IOC Report
https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35?preview=true

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text
dropped
Chrome Cache Entry: 101
HTML document, ASCII text, with very long lines (27233)
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (19948), with no line terminators
dropped
Chrome Cache Entry: 104
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (6826), with no line terminators
dropped
Chrome Cache Entry: 106
ASCII text
dropped
Chrome Cache Entry: 107
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 108
ASCII text
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (32065)
dropped
Chrome Cache Entry: 110
ASCII text
downloaded
Chrome Cache Entry: 111
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 112
ASCII text
downloaded
Chrome Cache Entry: 113
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 115
ASCII text
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 117
ASCII text
dropped
Chrome Cache Entry: 118
ASCII text
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (47531)
downloaded
Chrome Cache Entry: 120
ASCII text
dropped
Chrome Cache Entry: 121
ASCII text
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (1266)
downloaded
Chrome Cache Entry: 123
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 124
ASCII text
downloaded
Chrome Cache Entry: 125
PNG image data, 1400 x 812, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (47531)
dropped
Chrome Cache Entry: 127
ASCII text
dropped
Chrome Cache Entry: 128
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 129
ASCII text
dropped
Chrome Cache Entry: 130
PNG image data, 97 x 88, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 131
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 132
ASCII text
downloaded
Chrome Cache Entry: 133
ASCII text
downloaded
Chrome Cache Entry: 134
ASCII text
downloaded
Chrome Cache Entry: 135
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 137
HTML document, ASCII text
downloaded
Chrome Cache Entry: 138
Java source, ASCII text, with very long lines (521)
dropped
Chrome Cache Entry: 139
ASCII text, with very long lines (460), with no line terminators
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (26516)
downloaded
Chrome Cache Entry: 141
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 29752, version 1.0
downloaded
Chrome Cache Entry: 143
ASCII text
downloaded
Chrome Cache Entry: 144
ASCII text
downloaded
Chrome Cache Entry: 145
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 148
Java source, ASCII text, with very long lines (521)
downloaded
Chrome Cache Entry: 149
HTML document, ASCII text, with very long lines (37642)
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (6826), with no line terminators
downloaded
Chrome Cache Entry: 151
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 152
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 153
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 154
JSON data
dropped
Chrome Cache Entry: 155
ASCII text
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 34852, version 1.0
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (59158)
downloaded
Chrome Cache Entry: 158
ASCII text
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 160
ASCII text
downloaded
Chrome Cache Entry: 161
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (3379)
downloaded
Chrome Cache Entry: 163
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 164
ASCII text
dropped
Chrome Cache Entry: 165
ASCII text
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 167
PNG image data, 97 x 88, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (50758)
dropped
Chrome Cache Entry: 169
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 170
ASCII text, with very long lines (1266)
dropped
Chrome Cache Entry: 171
ASCII text, with very long lines (7862)
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 173
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 174
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 175
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 176
HTML document, ASCII text, with very long lines (5033)
downloaded
Chrome Cache Entry: 92
ASCII text
dropped
Chrome Cache Entry: 93
ASCII text
dropped
Chrome Cache Entry: 94
ASCII text, with very long lines (7862)
downloaded
Chrome Cache Entry: 95
ASCII text
downloaded
Chrome Cache Entry: 96
ASCII text
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (19948), with no line terminators
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (65460)
dropped
There are 76 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2200,i,15314668013799059045,3054818101342585984,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35?preview=true"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35?preview=true
malicious
https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35?preview=true
malicious
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/js_/67225394692a4-ee6afde19908e3ff916152be91a2ed69
104.21.67.65
malicious
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/&redirect=8d114c20f4dfa853ac0da82d2be1795cdb99fe6bmain&uid=f253efe302d32ab264a76e0ce65be769672253940c446
malicious
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/sig/a34c4b53364292472052aeea81eb27d46722539925388
104.21.67.65
https://statics.myclickfunnels.com/workspace/JBKklY/image/5077803/file/0e96390bae9eb8ce5c1014c55c774
unknown
https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
104.16.80.73
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/favicon.ico
104.21.67.65
https://code.jquery.com/jquery-3.6.0.min.js
151.101.194.137
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/d3RMTWNIRE9wS3NPSlIxrobotd3RMTWNIRE9wS3NPSlIx
104.21.67.65
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8dac81613d1d479d&lang=auto
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8dac81613d1d479d/1730302845790/f67c5d2562c38b14aeb06f8dbd4911b5e1b63cb6c6bef24f044f21d736dafbd4/W-W77QO5wsxsZLW
104.18.94.41
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/b_/67225394692a2-ee6afde19908e3ff916152be91a2ed69
104.21.67.65
https://images.clickfunnels.com/images/mejs-controls.svg)
unknown
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/home66d5be0fe62ab09af6aba1f816021365
104.21.67.65
https://cdn.jsdelivr.net/npm/intersection-observer
unknown
https://cdn.jsdelivr.net/npm/intl-tel-input
unknown
https://cdnjs.cloudflare.com/ajax/libs/lazysizes/5.3.2/lazysizes.min.js
104.17.25.14
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-LWEF4ZVP.js
104.18.35.212
https://bam.nr-data.net/jserrors/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=20926&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://use.fontawesome.com/releases/v5.15.0/css/all.css
unknown
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.min.js
104.17.25.14
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-DZUDOFKS.js
104.18.35.212
https://bam.nr-data.net/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=7965&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35&af=err,xhr,stn,ins,spa&be=2354&fe=4108&dc=4024&perf=%7B%22timing%22:%7B%22of%22:1730302813892,%22n%22:0,%22f%22:3,%22dn%22:32,%22dne%22:32,%22c%22:32,%22s%22:32,%22ce%22:646,%22rq%22:647,%22rp%22:2355,%22rpe%22:3497,%22di%22:4794,%22ds%22:6372,%22de%22:6378,%22dc%22:6452,%22l%22:6452,%22le%22:6462%7D,%22navigation%22:%7B%7D%7D&fp=4991&fcp=4991
162.247.243.29
https://images.clickfunnels.com/cdn-cgi/image/width=1400,fit=scale-down,f=auto,q=80/https://statics.myclickfunnels.com/workspace/JBKklY/image/5077803/file/0e96390bae9eb8ce5c1014c55c774e90.png
104.16.16.194
https://fontawesome.com/license/free
unknown
https://fontawesome.com
unknown
https://cdnjs.cloudflare.com/ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js
104.17.25.14
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-SO4UFY4C.js
104.18.35.212
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-J2NSUZBX.js
104.18.35.212
https://images.clickfunnels.com/cdn-cgi/image/width=600
unknown
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/logo_/VwxA9UvLw9Mub8G
104.21.67.65
https://images.clickfunnels.com/cdn-cgi/image/width=800
unknown
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-Z2HGFAFQ.js
104.18.35.212
https://cdn.jsdelivr.net/npm/container-query-polyfill
unknown
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/user_pages-LSZBT7OC.css
104.18.35.212
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-ICTFBFTW.js
104.18.35.212
https://bam.nr-data.net/events/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=20925&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-NYO26TGU.js
104.18.35.212
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-2I7C3SSB.js
104.18.35.212
https://myworkspacec1d73.myclickfunnels.com/ahoy/visits
104.18.35.212
https://myworkspacec1d73.myclickfunnels.com/cdn-cgi/rum?
104.18.35.212
https://bam.nr-data.net/events/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=18802&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-RCLGCWNE.js
104.18.35.212
https://cdnjs.cloudflare.com/ajax/libs/loading-attribute-polyfill/1.5.4/loading-attribute-polyfill.m
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8dac81613d1d479d/1730302845797/W71WpwtbbZ67Juw
104.18.94.41
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/user_pages-SLSIZYTU.js
104.18.35.212
https://challenges.cloudflare.com/turnstile/v0/g/f2bbd6738e15/api.js
104.18.94.41
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/cdn-cgi/challenge-platform/h/g/rc/8dac81613d1d479d
104.21.67.65
https://images.clickfunnels.com/cdn-cgi/image/width=1000px
unknown
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/js___/6722539469294-ee6afde19908e3ff916152be91a2ed69
104.21.67.65
https://myworkspacec1d73.myclickfunnels.com/favicon.ico
104.18.35.212
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/logo_/a34c4b53364292472052aeea81eb27d46722539925345
104.21.67.65
https://getbootstrap.com/docs/3.4/customize/)
unknown
https://js-agent.newrelic.com/nr-spa-1.242.0.min.js
162.247.243.39
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-INL62BHI.js
104.18.35.212
https://statics.myclickfunnels.com/image/474299/file/07ff1b9e40163a8c6578125048d53275.webp
unknown
https://events.myclickfunnels.com/api/v1
unknown
https://statics.myclickfunnels.com/workspace/JBKklY/image/5067568/file/8561f08f217958aae95a202f227a8
unknown
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/2svg/aCIATvYYfkZmve6
104.21.67.65
https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/dvb10/0x4AAAAAAAySs7_d-jW6RQ25/auto/fbE/normal/auto/
104.18.94.41
https://bam.nr-data.net/jserrors/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=18800&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://images.clickfunnels.com/cdn-cgi/image/width=2600
unknown
https://bam.nr-data.net/events/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=18798&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://images.clickfunnels.com/cdn-cgi/image/width=400
unknown
https://getbootstrap.com/)
unknown
https://a.nel.cloudflare.com/report/v4?s=kU0pcYd%2BXKtDPhIll9dibysH7WrgsPmBfkIaSkNz7Phv4bBZJ4uwfLnCawl2OB5wR99VHpp%2FXUhcuaJkxd2Yx8X3%2FFR5E0xfvktoNDT7b0zOCmcp0juzo1EXDf6gT%2BTlfORyeNy6boxO%2BuKGI6WTXeAwkZ5mcgfkclUSYVjsu%2BfVemKoB3VDdg%3D%3D
35.190.80.1
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/css_/f3SLhFFPs6b1DJJ
104.21.67.65
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/fav/EA1iD2Ixd38IJ04
104.21.67.65
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/captcha/style.css
104.21.67.65
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-THVZP4SD.js
104.18.35.212
https://bam.nr-data.net/events/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=8799&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://images.clickfunnels.com/cdn-cgi/image/width=500
unknown
https://images.clickfunnels.com/images/SevenNationArmy.mp3
unknown
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-6FUAARY5.js
104.18.35.212
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
104.18.94.41
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://images.clickfunnels.com/cdn-cgi/image/width=1000
unknown
https://use.fontawesome.com/releases/v5.15.0/css/v4-shims.css
unknown
https://images.clickfunnels.com/cdn-cgi/image/width=1800
unknown
https://github.com/uuidjs/uuid#getrandomvalues-not-supported
unknown
https://bam.nr-data.net/jserrors/1/NRJS-7f8cfbfdce5f1f3d33b?a=1588871059&sa=1&v=1.242.0&t=Unnamed%20Transaction&rst=20924&ck=0&s=3be87d4afeda7604&ref=https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35
162.247.243.29
https://myworkspacec1d73.myclickfunnels.com/assets/projects/user_pages/chunk-2AVRDVVM.js
104.18.35.212
https://images.clickfunnels.com/cdn-cgi/image/width=1400
unknown
There are 76 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
fastly-tls12-bam.nr-data.net
162.247.243.29
a.nel.cloudflare.com
35.190.80.1
static.cloudflareinsights.com
104.16.80.73
js-agent.newrelic.com
162.247.243.39
s-part-0017.t-0009.t-msedge.net
13.107.246.45
myworkspacec1d73.myclickfunnels.com
104.18.35.212
fp2e7a.wpc.phicdn.net
192.229.221.95
code.jquery.com
151.101.194.137
cdnjs.cloudflare.com
104.17.25.14
challenges.cloudflare.com
104.18.94.41
www.google.com
142.250.185.100
images.clickfunnels.com
104.16.16.194
sweetingmiddletodaymanagingeverything.abfdrywalls.com
104.21.67.65
use.fontawesome.com
unknown
bam.nr-data.net
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.67.65
sweetingmiddletodaymanagingeverything.abfdrywalls.com
United States
104.18.94.41
challenges.cloudflare.com
United States
142.250.185.100
www.google.com
United States
192.168.2.4
unknown
unknown
104.16.80.73
static.cloudflareinsights.com
United States
151.101.194.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.16.79.73
unknown
United States
162.247.243.39
js-agent.newrelic.com
United States
104.16.16.194
images.clickfunnels.com
United States
104.16.14.194
unknown
United States
104.17.24.14
unknown
United States
172.64.152.44
unknown
United States
151.101.2.137
unknown
United States
172.67.215.204
unknown
United States
239.255.255.250
unknown
Reserved
162.247.243.29
fastly-tls12-bam.nr-data.net
United States
104.18.35.212
myworkspacec1d73.myclickfunnels.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States
There are 9 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35?preview=true
malicious
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/&redirect=8d114c20f4dfa853ac0da82d2be1795cdb99fe6bmain&uid=f253efe302d32ab264a76e0ce65be769672253940c446
malicious
https://myworkspacec1d73.myclickfunnels.com/onlinereview--9cb35?preview=true
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/
https://sweetingmiddletodaymanagingeverything.abfdrywalls.com/&redirect=8d114c20f4dfa853ac0da82d2be1795cdb99fe6bmain&uid=f253efe302d32ab264a76e0ce65be769672253940c446