IOC Report
https://wetransfer.com/downloads/e31c675f4d1575e8f8705ec0cb75047e20190206162658/ba82a30565ecfa365c3cdbb0c257063820190206162658/9cc10a

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 26 05:59:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 26 05:59:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 26 05:59:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 26 05:59:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 26 05:59:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 194
ASCII text, with very long lines (422), with no line terminators
dropped
Chrome Cache Entry: 197
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (12376)
dropped
Chrome Cache Entry: 201
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 208
Web Open Font Format, TrueType, length 31120, version 1.6554
downloaded
Chrome Cache Entry: 209
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (42170)
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (7728)
dropped
Chrome Cache Entry: 217
Web Open Font Format (Version 2), TrueType, length 27440, version 1.0
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 221
ASCII text, with very long lines (4054), with no line terminators
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (699)
dropped
Chrome Cache Entry: 229
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 4148x2208, components 3
downloaded
Chrome Cache Entry: 230
ASCII text, with very long lines (1472)
downloaded
Chrome Cache Entry: 232
ASCII text, with very long lines (26406)
dropped
Chrome Cache Entry: 236
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (26464)
downloaded
Chrome Cache Entry: 239
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 242
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 254
JSON data
dropped
Chrome Cache Entry: 256
Web Open Font Format (Version 2), TrueType, length 35884, version 1.0
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (8949)
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 262
HTML document, ASCII text
downloaded
Chrome Cache Entry: 263
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 265
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (3679)
dropped
Chrome Cache Entry: 273
ASCII text, with very long lines (4442)
dropped
Chrome Cache Entry: 274
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (54894)
downloaded
Chrome Cache Entry: 277
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (26297)
dropped
Chrome Cache Entry: 283
JSON data
dropped
Chrome Cache Entry: 286
JSON data
downloaded
Chrome Cache Entry: 287
ASCII text, with very long lines (16769)
dropped
Chrome Cache Entry: 288
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 293
ASCII text, with very long lines (4877), with no line terminators
downloaded
Chrome Cache Entry: 296
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 297
ASCII text, with very long lines (1308)
dropped
Chrome Cache Entry: 299
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 300
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 302
ASCII text, with very long lines (25927)
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (11635)
dropped
Chrome Cache Entry: 311
Unicode text, UTF-8 text, with very long lines (11346), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 312
Unicode text, UTF-8 text, with very long lines (36859), with CRLF line terminators
downloaded
Chrome Cache Entry: 314
Web Open Font Format (Version 2), TrueType, length 27984, version 1.0
downloaded
Chrome Cache Entry: 315
JSON data
dropped
Chrome Cache Entry: 317
JSON data
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (53562), with no line terminators
dropped
Chrome Cache Entry: 321
Web Open Font Format (Version 2), TrueType, length 28644, version 1.0
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 323
ASCII text, with very long lines (16769)
downloaded
Chrome Cache Entry: 324
Web Open Font Format, TrueType, length 43188, version 0.0
downloaded
Chrome Cache Entry: 327
ASCII text, with very long lines (4730), with no line terminators
dropped
Chrome Cache Entry: 328
gzip compressed data, was "main.babde0ae.js", last modified: Tue Nov 19 01:36:23 2024, from Unix, original size modulo 2^32 82781
dropped
Chrome Cache Entry: 329
ASCII text, with very long lines (1308)
dropped
Chrome Cache Entry: 330
ASCII text, with very long lines (19233), with no line terminators
downloaded
Chrome Cache Entry: 332
ASCII text, with very long lines (42170)
dropped
Chrome Cache Entry: 333
JSON data
dropped
Chrome Cache Entry: 334
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 335
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 337
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 338
ASCII text, with very long lines (44642)
downloaded
Chrome Cache Entry: 340
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 341
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (11712)
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 349
Web Open Font Format, TrueType, length 32124, version 1.6554
downloaded
Chrome Cache Entry: 350
HTML document, ASCII text, with very long lines (565), with no line terminators
downloaded
Chrome Cache Entry: 352
ASCII text, with very long lines (1308)
downloaded
Chrome Cache Entry: 354
ASCII text, with CRLF, LF line terminators
dropped
Chrome Cache Entry: 355
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 356
ISO Media, MP4 v2 [ISO 14496-14]
downloaded
Chrome Cache Entry: 358
HTML document, ASCII text
downloaded
Chrome Cache Entry: 364
HTML document, ASCII text, with very long lines (589)
downloaded
Chrome Cache Entry: 366
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 367
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 369
ASCII text, with very long lines (8874)
downloaded
Chrome Cache Entry: 375
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 379
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 380
ASCII text, with very long lines (65089)
dropped
Chrome Cache Entry: 381
ASCII text, with very long lines (15535)
dropped
Chrome Cache Entry: 385
ASCII text, with very long lines (4614), with CRLF line terminators
downloaded
Chrome Cache Entry: 387
gzip compressed data, from Unix, original size modulo 2^32 532
downloaded
Chrome Cache Entry: 392
ASCII text, with very long lines (1308)
downloaded
Chrome Cache Entry: 393
JSON data
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (56579)
dropped
Chrome Cache Entry: 396
ASCII text, with very long lines (9217)
dropped
Chrome Cache Entry: 398
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 399
HTML document, ASCII text, with very long lines (618)
downloaded
Chrome Cache Entry: 402
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (21910)
downloaded
Chrome Cache Entry: 404
ASCII text, with very long lines (9934), with no line terminators
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (34384)
dropped
Chrome Cache Entry: 417
ASCII text
dropped
Chrome Cache Entry: 418
ASCII text, with very long lines (65536), with no line terminators
dropped
There are 99 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://wetransfer.com/downloads/e31c675f4d1575e8f8705ec0cb75047e20190206162658/ba82a30565ecfa365c3cdbb0c257063820190206162658/9cc10a
https://wetransfer.com/
https://wetransfer.com/downloads/e31c675f4d1575e8f8705ec0cb75047e20190206162658/ba82a30565ecfa365c3cdbb0c257063820190206162658/9cc10a

Domains

Name
IP
Malicious
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
54.77.40.173
pug-sin12.pubmnet.com
207.65.33.82
user-data-eu.bidswitch.net
35.214.136.108
measure.lamp.avct.cloud
34.252.114.54
dg2iu7dxxehbo.cloudfront.net
13.227.2.22
adservice.google.com
172.217.19.226
backgrounds.wetransfer.net
18.165.220.19
insight.adsrvr.org
35.71.131.137
scontent.xx.fbcdn.net
157.240.196.15
cm.g.doubleclick.net
142.250.181.2
www.google.com
172.217.21.36
ara.paa-reporting-advertising.amazon
18.165.220.23
wetransfer.fides-cdn.ethyca.com
13.225.78.114
cdn.brandmetrics.com
104.26.0.90
bsp-proxy.wetransfer.net
54.77.33.29
match.adsrvr.org
52.223.40.198
star-mini.c10r.facebook.com
157.240.196.35
lebowski.wetransfer.com
52.213.46.103
s.amazon-adsystem.com
98.82.154.76
ad.doubleclick.net
172.217.17.70
e-prod-alb-s105-us-east-1-01.adzerk.net
54.147.118.178
dna8twue3dlxq.cloudfront.net
13.32.121.100
firewall-external-2134955858.eu-west-1.elb.amazonaws.com
54.247.49.181
d162h6x3rxav67.cloudfront.net
13.226.2.82
ax-0001.ax-msedge.net
150.171.27.10
d1ykf07e75w7ss.cloudfront.net
18.165.218.121
cdn.lamp.avct.cloud
13.226.2.12
analytics-v2.wetransfer.com
108.158.75.75
prod.pinterest.global.map.fastly.net
151.101.128.84
di.rlcdn.com
34.49.212.111
googleads.g.doubleclick.net
172.217.17.34
dsum-sec.casalemedia.com
104.18.26.193
donny.wetransfer.com
52.51.81.153
dt-external-217593033.us-east-1.elb.amazonaws.com
44.207.41.146
dualstack.pinterest.map.fastly.net
151.101.0.84
www.datadoghq-browser-agent.com
18.165.221.183
cdn.wetransfer.com
18.66.161.49
ekstrom.wetransfer.net
52.30.144.41
wetransfer.com
18.66.161.101
auth-session-caching.wetransfer.net
34.254.149.64
experiments.wetransfer.com
108.158.75.112
tagging.wetransfer.com
18.173.205.6
ib.anycast.adnxs.com
185.89.210.153
nolan.wetransfer.net
18.165.220.116
cdn.jsdelivr.net
unknown
snowplow.wetransfer.com
unknown
ct.pinterest.com
unknown
pixel.adsafeprotected.com
unknown
dt.adsafeprotected.com
unknown
secure.insightexpressai.com
unknown
x.bidswitch.net
unknown
www.facebook.com
unknown
js.adsrvr.org
unknown
c.amazon-adsystem.com
unknown
privacy.wetransfer.com
unknown
pixel.rubiconproject.com
unknown
connect.facebook.net
unknown
public.profitwell.com
unknown
collector.brandmetrics.com
unknown
simage2.pubmatic.com
unknown
s.pinimg.com
unknown
ib.adnxs.com
unknown
e-10220.adzerk.net
unknown
static.adsafeprotected.com
unknown
There are 54 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
151.101.0.84
dualstack.pinterest.map.fastly.net
United States
172.217.19.226
adservice.google.com
United States
172.217.17.67
unknown
United States
52.51.81.153
donny.wetransfer.com
United States
104.18.187.31
unknown
United States
172.217.17.66
unknown
United States
18.165.220.23
ara.paa-reporting-advertising.amazon
United States
185.89.210.153
ib.anycast.adnxs.com
Germany
108.158.75.75
analytics-v2.wetransfer.com
United States
151.101.128.84
prod.pinterest.global.map.fastly.net
United States
13.226.2.82
d162h6x3rxav67.cloudfront.net
United States
18.165.221.183
www.datadoghq-browser-agent.com
United States
108.158.75.119
unknown
United States
54.147.118.178
e-prod-alb-s105-us-east-1-01.adzerk.net
United States
18.66.161.66
unknown
United States
35.71.131.137
insight.adsrvr.org
United States
108.158.75.112
experiments.wetransfer.com
United States
172.67.69.191
unknown
United States
69.173.144.165
unknown
United States
104.26.0.90
cdn.brandmetrics.com
United States
1.1.1.1
unknown
Australia
104.18.186.31
unknown
United States
13.225.78.114
wetransfer.fides-cdn.ethyca.com
United States
172.217.17.34
googleads.g.doubleclick.net
United States
18.165.220.19
backgrounds.wetransfer.net
United States
13.226.2.23
unknown
United States
18.165.220.54
unknown
United States
23.218.208.36
unknown
United States
18.173.205.6
tagging.wetransfer.com
United States
52.213.46.103
lebowski.wetransfer.com
United States
64.233.165.84
unknown
United States
239.255.255.250
unknown
Reserved
13.226.2.32
unknown
United States
18.66.161.92
unknown
United States
54.77.33.29
bsp-proxy.wetransfer.net
United States
18.165.218.121
d1ykf07e75w7ss.cloudfront.net
United States
52.223.40.198
match.adsrvr.org
United States
157.240.196.35
star-mini.c10r.facebook.com
United States
172.217.17.70
ad.doubleclick.net
United States
44.207.41.146
dt-external-217593033.us-east-1.elb.amazonaws.com
United States
13.32.121.100
dna8twue3dlxq.cloudfront.net
United States
18.66.161.101
wetransfer.com
United States
35.214.136.108
user-data-eu.bidswitch.net
United States
52.31.24.224
unknown
United States
172.217.17.46
unknown
United States
192.168.2.16
unknown
unknown
54.247.49.181
firewall-external-2134955858.eu-west-1.elb.amazonaws.com
United States
52.30.144.41
ekstrom.wetransfer.net
United States
13.226.2.12
cdn.lamp.avct.cloud
United States
216.58.208.227
unknown
United States
54.77.40.173
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
United States
52.210.35.32
unknown
United States
52.208.172.50
unknown
United States
172.217.19.170
unknown
United States
54.205.49.139
unknown
United States
207.65.33.82
pug-sin12.pubmnet.com
United States
172.217.21.36
www.google.com
United States
18.66.161.49
cdn.wetransfer.com
United States
34.254.149.64
auth-session-caching.wetransfer.net
United States
98.82.154.76
s.amazon-adsystem.com
United States
54.246.207.144
unknown
United States
172.217.19.238
unknown
United States
18.165.220.116
nolan.wetransfer.net
United States
20.79.107.10
unknown
United States
34.252.114.54
measure.lamp.avct.cloud
United States
34.49.212.111
di.rlcdn.com
United States
104.18.26.193
dsum-sec.casalemedia.com
United States
142.250.181.100
unknown
United States
150.171.27.10
ax-0001.ax-msedge.net
United States
142.250.181.2
cm.g.doubleclick.net
United States
13.32.121.58
unknown
United States
157.240.196.15
scontent.xx.fbcdn.net
United States
13.227.2.22
dg2iu7dxxehbo.cloudfront.net
United States
There are 63 hidden IPs, click here to show them.