatech.com/favicon.ico

Detectie

Tijdstempel Detectieregel Type Item
2025-03-05T02:16:55.454588+00:00 html_phishing_fakecaptcha_006 HTML
2025-03-05T02:16:55.462412+00:00 html_phishing_fakecaptcha_007 HTML
2025-03-05T02:16:55.325456+00:00 nl_url_keyword_redirect_suspect_001 URL https://www.google.com/recaptcha/about/images/[email protected]

Verzoeken

Request 633 https://my.salviatech.com/

Domein: my.salviatech.com

Methode: GET Bron: Document Status: 200

Request 634 https://www.google.com/recaptcha/about/images/[email protected]

Domein: www.google.com

Methode: GET Bron: Image Status: 200

Request 635 https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css

Domein: cdnjs.cloudflare.com

Methode: GET Bron: Stylesheet Status: 200

Request 636 https://use.fontawesome.com/releases/v5.0.0/css/all.css

Domein: use.fontawesome.com

Methode: GET Bron: Stylesheet Status: 200

Request 637 https://use.fontawesome.com/releases/v5.0.0/webfonts/fa-brands-400.woff2

Domein: use.fontawesome.com

Methode: GET Bron: Font Status: 200

Request 638 https://my.salviatech.com/favicon.ico

Domein: my.salviatech.com

Methode: GET Bron: Other Status: 200

Antwoorden

Response 637 https://my.salviatech.com/

Status: 200

Mime: text/html | Charset:

Remote IP: 162.241.216.56:443 | Protocol: h2

Beveiligingsstatus: secure | Uitgever: R11

Headers:

{"accept-ranges":"bytes","content-encoding":"gzip","content-length":"3902","content-type":"text/html","date":"Wed, 05 Mar 2025 02:16:50 GMT","host-header":"c2hhcmVkLmJsdWVob3N0LmNvbQ==","last-modified":"Fri, 06 Dec 2024 17:15:37 GMT","server":"nginx/1.25.5","vary":"Accept-Encoding","x-proxy-cache":"EXPIRED","x-server-cache":"true"}
Response 638 https://www.google.com/recaptcha/about/images/[email protected]

Status: 200

Mime: image/png | Charset:

Remote IP: [2a00:1450:400e:811::2004]:443 | Protocol: h3

Beveiligingsstatus: secure | Uitgever: WR2

Headers:

{"accept-ranges":"bytes","age":"1837","alt-svc":"h3=\":443\"; ma=2592000,h3-29=\":443\"; ma=2592000","cache-control":"public, max-age=3000","content-length":"18160","content-security-policy-report-only":"require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/recaptcha","content-type":"image/png","cross-origin-opener-policy":"same-origin-allow-popups; report-to=\"recaptcha\"","cross-origin-resource-policy":"cross-origin","date":"Wed, 05 Mar 2025 01:46:14 GMT","expires":"Wed, 05 Mar 2025 02:36:14 GMT","last-modified":"Wed, 29 Jul 2020 17:15:00 GMT","report-to":"{\"group\":\"recaptcha\",\"max_age\":2592000,\"endpoints\":[{\"url\":\"https://csp.withgoogle.com/csp/report-to/recaptcha\"}]}","server":"sffe","x-content-type-options":"nosniff","x-xss-protection":"0"}
Response 639 https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css

Status: 200

Mime: text/css | Charset:

Remote IP: [2606:4700::6811:180e]:443 | Protocol: h3

Beveiligingsstatus: secure | Uitgever: WE1

Headers:

{"accept-ranges":"bytes","access-control-allow-origin":"*","age":"379493","alt-svc":"h3=\":443\"; ma=86400","cache-control":"public, max-age=30672000","cf-cache-status":"HIT","cf-cdnjs-via":"cfworker/r2","cf-ray":"91b61d181ef8ab40-AMS","content-encoding":"br","content-length":"14850","content-type":"text/css; charset=utf-8","cross-origin-resource-policy":"cross-origin","date":"Wed, 05 Mar 2025 02:16:51 GMT","etag":"\"64942a3c-3a02\"","expires":"Mon, 23 Feb 2026 02:16:51 GMT","last-modified":"Thu, 22 Jun 2023 11:02:20 GMT","nel":"{\"success_fraction\":0.01,\"report_to\":\"cf-nel\",\"max_age\":604800}","priority":"u=0,i=?0","report-to":"{\"endpoints\":[{\"url\":\"https:\\/\\/a.nel.cloudflare.com\\/report\\/v4?s=8sw7WoIHYzNjTqZ6I9kiasNXz27ofboBgx%2FhYhKGxE3b22o0QqY0kH0iwo8o4eI2t0uIYXChyvNw6kwqodIN7t2wYW7Vc9QAgRn9ndTF4qTWz9heBqjZ1GaY7F1eAT0uhV5ATyoc%2BGcjD%2Fat0zPy0x%2BW\"}],\"group\":\"cf-nel\",\"max_age\":604800}","server":"cloudflare","server-timing":"cfExtPri","strict-transport-security":"max-age=15780000","timing-allow-origin":"*","vary":"Accept-Encoding","x-content-type-options":"nosniff"}
Response 640 https://use.fontawesome.com/releases/v5.0.0/css/all.css

Status: 200

Mime: text/css | Charset:

Remote IP: [2606:4700:3036::6815:1b98]:443 | Protocol: h2

Beveiligingsstatus: secure | Uitgever: WE1

Headers:

{"age":"428633","alt-svc":"h3=\":443\"; ma=86400","cache-control":"max-age=31556926","cf-cache-status":"HIT","cf-ray":"91b61d181899f85f-AMS","content-encoding":"zstd","content-type":"text/css","date":"Wed, 05 Mar 2025 02:16:51 GMT","etag":"W/\"e35d9c4ebaea0573df8e4a9505b72eea\"","last-modified":"Fri, 22 Sep 2023 01:44:05 GMT","nel":"{\"success_fraction\":0,\"report_to\":\"cf-nel\",\"max_age\":604800}","report-to":"{\"endpoints\":[{\"url\":\"https:\\/\\/a.nel.cloudflare.com\\/report\\/v4?s=qJQxxrRk6pHT7RY7Zvg5gRxorJkRzbGHdCJ42jRIWi7YISuOLfrMErIK5AZbMPg9rcYvKFzFZrf8QMRRCUANj7vxyjQyq35eyUgVfH25F%2BRn3X31Sf%2FTwxHyGPhtyapWxsow6XAOqP71YYPXvjH6AhFQ\"}],\"group\":\"cf-nel\",\"max_age\":604800}","server":"cloudflare","server-timing":"cfL4;desc=\"?proto=TCP\u0026rtt=1153\u0026min_rtt=1140\u0026rtt_var=346\u0026sent=7\u0026recv=9\u0026lost=0\u0026retrans=0\u0026sent_bytes=4035\u0026recv_bytes=2381\u0026delivery_rate=3459366\u0026cwnd=254\u0026unsent_bytes=0\u0026cid=9d651804ff213bcf\u0026ts=29\u0026x=0\"","vary":"Accept-Encoding"}
Response 641 https://use.fontawesome.com/releases/v5.0.0/webfonts/fa-brands-400.woff2

Status: 200

Mime: font/woff2 | Charset:

Remote IP: [2606:4700:3036::6815:1b98]:443 | Protocol: h2

Beveiligingsstatus: secure | Uitgever: WE1

Headers:

{"accept-ranges":"bytes","access-control-allow-origin":"*","alt-svc":"h3=\":443\"; ma=86400","cache-control":"max-age=31556926","cf-cache-status":"HIT","cf-ray":"91b61d18a9970e32-AMS","content-length":"52648","content-type":"font/woff2","date":"Wed, 05 Mar 2025 02:16:51 GMT","etag":"\"657e828fb3a5963706e24cbf9d711bb8\"","last-modified":"Fri, 22 Sep 2023 01:44:04 GMT","nel":"{\"success_fraction\":0,\"report_to\":\"cf-nel\",\"max_age\":604800}","report-to":"{\"endpoints\":[{\"url\":\"https:\\/\\/a.nel.cloudflare.com\\/report\\/v4?s=CCRdcm8fonU%2BcEO%2ByHZP6PHC%2FHap1Qq%2FocCQR7hsm6uZFL2ySMW%2Bd8AN4KDeztmWfIKYjemqxx4L91WHQkI40DrmsmOSyTZ3p7HHG%2FP1F6%2BU7Mwsf7PaBOSbA56ziuzWLYD9i9lm0EwV5tjZN8XqeBSp\"}],\"group\":\"cf-nel\",\"max_age\":604800}","server":"cloudflare","server-timing":"cfL4;desc=\"?proto=TCP\u0026rtt=1855\u0026min_rtt=1734\u0026rtt_var=660\u0026sent=7\u0026recv=10\u0026lost=0\u0026retrans=0\u0026sent_bytes=4036\u0026recv_bytes=2360\u0026delivery_rate=2332179\u0026cwnd=254\u0026unsent_bytes=0\u0026cid=006d720f8c230004\u0026ts=415\u0026x=0\"","vary":"Origin, Accept-Encoding"}
Response 642 https://my.salviatech.com/favicon.ico

Status: 200

Mime: image/x-icon | Charset:

Remote IP: 162.241.216.56:443 | Protocol: h2

Beveiligingsstatus: secure | Uitgever: R11

Headers:

{"accept-ranges":"bytes","cache-control":"max-age=604800","content-length":"11712","content-type":"image/x-icon","date":"Wed, 05 Mar 2025 02:16:51 GMT","expires":"Mon, 10 Mar 2025 17:27:13 GMT","host-header":"c2hhcmVkLmJsdWVob3N0LmNvbQ==","last-modified":"Thu, 16 Oct 2014 05:53:07 GMT","server":"nginx/1.25.5","x-proxy-cache":"HIT","x-server-cache":"true"}