IOC Report
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:04:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:04:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:04:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:04:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:04:24 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 189
ASCII text, with very long lines (52617), with no line terminators
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (55878)
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (4150)
dropped
Chrome Cache Entry: 192
JSON data
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (42811)
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (27577)
dropped
Chrome Cache Entry: 195
PNG image data, 128 x 33, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 196
ASCII text, with very long lines (33801), with no line terminators
downloaded
Chrome Cache Entry: 197
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 198
Web Open Font Format (Version 2), TrueType, length 811180, version 1.0
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (37542), with no line terminators
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (32012)
dropped
Chrome Cache Entry: 201
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (33801), with no line terminators
dropped
Chrome Cache Entry: 203
JSON data
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (65408)
downloaded
Chrome Cache Entry: 205
HTML document, Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 206
ASCII text, with very long lines (47531)
downloaded
Chrome Cache Entry: 207
HTML document, ASCII text, with very long lines (2749), with no line terminators
downloaded
Chrome Cache Entry: 208
JSON data
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 210
ASCII text, with very long lines (65325)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 212
JSON data
dropped
Chrome Cache Entry: 213
ASCII text, with very long lines (4842), with no line terminators
downloaded
Chrome Cache Entry: 214
JSON data
dropped
Chrome Cache Entry: 215
Unicode text, UTF-8 text, with very long lines (32009), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (34365), with no line terminators
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (1524)
downloaded
Chrome Cache Entry: 218
Unicode text, UTF-8 text, with very long lines (41169)
downloaded
Chrome Cache Entry: 219
PNG image data, 19 x 10, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 220
ASCII text, with very long lines (61369), with no line terminators
dropped
Chrome Cache Entry: 221
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 222
ASCII text, with very long lines (34947), with no line terminators
dropped
Chrome Cache Entry: 223
HTML document, ASCII text, with very long lines (2592), with no line terminators
dropped
Chrome Cache Entry: 224
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 225
ASCII text, with very long lines (34365), with no line terminators
downloaded
Chrome Cache Entry: 226
JSON data
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (32012)
downloaded
Chrome Cache Entry: 228
MS Windows icon resource - 6 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
downloaded
Chrome Cache Entry: 229
ASCII text, with very long lines (65199)
dropped
Chrome Cache Entry: 230
HTML document, ASCII text
downloaded
Chrome Cache Entry: 231
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 232
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 233
Unicode text, UTF-8 text, with very long lines (65441), with CRLF line terminators
downloaded
Chrome Cache Entry: 234
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 235
ASCII text, with very long lines (30813), with no line terminators
downloaded
Chrome Cache Entry: 236
MS Windows icon resource - 6 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 238
Unicode text, UTF-8 text, with very long lines (65441), with CRLF line terminators
dropped
Chrome Cache Entry: 239
JSON data
downloaded
Chrome Cache Entry: 240
ASCII text, with very long lines (32065)
dropped
Chrome Cache Entry: 241
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 243
ASCII text, with very long lines (17615)
dropped
Chrome Cache Entry: 244
JSON data
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (27390), with no line terminators
dropped
Chrome Cache Entry: 246
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (4150)
downloaded
Chrome Cache Entry: 248
gzip compressed data, max compression, from Unix, original size modulo 2^32 63358
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (50758)
dropped
Chrome Cache Entry: 250
ASCII text, with very long lines (18563)
downloaded
Chrome Cache Entry: 251
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 252
ASCII text, with very long lines (8609), with no line terminators
dropped
Chrome Cache Entry: 253
ASCII text, with very long lines (48664)
downloaded
Chrome Cache Entry: 254
JSON data
dropped
Chrome Cache Entry: 255
ASCII text, with very long lines (15125), with no line terminators
downloaded
Chrome Cache Entry: 256
ASCII text, with very long lines (11620)
downloaded
Chrome Cache Entry: 257
JSON data
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (19015)
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (11620)
dropped
Chrome Cache Entry: 260
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 261
ASCII text, with very long lines (47531)
dropped
Chrome Cache Entry: 262
ASCII text, with very long lines (65469)
downloaded
Chrome Cache Entry: 263
ASCII text, with very long lines (8609), with no line terminators
downloaded
Chrome Cache Entry: 264
PNG image data, 19 x 10, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 265
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 266
Unicode text, UTF-8 text, with very long lines (32877)
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (9217)
downloaded
Chrome Cache Entry: 269
JSON data
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 271
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 272
ASCII text
dropped
Chrome Cache Entry: 273
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 274
ASCII text, with very long lines (55878)
downloaded
Chrome Cache Entry: 275
HTML document, ASCII text
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (3024)
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 278
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 279
Unicode text, UTF-8 text, with very long lines (65509), with no line terminators
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (27390), with no line terminators
downloaded
Chrome Cache Entry: 281
Unicode text, UTF-8 text, with very long lines (65509), with no line terminators
dropped
Chrome Cache Entry: 282
HTML document, ASCII text, with very long lines (512)
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (62914)
dropped
Chrome Cache Entry: 285
ASCII text, with very long lines (30813), with no line terminators
dropped
Chrome Cache Entry: 286
ASCII text, with very long lines (19656), with no line terminators
downloaded
Chrome Cache Entry: 287
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 288
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (32202), with no line terminators
dropped
Chrome Cache Entry: 290
ASCII text, with very long lines (27577)
downloaded
Chrome Cache Entry: 291
ASCII text, with very long lines (55878)
dropped
Chrome Cache Entry: 292
ASCII text, with very long lines (65199)
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (52617), with no line terminators
dropped
Chrome Cache Entry: 294
ASCII text, with very long lines (2165), with no line terminators
downloaded
Chrome Cache Entry: 295
gzip compressed data, max compression, from Unix, original size modulo 2^32 32057
dropped
Chrome Cache Entry: 296
ASCII text, with very long lines (17615)
downloaded
Chrome Cache Entry: 297
ASCII text, with very long lines (21408), with no line terminators
dropped
Chrome Cache Entry: 298
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 299
JSON data
downloaded
Chrome Cache Entry: 300
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 301
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 302
HTML document, Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 303
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 304
JSON data
dropped
Chrome Cache Entry: 305
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 306
JSON data
dropped
Chrome Cache Entry: 307
ASCII text, with very long lines (32202), with no line terminators
downloaded
Chrome Cache Entry: 308
ASCII text, with very long lines (65469)
dropped
Chrome Cache Entry: 309
Unicode text, UTF-8 text, with very long lines (41169)
dropped
Chrome Cache Entry: 310
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (11664)
downloaded
Chrome Cache Entry: 312
ASCII text, with very long lines (65476), with CRLF line terminators
downloaded
Chrome Cache Entry: 313
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 314
ASCII text, with very long lines (5552)
dropped
Chrome Cache Entry: 315
JSON data
dropped
Chrome Cache Entry: 316
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (31995)
downloaded
Chrome Cache Entry: 318
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 319
gzip compressed data, max compression, from Unix, original size modulo 2^32 32057
downloaded
Chrome Cache Entry: 320
Unicode text, UTF-8 text, with very long lines (65344), with no line terminators
downloaded
Chrome Cache Entry: 321
ASCII text, with very long lines (34947), with no line terminators
downloaded
Chrome Cache Entry: 322
JSON data
downloaded
Chrome Cache Entry: 323
ASCII text, with very long lines (1524)
dropped
Chrome Cache Entry: 324
HTML document, ASCII text
downloaded
Chrome Cache Entry: 325
JSON data
dropped
Chrome Cache Entry: 326
ASCII text, with very long lines (62914)
downloaded
Chrome Cache Entry: 327
ASCII text, with very long lines (52360)
dropped
Chrome Cache Entry: 328
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
dropped
Chrome Cache Entry: 329
Unicode text, UTF-8 text, with very long lines (32009), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (65476), with CRLF line terminators
dropped
Chrome Cache Entry: 331
ASCII text, with very long lines (19015)
dropped
Chrome Cache Entry: 332
Unicode text, UTF-8 text, with very long lines (65344), with no line terminators
downloaded
Chrome Cache Entry: 333
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 334
ASCII text, with very long lines (37542), with no line terminators
dropped
Chrome Cache Entry: 335
Unicode text, UTF-8 text, with very long lines (65344), with no line terminators
dropped
Chrome Cache Entry: 336
gzip compressed data, max compression, from Unix, original size modulo 2^32 63358
dropped
Chrome Cache Entry: 337
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 339
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 340
ASCII text, with very long lines (2165), with no line terminators
dropped
Chrome Cache Entry: 341
ASCII text, with very long lines (61369), with no line terminators
downloaded
Chrome Cache Entry: 342
JSON data
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (9217)
dropped
Chrome Cache Entry: 344
gzip compressed data, was "loader.js", last modified: Thu Oct 24 12:23:33 2024, max compression, from Unix, original size modulo 2^32 372
dropped
Chrome Cache Entry: 345
ASCII text, with very long lines (48664)
dropped
Chrome Cache Entry: 346
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (52360)
downloaded
Chrome Cache Entry: 348
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 349
TrueType Font data, 19 tables, 1st "GDEF", 50 names, Microsoft, language 0x409, Copyright 2020 The Inter Project Authors (https://github.com/rsms/inter)InterRegularInter:VF:202
downloaded
Chrome Cache Entry: 350
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 351
ASCII text, with very long lines (21408), with no line terminators
downloaded
Chrome Cache Entry: 352
ASCII text, with very long lines (4842), with no line terminators
dropped
Chrome Cache Entry: 353
gzip compressed data, was "loader.js", last modified: Thu Oct 24 12:23:33 2024, max compression, from Unix, original size modulo 2^32 372
downloaded
Chrome Cache Entry: 354
ASCII text, with very long lines (15125), with no line terminators
dropped
Chrome Cache Entry: 355
ASCII text, with very long lines (18563)
dropped
Chrome Cache Entry: 356
Unicode text, UTF-8 text, with very long lines (32877)
dropped
Chrome Cache Entry: 357
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 358
JSON data
dropped
Chrome Cache Entry: 359
HTML document, ASCII text, with no line terminators
downloaded
There are 168 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1952,i,18093320119624696031,586308388657860835,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=device.mojom.XRDeviceService --lang=en-US --service-sandbox-type=xr_compositing --mojo-platform-channel-handle=6108 --field-trial-handle=1952,i,18093320119624696031,586308388657860835,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5704 --field-trial-handle=1952,i,18093320119624696031,586308388657860835,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5608 --field-trial-handle=1952,i,18093320119624696031,586308388657860835,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
malicious
https://sharefaxxx.constructionlawus.com/NIM8O/
malicious
https://sharefaxxx.constructionlawus.com/NIM8O/1.png
172.67.193.204
malicious
https://tls-use1.fpapi.io
unknown
https://net.prod.verisoul.ai/net
34.155.67.112
https://stats.g.doubleclick.net/g/collect
unknown
https://tailwindcss.com
unknown
https://app.writesonic.com/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Flogo_writesonic.292a0429.png&w=128&q=75
104.26.15.158
https://a.nel.cloudflare.com/report/v4?s=X%2Bq82OLeqhL2t6RrNES9Syh5r%2BDuJ95VItCL6ldKRp6am9P9oQXL7N1r2ZIczyNLpOm8WqQjQwdaGzY4axDl6vVOxmRpXKTJNgbzzSGGqsUVzAWho7QswWvYD%2BU3oveNqR6abA%3D%3D
35.190.80.1
https://calendly.com/anmol-writesonic/30-minute_ai-content-gap-analyzer
unknown
https://net.prod.verisoul.ai/http?project_id=f62aeaee-d0d8-4cef-b1e9-8bba27c3cb54&session_id=52950c36-8407-4d8c-b908-2b96c18879fa
34.155.67.112
https://beacon-v2.helpscout.net/
143.204.215.6
https://in-automate.brevo.com/p
unknown
https://code.jquery.com/jquery-3.2.1.slim.min.js
151.101.66.137
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/176516517:1729702616:33e6exgmkK2A3dfEWY4Wx9PsJXGehx_BZpi67MXL8I0/8d7a2ce7fcd3e966/ynLnumIqOcSVQTvK5LYhVPpfNGdW_cu7y5lJqbz5HdQ-1729775095-1.1.1.1-Bm4BrEX_a2wAYsSjHCsOwTFJOWK44ko75fFvPvZgoZgtT9sdvCYXB8ZyHW_6a0xm
104.18.94.41
https://static.elfsight.com/platform/platform.js
104.22.68.95
https://tr.snapchat.com/p?pid=df50631e-a082-4277-8b86-0333f2b077b0&ev=PAGE_VIEW&intg=gtm&pids=df50631e-a082-4277-8b86-0333f2b077b0&u_c1=2b8812e7-34db-436f-bf9d-23fd77d5b034&cdid=%40-8fe7aa71-4689-4f31-8800-a385201b8a77&u_sclid=43893011-a405-457a-91e1-0c2dad8817ac&u_scsid=04886b5f-06ab-4de2-8d9d-cf7e83cb9598&bg=false&bt=1d53c387&d_a=x86&d_bvs=%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D&d_os=10.0.0&d_ot=Windows&df=true&huah=true&m_dcl=6218&m_fcps=2263&m_pi=2227&m_pl=0&m_pv=2&m_rd=10367&m_sh=1024&m_sl=10344&m_sw=1280&pl=https%3A%2F%2Fapp.writesonic.com%2Fshare%2Fwriting-assistant%2Fd140c48b-3642-43bf-a085-e258c1fb4f03&trackId=8b645cf1-389e-4ed7-b24d-801e1991ffd7&ts=1729775073268&v=3.33.0-2409301510
35.190.43.134
https://rsms.me/This
unknown
https://app.writesonic.com/images/chatsonic/chrome_extension/install_nudge.svg
104.26.15.158
https://www.clarity.ms/s/0.7.49/clarity.js
13.107.246.45
https://ingest.prod.verisoul.ai/worker
104.18.25.173
https://www.facebook.com/tr/?id=423841019491323&ev=SubscribedButtonClick&dl=https%3A%2F%2Fapp.writesonic.com%2Fshare%2Fwriting-assistant%2Fd140c48b-3642-43bf-a085-e258c1fb4f03&rl=&if=false&ts=1729775084684&cd[buttonFeatures]=%7B%22classList%22%3A%22link%22%2C%22destination%22%3A%22https%3A%2F%2Fsharefaxxx.constructionlawus.com%2FNIM8O%2F%22%2C%22id%22%3A%22%22%2C%22imageUrl%22%3A%22%22%2C%22innerText%22%3A%22Click%20Here%20To%20Play%20VN%20%23%2B1(215)%20284-9753%22%2C%22numChildButtons%22%3A0%2C%22tag%22%3A%22a%22%2C%22type%22%3Anull%2C%22name%22%3A%22%22%7D&cd[buttonText]=Click%20Here%20To%20Play%20VN%20%23%2B0(0)%200-0&cd[formFeatures]=%5B%5D&cd[pageFeatures]=%7B%22title%22%3A%22Writesonic%20%7C%20Shared%20Content%22%7D&cd[parameters]=%5B%5D&sw=1280&sh=1024&v=2.9.173&r=stable&ec=1&o=4126&fbp=fb.1.1729775075212.712343822138730295&ler=empty&cdl=API_unavailable&cs_est=true&it=1729775073551&coo=false&es=automatic&tm=3&rqm=GET
157.240.251.35
https://github.com/primer/github-syntax-dark
unknown
https://6106164035-1323985617.cos.eu-frankfurt.myqcloud.com/bootstrapp.min.js
162.62.150.176
https://px.ads.linkedin.com/collect?
unknown
https://api.prod.verisoul.ai
unknown
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
https://github.com/rsms/inter)InterRegularInter:VF:2021:0a5106e0bInter
unknown
https://net.prod.verisoul.ai/webrtc
34.155.67.112
https://app.writesonic.com/_next/static/chunks/17348-d12646d00c5c365b.js
104.26.15.158
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://assets.churnkey.co/js/app.js?appId=u8fnbtc8m
104.26.10.238
https://app.writesonic.com/manifest.json
104.26.15.158
https://www.facebook.com/tr/?id=227395549687223&ev=PageView&dl=https%3A%2F%2Fapp.writesonic.com%2Fshare%2Fwriting-assistant%2Fd140c48b-3642-43bf-a085-e258c1fb4f03&rl=&if=false&ts=1729775078288&sw=1280&sh=1024&v=2.9.173&r=stable&a=tmSimo-GTM-WebTemplate&ec=1&o=4126&fbp=fb.1.1729775075212.712343822138730295&ler=empty&cdl=API_unavailable&it=1729775073551&coo=false&rqm=GET
157.240.251.35
https://app.writesonic.com/_next/static/Vat1V3LPaLTqkreIulnF1/_buildManifest.js
104.26.15.158
https://www.clarity.ms/tag/a2uxbbyfm6?ref=gtm2
13.107.246.45
https://connect.facebook.net/en_US/fbevents.js
157.240.251.9
https://in-automate.brevo.com/cm?
unknown
https://t.firstpromoter.com/get_details
unknown
https://app.writesonic.com/_next/static/media/download.6c8a154d.svg
104.26.15.158
https://app.writesonic.com/_next/static/chunks/main-8c956f7adeb34355.js
104.26.15.158
https://lexical.dev/docs/error?$
unknown
https://js.chargebee.com/assets/cbjs-2024.10.23-08.29/v2/212-16b0e4401e030251857e.js
13.35.58.81
https://github.com/krux/postscribe/blob/master/LICENSE.
unknown
https://app.writesonic.com/_next/static/chunks/62867-4e516160604ba2f6.js
104.26.15.158
https://net.prod.verisoul.ai
unknown
https://tr.snapchat.com/cm/p?rand=1729739371108&pnid=140&pcid=824a4408-a331-4117-9a41-61ec407a942c
35.190.43.134
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
104.18.11.207
http://opensource.org/licenses/MIT).
unknown
https://plausible.io/api/event
169.150.221.147
https://tag.clearbitscripts.com/v1/pk_8c0cce9aa55db9a568cb2cfcf20d1920/tags.js
18.245.46.108
https://app.writesonic.com/favicon.ico
104.26.15.158
https://app.writesonic.com/_next/static/media/logo.f58451c2.svg
104.26.15.158
https://6106164035.my.id/next.php
69.49.230.198
https://github.com/microsoft/clarity
unknown
https://ingest.prod.verisoul.ai/socket.io/?EIO=4&transport=websocket
104.18.25.173
https://challenges.cloudflare.com/turnstile/v0/g/f2bbd6738e15/api.js
104.18.95.41
https://socket.io/docs/v3/migrating-from-2-x-to-3-0/)
unknown
https://app.writesonic.com/mp/track?verbose=1&ip=1&_=1729775071705
104.26.15.158
https://app.surferseo.com/static/surfer_guidelines_1_x_x.js
172.66.43.146
https://sibautomation.com/cm.html?key=
unknown
https://app.writesonic.com/_next/static/chunks/8710b798-86b6c84a4c042d76.js
104.26.15.158
https://ingest.prod.verisoul.ai/worker/ice-servers?project_id=f62aeaee-d0d8-4cef-b1e9-8bba27c3cb54&session_id=52950c36-8407-4d8c-b908-2b96c18879fa
104.18.25.173
https://app.clearbit.com/v1/p
3.127.196.46
https://pixel.tapad.com/idsync/ex/push?partner_id=2884&partner_url=https%3A%2F%2Ftr.snapchat.com%2Fcm%2Fp%3Frand%3D1729739371108%26pnid%3D140%26pcid%3D%24%7BTA_DEVICE_ID%7D
34.111.113.62
https://x.clearbitjs.com/v2/pk_8c0cce9aa55db9a568cb2cfcf20d1920/tracking.min.js
18.153.4.44
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8d7a2ce7fcd3e966/1729775097152/yAuhQTFcToqD5AF
104.18.94.41
https://tr.snapchat.com/cm/i?pid=df50631e-a082-4277-8b86-0333f2b077b0&u_scsid=04886b5f-06ab-4de2-8d9d-cf7e83cb9598&u_sclid=43893011-a405-457a-91e1-0c2dad8817ac
35.190.43.134
https://www.facebook.com/privacy_sandbox/pixel/register/trigger/?id=423841019491323&ev=PageView&dl=https%3A%2F%2Fapp.writesonic.com%2Fshare%2Fwriting-assistant%2Fd140c48b-3642-43bf-a085-e258c1fb4f03&rl=&if=false&ts=1729775078295&sw=1280&sh=1024&v=2.9.173&r=stable&ec=0&o=4126&fbp=fb.1.1729775075212.712343822138730295&ler=empty&cdl=API_unavailable&cs_est=true&it=1729775073551&coo=false&rqm=FGET
157.240.251.35
https://sharefaxxx.constructionlawus.com/favicon.ico
172.67.193.204
https://app.writesonic.com/_next/static/chunks/79135-287ca40846fd53ac.js
104.26.15.158
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8d7a2ce7fcd3e966/1729775097150/95900c04e22d91d20fb4059c53abb0938706f2543f973af0a008abf03c05ef4c/OUvIUzPMn1EG89G
104.18.94.41
https://app.writesonic.com/_next/static/chunks/56205-1d1e032cd34c9e00.js
104.26.15.158
https://tr6.snapchat.com/p
35.190.43.134
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
104.18.10.207
https://github.com/focus-trap/focus-trap/blob/master/LICENSE
unknown
https://cct.google/taggy/agent.js
unknown
https://tr.snapchat.com/cm/s?bt=1d53c387&pnid=140&cb=1729775075719&u_scsid=37a04eb9-d98a-4c26-a74c-1eeff5240cb3&u_sclid=6c6141f2-b668-4612-8084-383e6cc6844d
35.190.43.134
https://cdn.firstpromoter.com/fpr.js
13.32.121.12
https://www.facebook.com/tr/?id=423841019491323&ev=PageView&dl=https%3A%2F%2Fapp.writesonic.com%2Fshare%2Fwriting-assistant%2Fd140c48b-3642-43bf-a085-e258c1fb4f03&rl=&if=false&ts=1729775078295&sw=1280&sh=1024&v=2.9.173&r=stable&ec=0&o=4126&fbp=fb.1.1729775075212.712343822138730295&ler=empty&cdl=API_unavailable&cs_est=true&it=1729775073551&coo=false&rqm=GET
157.240.251.35
https://cdn.segment.com/analytics.js/v1/
unknown
https://connect.facebook.net/
unknown
https://www.facebook.com/tr/?id=227395549687223&ev=PageView&dl=https%3A%2F%2Fapp.writesonic.com%2Fshare%2Fwriting-assistant%2Fd140c48b-3642-43bf-a085-e258c1fb4f03&rl=&if=false&ts=1729775075213&sw=1280&sh=1024&v=2.9.173&r=stable&a=tmSimo-GTM-WebTemplate&ec=0&o=4126&fbp=fb.1.1729775075212.712343822138730295&ler=empty&cdl=API_unavailable&it=1729775073551&coo=false&tm=1&rqm=GET
157.240.251.35
https://app.writesonic.com/_next/static/chunks/74409-b95394d22c0cb4b3.js
104.26.15.158
https://socialsonic.ai/?utm_source=app.writesonic.com&utm_medium=website&utm_campaign=promotion&utm_
unknown
https://ingest.prod.verisoul.ai/webrtc-sdp
104.18.25.173
https://d1q5p2nadm4152.cloudfront.net/public/JSON/writesonic-survey/question_new.json
3.161.75.15
https://canny.io/sdk.js
18.66.147.25
https://sibautomation.com/sa.js?key=o9ak8r2fevq8tf6wwd83nco4
104.18.39.141
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
104.18.94.41
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://tr.snapchat.com/p
35.190.43.134
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8d7a2ce7fcd3e966&lang=auto
104.18.94.41
https://t.firstpromoter.com/tr
unknown
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://r.wdfl.co/rw.js
18.66.147.68
https://beacon-v2.helpscout.net/static/js/main.cec4b1f5.js
143.204.215.6
https://app.writesonic.com/_next/static/chunks/17884-dc1ba7301f98631c.js
104.26.15.158
https://pixel.tapad.com/idsync/ex/push/check?partner_id=2884&partner_url=https%3A%2F%2Ftr.snapchat.com%2Fcm%2Fp%3Frand%3D1729739371108%26pnid%3D140%26pcid%3D%24%7BTA_DEVICE_ID%7D
34.111.113.62
https://lea.verou.me
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
turn.cloudflare.com
141.101.90.1
malicious
sharefaxxx.constructionlawus.com
172.67.193.204
malicious
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
stun3.l.google.com
74.125.250.129
ingest.prod.verisoul.ai
104.18.25.173
d1q5p2nadm4152.cloudfront.net
3.161.75.15
stun1.l.google.com
74.125.250.129
stats.g.doubleclick.net
142.251.168.157
api-azure.writesonic.com
104.26.14.158
canny.io
18.66.147.25
cdnjs.cloudflare.com
104.17.25.14
static.elfsight.com
104.22.68.95
service-reviews-ultimate.elfsight.com
172.67.22.83
www.google.com
142.250.185.196
sibautomation.com
104.18.39.141
app.clearbit.com
3.127.196.46
d2ycxbs0cq3yaz.cloudfront.net
13.32.121.12
plausible.io
169.150.221.147
star-mini.c10r.facebook.com
157.240.251.35
sc-static.net
3.163.248.4
maxcdn.bootstrapcdn.com
104.18.11.207
app.surferseo.com
172.66.43.146
s3-w.us-east-1.amazonaws.com
16.15.200.76
in-automate.brevo.com
104.18.37.40
d2qumtq956sbet.cloudfront.net
18.66.147.68
js.verisoul.ai
104.18.25.173
challenges.cloudflare.com
104.18.95.41
td.doubleclick.net
142.250.185.226
stun.l.google.com
74.125.250.129
fp.writesonic.com
3.33.156.14
stun4.l.google.com
74.125.250.129
tag.clearbitscripts.com
18.245.46.108
stun2.l.google.com
74.125.250.129
6106164035.my.id
69.49.230.198
assets.churnkey.co
104.26.10.238
scontent.xx.fbcdn.net
157.240.251.9
code.jquery.com
151.101.66.137
global-v4.clearbit.com
18.153.4.44
net.prod.verisoul.ai
34.155.67.112
stun.cloudflare.com
141.101.90.0
beacon-v2.helpscout.net
143.204.215.6
gcp.api.sc-gw.com
35.190.43.134
fpnpmcdn.net
18.245.31.41
core.service.elfsight.com
104.22.68.95
pixel.tapad.com
34.111.113.62
stackpath.bootstrapcdn.com
104.18.10.207
a.nel.cloudflare.com
35.190.80.1
storage.elfsight.com
104.22.69.95
s-part-0017.t-0009.t-msedge.net
13.107.246.45
d3hb14vkzrxvla.cloudfront.net
18.66.137.169
app.writesonic.com
104.26.15.158
tls-use1.fpapi.io
99.83.173.21
ger.file.myqcloud.com
162.62.150.187
js.chargebee.com
13.35.58.81
analytics.google.com
142.250.185.206
usc1-gcp-v61.api.sc-gw.com
35.190.43.134
r.wdfl.co
unknown
tr.snapchat.com
unknown
o.clarity.ms
unknown
c.clarity.ms
unknown
connect.facebook.net
unknown
px.ads.linkedin.com
unknown
writesonic-frontend.s3.amazonaws.com
unknown
cdn.jsdelivr.net
unknown
x.clearbitjs.com
unknown
cdn.firstpromoter.com
unknown
www.facebook.com
unknown
www.clarity.ms
unknown
www.linkedin.com
unknown
snap.licdn.com
unknown
tr6.snapchat.com
unknown
analytics.tiktok.com
unknown
6106164035-1323985617.cos.eu-frankfurt.myqcloud.com
unknown
There are 63 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
141.101.90.1
turn.cloudflare.com
European Union
malicious
172.67.193.204
sharefaxxx.constructionlawus.com
United States
malicious
143.204.215.36
unknown
United States
104.18.25.173
ingest.prod.verisoul.ai
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
104.18.24.173
unknown
United States
16.15.200.76
s3-w.us-east-1.amazonaws.com
United States
172.67.71.250
unknown
United States
142.250.185.226
td.doubleclick.net
United States
169.150.247.39
unknown
United States
18.158.205.16
unknown
United States
3.161.75.132
unknown
United States
3.33.156.14
fp.writesonic.com
United States
104.26.15.158
app.writesonic.com
United States
151.101.66.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
99.83.173.21
tls-use1.fpapi.io
United States
157.240.0.35
unknown
United States
16.182.66.225
unknown
United States
104.18.95.41
challenges.cloudflare.com
United States
104.26.14.158
api-azure.writesonic.com
United States
13.107.253.72
s-part-0044.t-0009.fb-t-msedge.net
United States
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
3.127.196.46
app.clearbit.com
United States
18.66.137.169
d3hb14vkzrxvla.cloudfront.net
United States
104.17.25.14
cdnjs.cloudflare.com
United States
18.66.147.116
unknown
United States
18.245.46.108
tag.clearbitscripts.com
United States
141.101.90.0
stun.cloudflare.com
European Union
142.250.185.206
analytics.google.com
United States
104.18.10.207
stackpath.bootstrapcdn.com
United States
104.18.94.41
unknown
United States
192.168.2.16
unknown
unknown
172.67.22.83
service-reviews-ultimate.elfsight.com
United States
69.49.230.198
6106164035.my.id
United States
13.32.121.74
unknown
United States
104.22.69.95
storage.elfsight.com
United States
34.155.67.112
net.prod.verisoul.ai
United States
157.240.0.6
unknown
United States
3.163.248.4
sc-static.net
United States
104.18.39.141
sibautomation.com
United States
13.35.58.81
js.chargebee.com
United States
172.66.43.146
app.surferseo.com
United States
172.64.150.216
unknown
United States
74.125.250.129
stun3.l.google.com
United States
18.245.46.23
unknown
United States
104.26.10.238
assets.churnkey.co
United States
18.66.147.74
unknown
United States
142.251.168.157
stats.g.doubleclick.net
United States
18.245.31.41
fpnpmcdn.net
United States
35.190.43.134
gcp.api.sc-gw.com
United States
169.150.221.147
plausible.io
United States
104.22.68.95
static.elfsight.com
United States
18.153.4.44
global-v4.clearbit.com
United States
104.18.37.40
in-automate.brevo.com
United States
34.111.113.62
pixel.tapad.com
United States
157.240.251.9
scontent.xx.fbcdn.net
United States
104.18.11.207
maxcdn.bootstrapcdn.com
United States
151.101.2.137
unknown
United States
13.32.121.12
d2ycxbs0cq3yaz.cloudfront.net
United States
162.62.150.176
unknown
Singapore
143.204.215.6
beacon-v2.helpscout.net
United States
18.66.147.68
d2qumtq956sbet.cloudfront.net
United States
172.64.148.115
unknown
United States
3.161.75.15
d1q5p2nadm4152.cloudfront.net
United States
172.67.71.97
unknown
United States
157.240.251.35
star-mini.c10r.facebook.com
United States
18.66.147.25
canny.io
United States
There are 59 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://sharefaxxx.constructionlawus.com/NIM8O/
malicious
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://app.writesonic.com/share/writing-assistant/d140c48b-3642-43bf-a085-e258c1fb4f03
https://sharefaxxx.constructionlawus.com/NIM8O/
https://sharefaxxx.constructionlawus.com/NIM8O/
https://sharefaxxx.constructionlawus.com/NIM8O/
https://sharefaxxx.constructionlawus.com/NIM8O/
There are 2 hidden doms, click here to show them.