IOC Report
https://wetransfer.com/downloads/bd15c1f671ae60c5a56e558eb8cc43bf20241030150256/3b30cd5b9ce1ffb29d79c9118153941c20241030150256/70baef?t_exp=1730559776&t_lsid=6bd545a9-d09b-4abd-a317-124dbe9fe64d&t_network=email&t_rid=YXV0aDB8NjZlYWI0YTExODhmYzc1OGMzMmNiODIx&t_s=download_link&t_ts=1730300576&utm_camp

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 15:37:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 15:37:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 15:37:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 15:37:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 15:37:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\Downloads\Technical_Specifications_Datasheet_&_Project_Blueprint.html (copy)
HTML document, ASCII text, with very long lines (1952), with CRLF line terminators
dropped
C:\Users\user\Downloads\Technical_Specifications_Datasheet_&_Project_Blueprint.html.crdownload (copy)
HTML document, ASCII text, with very long lines (1952), with CRLF line terminators
dropped
C:\Users\user\Downloads\f81a0a24-f08c-4d64-a9d7-688c9e4e171b.tmp
HTML document, ASCII text, with very long lines (1952), with CRLF line terminators
dropped

URLs

Name
IP
Malicious
https://wetransfer.com/downloads/bd15c1f671ae60c5a56e558eb8cc43bf20241030150256/3b30cd5b9ce1ffb29d79c9118153941c20241030150256/70baef?t_exp=1730559776&t_lsid=6bd545a9-d09b-4abd-a317-124dbe9fe64d&t_network=email&t_rid=YXV0aDB8NjZlYWI0YTExODhmYzc1OGMzMmNiODIx&t_s=download_link&t_ts=1730300576&utm_campaign=TRN_TDL_01&utm
malicious
file:///C:/Users/user/Downloads/Technical_Specifications_Datasheet_&_Project_Blueprint.html
malicious

Domains

Name
IP
Malicious
jsdelivr.map.fastly.net
151.101.1.229
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
34.249.124.146
a2372.casalemedia.com
209.204.225.54
global.px.quantserve.com
91.228.74.200
s.dsp-prod.demandbase.com
34.96.71.22
p.tvpixel.com
99.83.205.94
d-ams1.turn.com
46.228.164.13
eu-eb2.3lift.com
13.248.245.213
cdn.w55c.net
18.158.171.52
cm.g.doubleclick.net
172.217.16.194
idaas-ext.cph.liveintent.com
35.171.231.154
ds-pr-bh.ybp.gysm.yahoodns.net
18.200.53.175
www.google.com
142.250.184.228
wetransfer.fides-cdn.ethyca.com
18.245.86.74
imagsync-lhrpairbc.pubmatic.com
185.64.191.214
cdn.brandmetrics.com
172.67.69.191
bsp-proxy.wetransfer.net
54.217.172.44
match.adsrvr.org
3.33.220.150
star-mini.c10r.facebook.com
157.240.251.35
match.prod.bidr.io
54.170.178.201
d8ghbpr3r4dzt.cloudfront.net
13.33.187.85
nydc1.outbrain.org
64.202.112.223
dna8twue3dlxq.cloudfront.net
13.32.121.100
firewall-external-2134955858.eu-west-1.elb.amazonaws.com
52.214.78.21
d162h6x3rxav67.cloudfront.net
18.66.112.44
d1ykf07e75w7ss.cloudfront.net
108.138.6.136
download.wetransfer.com
18.245.60.84
analytics-v2.wetransfer.com
18.245.86.11
prod.pinterest.global.map.fastly.net
151.101.0.84
ssum-sec.casalemedia.com
104.18.36.155
di.rlcdn.com
35.244.174.68
googleads.g.doubleclick.net
142.250.181.226
js-sec.indexww.com
104.18.38.76
dualstack.pinterest.map.fastly.net
151.101.192.84
challenges.cloudflare.com
104.18.94.41
ekstrom.wetransfer.net
52.48.5.216
wetransfer.com
143.204.98.97
experiments.wetransfer.com
13.33.187.50
tagging.wetransfer.com
18.245.46.98
nolan.wetransfer.net
18.245.162.11
s0.2mdn.net
142.250.185.166
simple-redirect-eu-west-1-kaas-blue.sre.nielsen.com
52.48.211.82
htlb.casalemedia.com
104.18.36.155
low0qsz1te4er83672235911c6a3.fanaticsretailgroupindividual.icu
188.114.96.3
dg2iu7dxxehbo.cloudfront.net
18.172.103.101
backgrounds.wetransfer.net
65.9.66.34
insight.adsrvr.org
15.197.193.217
scontent.xx.fbcdn.net
157.240.251.9
code.jquery.com
151.101.194.137
sni1gl.wpc.upsiloncdn.net
152.199.21.175
rtb.adentifi.com
44.213.140.1
ara.paa-reporting-advertising.amazon
18.245.46.109
sync.srv.stackadapt.com
3.209.70.78
thrtle.com
54.159.18.116
lebowski.wetransfer.com
54.228.158.30
a.nel.cloudflare.com
35.190.80.1
ax-0001.ax-dc-msedge.net
150.171.30.10
s.amazon-adsystem.com
98.82.157.137
ad.doubleclick.net
172.217.23.102
e-prod-alb-s105-us-east-1-01.adzerk.net
3.209.79.2
api.pico.bendingspoonsapps.com
34.102.204.67
ax-0001.ax-msedge.net
150.171.27.10
prod-cdn.wetransfer.net
13.32.27.4
dt-external-521234871.us-west-2.elb.amazonaws.com
52.24.157.58
dsum-sec.casalemedia.com
172.64.151.101
donny.wetransfer.com
54.155.202.146
dt-external-217593033.us-east-1.elb.amazonaws.com
107.20.123.147
www.datadoghq-browser-agent.com
13.33.219.205
cdn.wetransfer.com
143.204.98.71
auth-session-caching.wetransfer.net
34.240.255.32
ib.anycast.adnxs.com
185.89.210.46
pm.w55c.net
unknown
snowplow.wetransfer.com
unknown
ads.stickyadstv.com
unknown
z.moatads.com
unknown
pixel.adsafeprotected.com
unknown
js.adsrvr.org
unknown
s.company-target.com
unknown
privacy.wetransfer.com
unknown
pixel.rubiconproject.com
unknown
connect.facebook.net
unknown
secure-gl.imrworldwide.com
unknown
1f2e7.v.fwmrm.net
unknown
83rlahvezbatmc6b7zf4tpedq4dzg1730306290.darnuid.imrworldwide.com
unknown
d.turn.com
unknown
ir.surveywall-api.survata.com
unknown
cdn.jsdelivr.net
unknown
image8.pubmatic.com
unknown
ct.pinterest.com
unknown
fw.adsafeprotected.com
unknown
aadcdn.msauthimages.net
unknown
dt.adsafeprotected.com
unknown
k8s1-event-tracker-la.lb.indexww.com
unknown
pr-bh.ybp.yahoo.com
unknown
cs.lkqd.net
unknown
www.facebook.com
unknown
c.amazon-adsystem.com
unknown
i.liadm.com
unknown
public.profitwell.com
unknown
collector.brandmetrics.com
unknown
There are 90 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
34.241.194.212
unknown
United States
142.250.186.68
unknown
United States
151.101.0.84
prod.pinterest.global.map.fastly.net
United States
65.9.66.18
unknown
United States
91.228.74.200
global.px.quantserve.com
United Kingdom
54.217.17.146
unknown
United States
98.82.157.137
s.amazon-adsystem.com
United States
52.16.248.34
unknown
United States
143.204.98.97
wetransfer.com
United States
54.228.158.30
lebowski.wetransfer.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
35.171.231.154
idaas-ext.cph.liveintent.com
United States
3.209.70.78
sync.srv.stackadapt.com
United States
172.67.69.191
cdn.brandmetrics.com
United States
18.245.86.11
analytics-v2.wetransfer.com
United States
34.249.124.146
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
United States
34.247.9.27
unknown
United States
1.1.1.1
unknown
Australia
13.248.245.213
eu-eb2.3lift.com
United States
54.159.18.116
thrtle.com
United States
3.209.79.2
e-prod-alb-s105-us-east-1-01.adzerk.net
United States
18.66.112.44
d162h6x3rxav67.cloudfront.net
United States
18.66.112.50
unknown
United States
142.250.185.193
unknown
United States
108.138.6.136
d1ykf07e75w7ss.cloudfront.net
United States
44.213.140.1
rtb.adentifi.com
United States
239.255.255.250
unknown
Reserved
172.217.23.102
ad.doubleclick.net
United States
142.250.185.194
unknown
United States
184.28.89.220
unknown
United States
142.250.186.142
unknown
United States
152.199.21.175
sni1gl.wpc.upsiloncdn.net
United States
35.244.174.68
di.rlcdn.com
United States
151.101.192.84
dualstack.pinterest.map.fastly.net
United States
18.200.53.175
ds-pr-bh.ybp.gysm.yahoodns.net
United States
108.138.26.38
unknown
United States
52.24.157.58
dt-external-521234871.us-west-2.elb.amazonaws.com
United States
216.58.206.34
unknown
United States
52.48.208.18
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.166
s0.2mdn.net
United States
18.134.84.24
unknown
United States
157.240.0.6
unknown
United States
64.233.166.84
unknown
United States
46.228.164.13
d-ams1.turn.com
United Kingdom
13.33.187.87
unknown
United States
150.171.30.10
ax-0001.ax-dc-msedge.net
United States
13.33.187.85
d8ghbpr3r4dzt.cloudfront.net
United States
142.250.186.132
unknown
United States
99.83.205.94
p.tvpixel.com
United States
54.217.172.44
bsp-proxy.wetransfer.net
United States
185.89.210.46
ib.anycast.adnxs.com
Germany
52.48.211.82
simple-redirect-eu-west-1-kaas-blue.sre.nielsen.com
United States
150.171.27.10
ax-0001.ax-msedge.net
United States
142.250.181.226
googleads.g.doubleclick.net
United States
18.245.46.51
unknown
United States
52.48.5.216
ekstrom.wetransfer.net
United States
13.33.219.205
www.datadoghq-browser-agent.com
United States
188.114.96.3
low0qsz1te4er83672235911c6a3.fanaticsretailgroupindividual.icu
European Union
75.2.57.54
unknown
United States
52.214.78.21
firewall-external-2134955858.eu-west-1.elb.amazonaws.com
United States
209.204.225.54
a2372.casalemedia.com
Canada
142.250.185.98
unknown
United States
104.18.187.31
unknown
United States
52.48.47.179
unknown
United States
18.245.86.118
unknown
United States
107.20.123.147
dt-external-217593033.us-east-1.elb.amazonaws.com
United States
13.32.121.46
unknown
United States
34.102.204.67
api.pico.bendingspoonsapps.com
United States
154.54.250.80
unknown
United States
143.204.98.51
unknown
United States
151.101.66.137
unknown
United States
142.250.184.225
unknown
United States
142.250.184.228
www.google.com
United States
34.240.255.32
auth-session-caching.wetransfer.net
United States
3.33.220.150
match.adsrvr.org
United States
13.32.27.84
unknown
United States
18.245.60.84
download.wetransfer.com
United States
108.138.26.29
unknown
United States
34.96.71.22
s.dsp-prod.demandbase.com
United States
185.89.210.122
unknown
Germany
104.18.95.41
unknown
United States
104.18.36.155
ssum-sec.casalemedia.com
United States
104.18.38.76
js-sec.indexww.com
United States
13.33.187.50
experiments.wetransfer.com
United States
18.245.162.11
nolan.wetransfer.net
United States
185.64.191.214
imagsync-lhrpairbc.pubmatic.com
United Kingdom
188.114.97.3
unknown
European Union
64.202.112.223
nydc1.outbrain.org
United States
172.217.16.194
cm.g.doubleclick.net
United States
18.245.46.38
unknown
United States
52.223.40.198
unknown
United States
172.217.16.198
unknown
United States
216.58.206.70
unknown
United States
13.32.121.100
dna8twue3dlxq.cloudfront.net
United States
104.26.1.90
unknown
United States
18.245.86.84
unknown
United States
54.170.178.201
match.prod.bidr.io
United States
18.172.103.101
dg2iu7dxxehbo.cloudfront.net
United States
54.205.46.242
unknown
United States
There are 90 hidden IPs, click here to show them.