refunddavid0.werite.net
172.67.135.15
Public Scan
Open in
urlscan Pro
https://refunddavid0.werite.net/5-ehtuphl-thii-khun-aimsmkhwr-haayaip-aephltf-rm-ufa-amb 1yr old
Submission: On July 16 via manual (July 16th 2025, 12:28:43 am UTC) from FI — Scanned from IT
Summary
TLS certificate: Issued by WE1 on May 31st 2025. Valid for: 3mo.
This is the only time refunddavid0.werite.net was scanned on urlscan.io!
urlscan.io Verdict: No classification
Domain & IP information
| IP Address | AS Autonomous System | ||
|---|---|---|---|
| 9 | 172.67.135.15 172.67.135.15 | 13335 (CLOUDFLAR...) (CLOUDFLARENET) | |
| 2 | 95.128.47.156 95.128.47.156 | 41653 (AQUARAY A...) (AQUARAY Aqua Ray SAS) | |
| 1 2 | 213.186.33.87 213.186.33.87 | 16276 (OVH OVH SAS) (OVH OVH SAS) | |
| 1 | 5.135.215.212 5.135.215.212 | 16276 (OVH OVH SAS) (OVH OVH SAS) | |
| 1 | 212.129.32.216 212.129.32.216 | 12876 (AS12876 S...) (AS12876 SCALEWAY S.A.S.) | |
| 2 | 13.35.58.69 13.35.58.69 | 16509 (AMAZON-02) (AMAZON-02) | |
| 18 | 7 |
ASN41653 (AQUARAY Aqua Ray SAS, FR)
PTR: web.aquaray.com
| am.ambafrance.org 8yr old |
ASN16276 (OVH OVH SAS, FR)
PTR: cluster014.ovh.net
| armes-ufa.com 10yr old | |
| www.armes-ufa.com 10yr old |
ASN16276 (OVH OVH SAS, FR)
PTR: wordpress2.tooeasy.fr
| cfp-montplaisir.org 5yr old |
ASN12876 (AS12876 SCALEWAY S.A.S., FR)
PTR: sw-002.exoca.fr
| www.cfajeanbosco.fr 8yr old |
ASN16509 (AMAZON-02, US)
PTR: server-13-35-58-69.fra60.r.cloudfront.net
| i.snap.as 9yr old |
| Apex Domain Subdomains |
Transfer | |
|---|---|---|
| 9 |
werite.net
refunddavid0.werite.net 1yr old |
158 KB |
| 2 |
snap.as
i.snap.as 9yr old |
11 KB |
| 2 |
armes-ufa.com
1 redirects
armes-ufa.com 10yr old www.armes-ufa.com 10yr old |
1 MB |
| 2 |
ambafrance.org
am.ambafrance.org 8yr old |
240 KB |
| 1 |
cfajeanbosco.fr
www.cfajeanbosco.fr 8yr old |
516 KB |
| 1 |
cfp-montplaisir.org
cfp-montplaisir.org 5yr old |
66 KB |
| 0 |
unsplash.com
Failed
source.unsplash.com Failed 9yr old |
|
| 0 |
madel.com
Failed
www.madel.com Failed 7yr old |
|
| 18 | 8 |
| Domain | Requested by | |
|---|---|---|
| 9 | refunddavid0.werite.net |
refunddavid0.werite.net
|
| 2 | i.snap.as |
refunddavid0.werite.net
|
| 2 | am.ambafrance.org |
refunddavid0.werite.net
|
| 1 | www.cfajeanbosco.fr |
refunddavid0.werite.net
|
| 1 | cfp-montplaisir.org |
refunddavid0.werite.net
|
| 1 | www.armes-ufa.com |
refunddavid0.werite.net
|
| 1 | armes-ufa.com | 1 redirects |
| 0 | source.unsplash.com Failed |
refunddavid0.werite.net
|
| 0 | www.madel.com Failed |
refunddavid0.werite.net
|
| 18 | 9 |
This site contains links to these domains. Also see Links.
| Domain |
|---|
| ufaamb.net |
| writefreely.org |
| Subject Issuer | Validity | Valid | |
|---|---|---|---|
| werite.net WE1 |
2025-05-31 - 2025-08-29 |
3mo | crt.sh |
| *.ambafrance.org GlobalSign ECC OV SSL CA 2018 |
2024-12-12 - 2026-01-13 |
1yr | crt.sh |
| cfp-montplaisir.org R10 |
2025-06-28 - 2025-09-26 |
3mo | crt.sh |
| cfajeanbosco.fr R10 |
2025-06-01 - 2025-08-30 |
3mo | crt.sh |
| i.snap.as Amazon RSA 2048 M03 |
2025-05-24 - 2026-06-20 |
1yr | crt.sh |
This page contains 1 frames:
Primary Page:
https://refunddavid0.werite.net/5-ehtuphl-thii-khun-aimsmkhwr-haayaip-aephltf-rm-ufa-amb
Frame ID: F7476FEFA3B404D6FA6A767D04B95104
Requests: 18 HTTP requests in this frame
2 Outgoing links
These are links going to different origins than the main page.
Title: UFA AMB
Search URL Search Domain Scan URL
Title: writefreely
Search URL Search Domain Scan URL
Redirected requests
There were HTTP redirect chains for the following requests:
Request Chain 4- https://armes-ufa.com/IMG/jpg/sticker_-_1.jpg HTTP 301
- https://www.armes-ufa.com/IMG/jpg/sticker_-_1.jpg
18 HTTP transactions
0 data transactions
| Method Protocol |
Status | Resource Path |
Size x-fer |
Time Latency |
Type MIME-Type |
IP Location |
|||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
GET H2 |
200 |
Primary Request
5-ehtuphl-thii-khun-aimsmkhwr-haayaip-aephltf-rm-ufa-amb
Show response
refunddavid0.werite.net/ |
24 KB 7 KB |
1530ms
800ms |
Document
text/html |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
write.css
refunddavid0.werite.net/css/ |
56 KB 12 KB |
779ms
778ms |
Stylesheet
text/css |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
custom.css
refunddavid0.werite.net/css/ |
3 KB 2 KB |
767ms
766ms |
Stylesheet
text/css |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET |
|
UFA-DFR_Hospital-Curico_3.jpg
www.madel.com/wp-content/uploads/2015/09/ |
0 0 |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
8ab350f4720d6691-eab47.png
am.ambafrance.org/local/cache-vignettes/L720xH540/ |
165 KB 165 KB |
598ms
167ms |
Image
image/png |
95.128.47.156 AQUARAY Aqua Ray SAS |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
sticker_-_1.jpg
www.armes-ufa.com/IMG/jpg/ Redirect Chain
|
1 MB 1 MB |
134ms
99ms |
Image
image/jpeg |
213.186.33.87 OVH OVH SAS |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
Redirect headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
UFA-LOGO.png
cfp-montplaisir.org/app/uploads/2020/12/ |
66 KB 66 KB |
529ms
128ms |
Image
image/png |
5.135.215.212 OVH OVH SAS |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H/1.1 |
200 OK |
accompagnement-nouvelles-UFA-CFA-Jean-Bosco-scaled.jpg
www.cfajeanbosco.fr/wp-content/uploads/2021/06/ |
515 KB 516 KB |
585ms
136ms |
Image
image/jpeg |
212.129.32.216 AS12876 SCALEWAY ... |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
arton4674-41b91.jpg
am.ambafrance.org/local/cache-vignettes/L770xH514/ |
74 KB 74 KB |
92ms
91ms |
Image
image/jpeg |
95.128.47.156 AQUARAY Aqua Ray SAS |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
localdate.js
Show response
refunddavid0.werite.net/js/ |
697 B 652 B |
772ms
772ms |
Script
application/javascript |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET |
|
800x600
source.unsplash.com/random/ |
0 0 |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
yomRpCm.gif
i.snap.as/ |
977 B 1 KB |
760ms
103ms |
Image
image/png |
13.35.58.69 AMAZON-02 |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
0qZD5r6.gif
i.snap.as/ |
9 KB 10 KB |
797ms
142ms |
Image
image/png |
13.35.58.69 AMAZON-02 |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
webfont.js
Show response
refunddavid0.werite.net/js/ |
12 KB 5 KB |
808ms
807ms |
Script
application/javascript |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
fonts.css
refunddavid0.werite.net/css/ |
2 KB 671 B |
794ms
794ms |
Stylesheet
text/css |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
Lora-Regular.woff2
refunddavid0.werite.net/fonts/ |
62 KB 63 KB |
765ms
765ms |
Font
font/woff2 |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
Lora-Bold.woff2
refunddavid0.werite.net/fonts/ |
67 KB 67 KB |
771ms
770ms |
Font
font/woff2 |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
GET H2 |
200 |
favicon.ico
refunddavid0.werite.net/ |
6 KB 1 KB |
760ms
760ms |
Other
image/vnd.microsoft.icon |
172.67.135.15 CLOUDFLARENET |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
General
Request headers
Response headers
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||
Failed requests
These URLs were requested, but there was no response received. You will also see them in the list above.
- Domain
- www.madel.com
- URL
- https://www.madel.com/wp-content/uploads/2015/09/UFA-DFR_Hospital-Curico_3.jpg
- Domain
- source.unsplash.com
- URL
- https://source.unsplash.com/random/800x600
Verdicts & Comments Add Verdict or Comment
5 JavaScript Window variables
These are the non-standard variables defined on the window object. These include var declarations and global functions and can be helpful in identifying possible client-side frameworks and code.
function| toLocalDate object| $dates function| unpinPost object| WebFontConfig object| WebFont0 Cookies
Cookies are little pieces of information stored in the browser of a user. Whenever a user visits the site again, he will also send his cookie values, thus allowing the website to re-identify him even if he changed locations. This is how permanent logins work.
Indicators
This is a term in the security industry to describe indicators such as IPs, Domains, Hashes, etc. This does not imply that any of these indicate malicious activity.
am.ambafrance.org
armes-ufa.com
cfp-montplaisir.org
i.snap.as
refunddavid0.werite.net
source.unsplash.com
www.armes-ufa.com
www.cfajeanbosco.fr
www.madel.com
source.unsplash.com
www.madel.com
13.35.58.69
172.67.135.15
212.129.32.216
213.186.33.87
5.135.215.212
95.128.47.156
07f21b0019b177702850bd361c403dfab328f7fc8fd234396a4b334652bf1f50
12552816bf0f3bf7ff4b56eee155f2029985f23bbbb94a13c32157999ce8219a
22118b3a5aa7f7cbe3e64fb629fd6a63e9d7117b446fa92ac62a92c94662759b
26ee6f80607aa285386fc2132073fda3639fddfb3c139d7e92490de306d2b8d1
2711b037e078e306e59765e9fc22d9f86867eb26af8c6af72d864a1c52bed8ac
3d631b81c278eed048159a21c22e56f9bbf182be24f1a868907c35e75e985671
3e0c6f7fe079da02b25593dca6bed7a839bda33209229291b41b170d70334911
432281499e611a248cd062f5c4405969c514b4b611c3ebc6ed62d32de1324320
447d002c10914475cbfbd9db889e8a4267f90c4facf6af2ca22ef9c08597802f
5aad84fd548b01f6f96d44b6254b68a247e5d12800b5284c72a5310d05746ee5
8a7be585b1fb4fb1a26b547dd62ef1ae034c5ba42aad471473704a8ac9a9637a
a961725c85789a66a4cfa2e42f7e0237c9366ce03d8d25074a4c42bc14650318
baa1f0bfa6c9722fde0471a7a4ebe7b74bc5fb40e733778ce80bec12e85a404c
c3d2b0aecf07de182ab17bea18cde276f7e19b7da20b35f63ae6a3ba4595a416
dfb55ef858e45648a11635b6d64aa62bfb2ac5eb80307cfff1a2565bf82cf8cf
e94920932548ae028f306992283abea78abd79fd2fbb95b6c99a9175690f315e