Windows
Analysis Report
https://safety.wetransfer.com/report?productUrl=https://wetransfer.com/downloads/7d47cd6c6811547fd81babd91c52e6d720250409164013/47451c?t_exp=1746808819&t_network=link&t_rid=YXV0aDB8YWRyb2l0fDg2YzNlODFmLTc0MjAtNGQzNS1hYWJiLTAyNjM0ZmYwMmM3MQ%3D%3D&t_s=download_link&t_ts=1744216813
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 6960 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6216 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1868,i ,323910657 4771818771 ,151806949 2800775788 2,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version --mojo-pl atform-cha nnel-handl e=2156 /pr efetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 380 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://safet y.wetransf er.com/rep ort?produc tUrl=https ://wetrans fer.com/do wnloads/7d 47cd6c6811 547fd81bab d91c52e6d7 2025040916 4013/47451 c?t_exp=17 46808819&t _network=l ink&t_rid= YXV0aDB8YW Ryb2l0fDg2 YzNlODFmLT c0MjAtNGQz NS1hYWJiLT AyNjM0ZmYw MmM3MQ%3D% 3D&t_s=dow nload_link &t_ts=1744 216813" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Memory has grown: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Extra Window Memory Injection | 1 Extra Window Memory Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
safety-hub.wetransfer.com | 18.164.78.45 | true | false | unknown | |
www.google.com | 142.250.190.4 | true | false | high | |
safety.wetransfer.com | 54.217.242.208 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.253.124.100 | unknown | United States | 15169 | GOOGLEUS | false | |
142.251.15.100 | unknown | United States | 15169 | GOOGLEUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
142.250.190.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
64.233.176.84 | unknown | United States | 15169 | GOOGLEUS | false | |
54.217.242.208 | safety.wetransfer.com | United States | 16509 | AMAZON-02US | false | |
142.251.15.94 | unknown | United States | 15169 | GOOGLEUS | false | |
108.177.122.95 | unknown | United States | 15169 | GOOGLEUS | false | |
108.128.252.147 | unknown | United States | 16509 | AMAZON-02US | false | |
18.164.78.45 | safety-hub.wetransfer.com | United States | 3 | MIT-GATEWAYSUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1663839 |
Start date and time: | 2025-04-12 17:43:22 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://safety.wetransfer.com/report?productUrl=https://wetransfer.com/downloads/7d47cd6c6811547fd81babd91c52e6d720250409164013/47451c?t_exp=1746808819&t_network=link&t_rid=YXV0aDB8YWRyb2l0fDg2YzNlODFmLTc0MjAtNGQzNS1hYWJiLTAyNjM0ZmYwMmM3MQ%3D%3D&t_s=download_link&t_ts=1744216813 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@21/15@8/56 |
- Exclude process from analysis
(whitelisted): svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.15.100, 14 2.251.15.102, 142.251.15.138, 142.251.15.101, 142.251.15.139 , 142.251.15.113, 142.251.15.9 4, 172.253.124.100, 172.253.12 4.138, 172.253.124.139, 172.25 3.124.113, 172.253.124.102, 17 2.253.124.101, 64.233.176.84, 173.194.219.138, 173.194.219.1 13, 173.194.219.101, 173.194.2 19.102, 173.194.219.139, 173.1 94.219.100, 74.125.138.139, 74 .125.138.102, 74.125.138.138, 74.125.138.101, 74.125.138.100 , 74.125.138.113, 108.177.122. 95, 64.233.177.95, 74.125.136. 95, 172.253.124.95, 74.125.138 .95, 142.250.9.95, 173.194.219 .95, 64.233.185.95, 74.125.21. 95, 142.250.105.95, 172.217.21 5.95, 64.233.176.95 - Excluded domains from analysis
(whitelisted): clients2.googl e.com, accounts.google.com, re director.gvt1.com, content-aut ofill.googleapis.com, clientse rvices.googleapis.com, clients .l.google.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data. - VT rate limit hit for: https:
//safety.wetransfer.com/report ?productUrl=https://wetransfer .com/downloads/7d47cd6c6811547 fd81babd91c52e6d72025040916401 3/47451c?t_exp=1746808819& t_network=link&t_rid=YXV0a DB8YWRyb2l0fDg2YzNlODFmLTc0MjA tNGQzNS1hYWJiLTAyNjM0ZmYwMmM3M Q%3D%3D&t_s=download_link& amp;t_ts=1744216813
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 88803 |
Entropy (8bit): | 5.427174975622368 |
Encrypted: | false |
SSDEEP: | |
MD5: | D28BC26C36C89ADC8D4C682F9727B1D6 |
SHA1: | 727FFDD73704438609896D2A7E8BCF0126A44288 |
SHA-256: | 1C9E3B7453E097CCB81D6637FFFB8A75BDB441C6CF2BC572B5F17A613FE47D84 |
SHA-512: | 11E93B8531A3FBFFB020ABD41FFB6D9C4FE51194AA0DB8975C5A71669821ABBC106DF2B1C3B55D96291C6D72F4C01E1CCB6EA00F122E5D80ED3917A5F6391E41 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/869-68e921f20a2c4cdd.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 149929 |
Entropy (8bit): | 5.481488778592261 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8E6B6F973FB6DA3A4084E486565241ED |
SHA1: | 1645B6E2E6D4B254773BBB4B320D291D724FD321 |
SHA-256: | 419A5DCBBDCD4A8D226CC4828B3B83C8834D37268A78BC3EE52B33E934497192 |
SHA-512: | CF581CD549C3331240EC4430131FD67D32E4AE1988ECF54854337353379870E216C0C3DEC6364281D0ECD9CA84F3373DA9279ACC83719585F06F139D75DA9C17 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/29-e5c1236ed7a2ace9.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17044 |
Entropy (8bit): | 5.201698302589305 |
Encrypted: | false |
SSDEEP: | |
MD5: | F9827A15AC0963FC2089A0C62563F94A |
SHA1: | 3FD0068B734CFDD539575E9FA618D98F8438B1AC |
SHA-256: | 6167DFDB89CCAA75FC261115ED8A9D5C4BC492B5D93F19624F0AC39EB99921B7 |
SHA-512: | B7C6443A9CA7EF42C400A54AF56109310B07745E73BF6C85CEC3E25E024EA7F3D2D216A186C5972468DBB85EA47CC8503659F95D4F8426FD5815039FE05344C2 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/app/report/page-c1edcc336b7c53bd.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 109760 |
Entropy (8bit): | 5.325160004234391 |
Encrypted: | false |
SSDEEP: | |
MD5: | CB18EDB92EC72F27E6D4E762A70D4128 |
SHA1: | D324EB7320515E1D3ABDDBEB95EB67B89A272806 |
SHA-256: | 9EEA4D3BDAA9E8331A6EA32FC9F6AAE260C396A3C485E097D18B3B8D902E0DA9 |
SHA-512: | 22DFCC19126095589B2AEC070210E5DC1610D522558CC74F2F25C70A752A1D5A236B41F77E27B591ED2ADD8A704D136C3413A767A12D5AEC1E0481B2720CDCC0 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/472-baccb264751cbb0e.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7999 |
Entropy (8bit): | 5.226000652651312 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8A2984F39D5053E8804B3B3DBDC0D9C0 |
SHA1: | 78CC104D1AA6FD297A4E40448288229DB1F62A55 |
SHA-256: | 4B216CE7FFA0A8D41B8E32B2F828DF5624B232365ECE7CBC78F0AECE9970CBDA |
SHA-512: | 02483B44C33B16EDD1988F6750139FEDABB2207A047ADAEDA946E0F83F555EBA962BE12D2E1DE1426AD9E7882DD45D3410D71855EEE3E2AFB2E0C927ACE50037 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/css/8e942da3f9912610.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 11740 |
Entropy (8bit): | 5.505268916704868 |
Encrypted: | false |
SSDEEP: | |
MD5: | BBF59694E833A4F34EA87D8C0E05DDB0 |
SHA1: | F1F3C1A300EEE20FC92C5771E0D317284A9A0F3C |
SHA-256: | 40A57120A828EFC676A49157F765F0370C5AC7DBEB1ED56536C785B52C27F266 |
SHA-512: | F8A37A4ECF2417AF0FDA775598F6E2516E3A69BD3C90B872D271647464922825026B13AF246B2B247EB3F27D26B5457491BD212C7E4B19F694C9833A3702D4BC |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/app/layout-a2f723c0ce072f4e.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 56 |
Entropy (8bit): | 4.677279698572887 |
Encrypted: | false |
SSDEEP: | |
MD5: | 513D4FF1D6F682ADE10347566CC95551 |
SHA1: | 68F16CC97E6EB882803CA3C4E83A43A5401448F1 |
SHA-256: | 50B12E11C93FE0145B18341B7BE4DD2082F723801B90CF9077DE16FA3307E350 |
SHA-512: | 0508647FA25D88BA53ADDE44F97E5EB476751B2033B72E18C24056EAE0967F4E50145889B624C9D28BC97A2E98EB393F9FC6787137687CBB78839E882B0C1294 |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIuCW-tdMZkyFMOEgUNgVEughIFDYOoWz0SBQ2UVPrPEgUNZecJJiFRb6KlhAUPGg==?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5635 |
Entropy (8bit): | 5.437707041850306 |
Encrypted: | false |
SSDEEP: | |
MD5: | C49D8CE33856B069B17929DA92F0C809 |
SHA1: | 0A04FAA1A2D96DBADCE6337ECBD1B829380C8E32 |
SHA-256: | D4A3CCFB3A8DD8ED9DECDF654A78587E27EA1208A5BF4D764B0F0821604761AC |
SHA-512: | 7B9033D4E4A7B160E10E99B3436BE06EB9DC962C6801B2237F20F0C252AEDF4E6A371268E0ED0094F2008973FC1276CA04CF64A717C05ACBD5D38492B118D761 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/304-e940b7473b2fb1a3.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 82079 |
Entropy (8bit): | 5.29687375408379 |
Encrypted: | false |
SSDEEP: | |
MD5: | F0C4F412DCD075B8D9C8FB9C30BFB909 |
SHA1: | 05204A82336A553163E8D2963ED53A68A15EAED5 |
SHA-256: | BB0EBEA1DB4043769108346705E073B333EF942337CCF862A5B5B2324A6CD7E9 |
SHA-512: | A0CCDDBF5A513091AF182BD86536D36D9DE42C8533F216A8BD507C307865A686054220FB2D4819F6CC63D4A9DEB382417921DC788F2EF582CBF2C5F80CFB461F |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/626-3410d6c89b842ad7.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 13177 |
Entropy (8bit): | 4.52255731690471 |
Encrypted: | false |
SSDEEP: | |
MD5: | FD617EF488BBD7032DD87B7FFE0D191C |
SHA1: | 4806E21A408314D86603E1F2108ECEEA472F169E |
SHA-256: | FA0E67F2B16D3CB8D86FCF264C6082788A9FFD053D6F64A720C81E0BD3604B7C |
SHA-512: | 0019500C265BDB3FEB03E6246C7A74220AAA3B642260336DC43736EB50879C923EAFBA9FE6F60E6D40DD9DAA687A648A07215B3FF49AFDABFE7659BC7021AE13 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety.wetransfer.com/api/getCategories |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4216 |
Entropy (8bit): | 5.374571444824168 |
Encrypted: | false |
SSDEEP: | |
MD5: | 933E149FC9F801B0B22C237F6CED31A4 |
SHA1: | 0D4DF8EE140E8134411DA1D0BE8C054341A516C5 |
SHA-256: | CBEB970C66FE3D2682817952C33C85F22EE39B89EF13E5A5A38B94A6818F939E |
SHA-512: | 793FB3A76EA1BA99756EA28769B5F26844E049E69CFBED489B24E394F9636A0E26284F478453F10C21A6F0268B8592AF5CFC7C5ECA1878771B9A61046D9974C1 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/webpack-1ed0dab5f68b0f33.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 463 |
Entropy (8bit): | 5.047317901744565 |
Encrypted: | false |
SSDEEP: | |
MD5: | C4545E05A2F3E820749C810D91D84940 |
SHA1: | 044CA1C75EC227AA064BA9E226004894A83D6631 |
SHA-256: | 8ED15B9866DF7A7160E7F4DEA47D1AF150BC667FC73B04F3BF06ACF7C4B4BAA6 |
SHA-512: | F720D20F8F7125CEB5C2B340BCCDC2A0EB6ED75F44376BE37D23826F481779BBE14459BCFA3FC063FF7BF685307ADAAE16BF32B2F596311F61BEC3201C5A5BD5 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/main-app-88b2dc2b3fa32f47.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41566 |
Entropy (8bit): | 2.306414372045211 |
Encrypted: | false |
SSDEEP: | |
MD5: | 692E1C7339C359B6412F059C9C9A0474 |
SHA1: | E7C1A53DCA16B7664880E5B8A92524CF9A47FB62 |
SHA-256: | D12161435ACE47C6883360E08466508593325F134C1852B1D0E6E75D5F76ADDA |
SHA-512: | 115B958093186BF5F98BECED2BDE91775121083B1E73F720372D793A23EBC7CF130CC4C6196F5F0D725A809FD63997666AE1DE36CF070DCB6B6D2178C6796894 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18672 |
Entropy (8bit): | 5.073126959704564 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1F46142084940AECD7745FA1858ACD67 |
SHA1: | AB8C61B60B8F4BA9D2B054066F98456269D05B1E |
SHA-256: | C078974A6C34E4F6FABABA9DEFC1D8B6431C7FB871DF69A878DBA0E04C6FE8AA |
SHA-512: | 9F092EDA40CAD8AFBE966235A4C65AE8FF60C66B244CA3E81ABF75DE7C6D15A6548CF536BD44F8694DA8A97929F8E45D1D7E6B890FD1D5641D77AF1633A992DA |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/css/d114a38c5e46c19d.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 171902 |
Entropy (8bit): | 5.246680638995744 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9DEE4994F9E89448FF05C84F6BB40B96 |
SHA1: | 41A9685C063EA850B14CF5BE64502A17A637D529 |
SHA-256: | 8AFE99281B9756F2EB2F78BED72A926553F880B1B9DD12F5BBDDFCE6CC4BDF2B |
SHA-512: | A709D4A77AB46680DD8D0F81178BF883C3B285D0E1CE721A42BAC58C55F1589380D3709FD0363675C52C4843A792AD762EB91874CFF99C3284D105CD461D1D68 |
Malicious: | false |
Reputation: | unknown |
URL: | https://safety-hub.wetransfer.com/_next/static/chunks/fd9d1056-5d1888406a6a45ed.js |
Preview: |