IOC Report
https://williamsontx.mugshots.zone/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 26 17:53:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 26 17:53:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 26 17:53:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 26 17:53:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Mar 26 17:53:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://williamsontx.mugshots.zone/
https://williamsontx.mugshots.zone/
https://googleads.g.doubleclick.net/pagead/ads?gdpr=0&us_privacy=1NNN&client=ca-pub-1349470098454340&output=html&adk=1812271804&adf=3025194257&lmt=1711479196&plaf=7%3A2&plat=3%3A128%2C4%3A128%2C9%3A32776%2C16%3A8388608%2C17%3A32%2C24%3A32%2C25%3A32%2C30%3A1081344%2C32%3A32%2C41%3A32%2C42%3A32&format=0x0&url=https%3A%2F%2Fwilliamsontx.mugshots.zone%2F&pra=5&wgl=1&easpi=0&asro=0&uach=WyJXaW5kb3dzIiwiMTAuMC4wIiwieDg2IiwiIiwiMTE3LjAuNTkzOC4xMzIiLG51bGwsMCxudWxsLCI2NCIsW1siR29vZ2xlIENocm9tZSIsIjExNy4wLjU5MzguMTMyIl0sWyJOb3Q7QT1CcmFuZCIsIjguMC4wLjAiXSxbIkNocm9taXVtIiwiMTE3LjAuNTkzOC4xMzIiXV0sMF0.&dt=1711479195494&bpp=4&bdt=1614&idt=730&shv=r20240321&mjsv=m202403190101&ptt=9&saldr=aa&abxe=1&nras=1&correlator=7449945667424&frm=20&pv=2&ga_vid=220955852.1711479196&ga_sid=1711479196&ga_hid=9210995&ga_fc=0&u_tz=60&u_his=1&u_h=1024&u_w=1280&u_ah=984&u_aw=1280&u_cd=24&u_sd=1&dmc=8&adx=-12245933&ady=-12245933&biw=1263&bih=907&scr_x=0&scr_y=0&eid=44759875%2C44759926%2C44759837%2C31082031%2C95322329%2C31081872%2C31081792%2C95328825%2C31078663%2C31078665%2C31078668%2C31078670&oid=2&pvsid=3031284066677754&tmod=1846353226&uas=0&nvt=1&fsapi=1&fc=1920&brdim=0%2C0%2C0%2C0%2C1280%2C0%2C1280%2C984%2C1280%2C907&vis=1&rsz=%7C%7Cs%7C&abl=NS&fu=32768&bc=31&bz=1&td=1&psd=W251bGwsbnVsbCxudWxsLDNd&nt=1&ifi=1&uci=a!1&fsb=1&dtd=763
https://securepubads.g.doubleclick.net/static/topics/topics_frame.html
https://googleads.g.doubleclick.net/pagead/drt/s?v=r20120211
https://googleads.g.doubleclick.net/pagead/html/r20240321/r20110914/zrt_lookup_fy2021.html
about:blank
https://googleads.g.doubleclick.net/pagead/drt/si?st=NO_DATA
https://googleads.g.doubleclick.net/pagead/html/r20240321/r20110914/zrt_lookup_fy2021.html#RS-0-&adk=1812271808&client=ca-pub-1349470098454340&fa=8&ifi=4&uci=a!4
https://s0.2mdn.net/sadbundle/10879140509440876581/TF-Display-2022-08-CriminalHTMLAds-728x90-peeking.html?ev=01_250
https://googleads.g.doubleclick.net/pagead/html/r20240321/r20110914/zrt_lookup_fy2021.html#RS-1-&adk=1812271801&client=ca-pub-1349470098454340&fa=1&ifi=5&uci=a!5&btvi=1
https://www.google.com/recaptcha/api2/aframe
https://ad.doubleclick.net/ddm/adi/N527801.3245556TRUTHFINDER/B20886704.346115576;dc_ver=99.292;dc_eid=40004000;sz=728x90;u_sd=1;gdpr=0;nel=1;dc_adk=1972255007;ord=e4eowe;click=https%3A%2F%2Fadclick.g.doubleclick.net%2Faclk%3Fsa%3Dl%26ai%3DCZuHNnRkDZsi_ObjvxtYPzOyw-A7VwLygdbDykJzrEMCNtwEQASCNvv4gYMnuoIzQpPQPoAGa4t_IA8gBCagDAcgDAqoE-AFP0BpOeyrEOmgPLs0Me1Pvz5gFovM40wS9RAxHhvISVAepX5r2UF2fImsdPujw1U4gSqTTSyujejjCx7HekYWDjrW-fP2GFTGFAMhLOi7_i2Fa2x7DRnvHL0X9P2ymTQoEjhv_tYvj7Hf_GPii38VjstJM-c0tucUKhGxrZbRSiemKZ_SvGGWZQyGGCC3qt5iK_vbt9dSzNH4xEXs1L6zeyjR4wLYt3QhIVPuLKHLMfj6gQpNCXYkkdO-85Yd_fIlCdQ3l3kkY_ilD5cglVuBNoqZsF_zVnmdbr9N6dQwvyFL9mRZ1gUVpuhZm9IrXagnlQSqeyrJ2SsAEooOvwpgEiAWu0N6SBqAGEYAH_9LYiAGoB6--sQKoB9XJG6gHpr4bqAeOzhuoB5PYG6gH7paxAqgH_p6xAqgHmgaoB_PRG6gHltgbqAeqm7ECqAeDrbECqAfgvbECqAf_nrECqAffn7ECqAfKqbECqAfrpbECqAfqsbECqAeZtbECqAe-t7EC2AcA0ggkCIBhEAEYHzICigI6CYBAgMCAgICgKEi9_cE6WMXGiO3MkoUDgAoBmAsByAsBgAwB2gwQCgoQkMCR-5iqif5mEgIBA6oNAlVTyA0B2BMM0BUBmBYB-BYBgBcBshgJEgKUaxgRIgEA%26ase%3D2%26gclid%3DEAIaIQobChMIiIKJ7cyShQMVuLfRBB1MNgzvEAEYASAAEgI7nfD_BwE%26num%3D1%26cid%3DCAQSTwB7FLtqS_PijDA2af4w7ZV5RwZ0KAGVZaGQpBrPqNO6fEg0gPINfVGhlxFpJcuzbYZM_PeqpOgtwUMHC_9fI9jXUC1uf379U6YiEAVw_eUYAQ%26sig%3DAOD64_3AlRlW8h0mDwgLmqSIyMSsQB2UOg%26client%3Dca-pub-1349470098454340%26adurl%3D;uach=WyJXaW5kb3dzIiwiMTAuMC4wIiwieDg2IiwiIiwiMTE3LjAuNTkzOC4xMzIiLG51bGwsMCxudWxsLCI2NCIsW1siR29vZ2xlIENocm9tZSIsIjExNy4wLjU5MzguMTMyIl0sWyJOb3Q7QT1CcmFuZCIsIjguMC4wLjAiXSxbIkNocm9taXVtIiwiMTE3LjAuNTkzOC4xMzIiXV0sMF0.;dc_rfl=1,https%3A%2F%2Fwilliamsontx.mugshots.zone%2F$0;xdt=1;crlt=xBrY53cN7S;cmpl=8;gcsr=m;stc=1;chaa=1;sttr=1583;prcl=s
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
d2rsbg09kis203.cloudfront.net
52.85.151.101
nmm-use1-prod-alb-pbs-server-1662300823.us-east-1.elb.amazonaws.com
52.1.95.24
pagead-googlehosted.l.google.com
172.253.115.132
www.googletagservices.com
172.253.115.155
securepubads46.g.doubleclick.net
142.250.31.155
ad.doubleclick.net
142.251.163.149
monetizemore-d.openx.net
34.98.64.218
adservice.google.com
172.253.115.155
blackbird-prd-ue1-alb-1973039460.us-east-1.elb.amazonaws.com
34.198.232.242
googleads.g.doubleclick.net
172.253.62.157
www3.l.google.com
172.253.62.102
williamsontx.mugshots.zone
18.219.134.116
cdnjs.cloudflare.com
104.17.25.14
www.google.com
142.251.111.99
cdn-content.ampproject.org
172.253.122.132
ib.anycast.adnxs.com
68.67.160.114
s0.2mdn.net
142.250.31.149
d23sp3kzv1t6m5.cloudfront.net
13.249.39.84
securepubads.g.doubleclick.net
unknown
ap.lijit.com
unknown
fundingchoicesmessages.google.com
unknown
cdn.mugshots.zone
unknown
cdn.ampproject.org
unknown
ib.adnxs.com
unknown
cmp.inmobi.com
unknown
pbs.nextmillmedia.com
unknown
There are 16 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.253.62.154
unknown
United States
142.251.16.132
unknown
United States
172.253.122.132
cdn-content.ampproject.org
United States
142.251.163.149
ad.doubleclick.net
United States
142.251.16.139
unknown
United States
142.251.179.148
unknown
United States
142.250.31.94
unknown
United States
172.253.62.149
unknown
United States
172.253.62.148
unknown
United States
172.253.62.102
www3.l.google.com
United States
142.251.111.99
www.google.com
United States
1.1.1.1
unknown
Australia
142.250.31.132
unknown
United States
172.253.63.95
unknown
United States
142.251.163.154
unknown
United States
142.251.167.138
unknown
United States
172.253.122.94
unknown
United States
239.255.255.250
unknown
Reserved
172.253.115.155
www.googletagservices.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States
172.253.62.157
googleads.g.doubleclick.net
United States
142.250.31.149
s0.2mdn.net
United States
13.249.39.84
d23sp3kzv1t6m5.cloudfront.net
United States
192.168.2.16
unknown
unknown
142.251.16.156
unknown
United States
142.251.16.157
unknown
United States
172.253.122.113
unknown
United States
172.253.122.155
unknown
United States
35.244.159.8
unknown
United States
34.233.56.143
unknown
United States
142.251.167.94
unknown
United States
142.251.167.95
unknown
United States
52.1.95.24
nmm-use1-prod-alb-pbs-server-1662300823.us-east-1.elb.amazonaws.com
United States
172.253.115.99
unknown
United States
172.253.62.99
unknown
United States
142.251.16.84
unknown
United States
142.251.163.97
unknown
United States
142.251.179.207
unknown
United States
142.251.163.95
unknown
United States
172.253.115.95
unknown
United States
18.219.134.116
williamsontx.mugshots.zone
United States
68.67.160.114
ib.anycast.adnxs.com
United States
142.251.111.154
unknown
United States
68.67.160.117
unknown
United States
142.251.167.154
unknown
United States
142.250.31.155
securepubads46.g.doubleclick.net
United States
142.250.31.156
unknown
United States
142.251.163.132
unknown
United States
172.253.115.207
unknown
United States
34.198.232.242
blackbird-prd-ue1-alb-1973039460.us-east-1.elb.amazonaws.com
United States
34.98.64.218
monetizemore-d.openx.net
United States
52.85.151.101
d2rsbg09kis203.cloudfront.net
United States
172.253.115.132
pagead-googlehosted.l.google.com
United States
There are 43 hidden IPs, click here to show them.