IOC Report
https://returns.gatsbyshoes.co

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 18 12:11:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 18 12:11:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 18 12:11:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 18 12:11:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 18 12:11:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 213
JSON data
downloaded
Chrome Cache Entry: 214
Unicode text, UTF-8 text, with very long lines (32798), with no line terminators
downloaded
Chrome Cache Entry: 215
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (65508)
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (11426)
downloaded
Chrome Cache Entry: 219
Unicode text, UTF-8 text, with very long lines (61316)
downloaded
Chrome Cache Entry: 220
Web Open Font Format (Version 2), TrueType, length 24344, version 2.262
downloaded
Chrome Cache Entry: 226
Web Open Font Format (Version 2), TrueType, length 73080, version 1.0
downloaded
Chrome Cache Entry: 229
Unicode text, UTF-8 text, with very long lines (44742)
downloaded
Chrome Cache Entry: 230
gzip compressed data, max compression, from Unix, original size modulo 2^32 27225
downloaded
Chrome Cache Entry: 231
PNG image data, 360 x 360, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 233
ASCII text, with very long lines (65528)
downloaded
Chrome Cache Entry: 234
HTML document, ASCII text, with very long lines (719)
downloaded
Chrome Cache Entry: 236
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 237
ASCII text, with very long lines (7901), with no line terminators
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (336)
downloaded
Chrome Cache Entry: 242
PNG image data, 360 x 360, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (16147), with no line terminators
dropped
Chrome Cache Entry: 247
ASCII text, with very long lines (31043), with no line terminators
dropped
Chrome Cache Entry: 248
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 251
HTML document, ASCII text
dropped
Chrome Cache Entry: 253
JSON data
dropped
Chrome Cache Entry: 256
ASCII text, with very long lines (7747)
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (3291)
dropped
Chrome Cache Entry: 259
ASCII text, with very long lines (65465)
dropped
Chrome Cache Entry: 260
JSON data
dropped
Chrome Cache Entry: 261
PNG image data, 540 x 540, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 262
JSON data
dropped
Chrome Cache Entry: 263
JSON data
downloaded
Chrome Cache Entry: 265
Web Open Font Format (Version 2), TrueType, length 16312, version 1.66
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (21972)
dropped
Chrome Cache Entry: 268
ASCII text, with very long lines (14457)
downloaded
Chrome Cache Entry: 269
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 273
Unicode text, UTF-8 text, with very long lines (65466)
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 277
gzip compressed data, max compression, from Unix, original size modulo 2^32 362522
downloaded
Chrome Cache Entry: 279
HTML document, Unicode text, UTF-8 text, with very long lines (35170), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (34240), with no line terminators
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (2345)
downloaded
Chrome Cache Entry: 283
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (495), with no line terminators
downloaded
Chrome Cache Entry: 285
PNG image data, 233 x 70, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 286
ASCII text, with very long lines (32066)
dropped
Chrome Cache Entry: 287
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 292
Unicode text, UTF-8 text, with very long lines (61316)
downloaded
Chrome Cache Entry: 296
ASCII text, with very long lines (20233), with no line terminators
dropped
Chrome Cache Entry: 297
gzip compressed data, max compression, from Unix, original size modulo 2^32 476
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (54456), with no line terminators
downloaded
Chrome Cache Entry: 300
Unicode text, UTF-8 text, with very long lines (22646)
dropped
Chrome Cache Entry: 301
ASCII text, with very long lines (11575)
downloaded
Chrome Cache Entry: 306
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (674)
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (2812), with no line terminators
dropped
Chrome Cache Entry: 313
ASCII text, with very long lines (23843), with escape sequences
downloaded
Chrome Cache Entry: 315
JSON data
downloaded
Chrome Cache Entry: 316
PNG image data, 149 x 33, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 318
HTML document, ASCII text
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (32117)
downloaded
Chrome Cache Entry: 322
PNG image data, 360 x 360, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 323
Unicode text, UTF-8 text, with very long lines (36539)
dropped
Chrome Cache Entry: 324
ASCII text, with very long lines (6497), with no line terminators
dropped
Chrome Cache Entry: 326
ASCII text
downloaded
Chrome Cache Entry: 327
JSON data
downloaded
Chrome Cache Entry: 328
Unicode text, UTF-8 text, with very long lines (18747)
downloaded
Chrome Cache Entry: 331
ASCII text, with very long lines (62605)
downloaded
Chrome Cache Entry: 332
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 334
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 335
Unicode text, UTF-8 text, with very long lines (60531)
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (8298), with no line terminators
dropped
Chrome Cache Entry: 339
Unicode text, UTF-8 text, with very long lines (61316)
downloaded
Chrome Cache Entry: 340
HTML document, Unicode text, UTF-8 text, with very long lines (61318)
downloaded
Chrome Cache Entry: 341
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 342
ASCII text, with very long lines (1032)
dropped
Chrome Cache Entry: 343
ASCII text, with very long lines (11921), with no line terminators
dropped
Chrome Cache Entry: 344
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (7255)
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (10854)
downloaded
Chrome Cache Entry: 348
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 350
ASCII text, with very long lines (14911), with no line terminators
downloaded
Chrome Cache Entry: 352
ASCII text, with very long lines (2345)
dropped
Chrome Cache Entry: 354
Unicode text, UTF-8 text, with very long lines (65504), with no line terminators
dropped
Chrome Cache Entry: 355
ASCII text
dropped
Chrome Cache Entry: 357
PNG image data, 628 x 275, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 358
ASCII text, with very long lines (14295)
downloaded
Chrome Cache Entry: 359
Web Open Font Format (Version 2), TrueType, length 74348, version 329.31064
downloaded
Chrome Cache Entry: 365
HTML document, Unicode text, UTF-8 text, with very long lines (61318)
downloaded
Chrome Cache Entry: 366
ASCII text, with very long lines (12875), with no line terminators
dropped
Chrome Cache Entry: 367
JSON data
dropped
Chrome Cache Entry: 368
ASCII text, with very long lines (40713)
downloaded
Chrome Cache Entry: 371
JSON data
dropped
Chrome Cache Entry: 372
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 374
Unicode text, UTF-8 text, with very long lines (19006)
downloaded
Chrome Cache Entry: 380
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 381
ASCII text
dropped
Chrome Cache Entry: 383
PNG image data, 167 x 50, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 385
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 387
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 390
ASCII text, with very long lines (2697), with no line terminators
downloaded
Chrome Cache Entry: 391
ASCII text, with very long lines (32273), with no line terminators
downloaded
Chrome Cache Entry: 392
Web Open Font Format (Version 2), TrueType, length 40094, version 3.131
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (25197)
dropped
Chrome Cache Entry: 394
ASCII text, with very long lines (8941)
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (8624)
dropped
Chrome Cache Entry: 396
JSON data
dropped
Chrome Cache Entry: 398
ASCII text, with very long lines (13109)
dropped
Chrome Cache Entry: 399
ASCII text, with very long lines (11111)
dropped
Chrome Cache Entry: 400
ASCII text, with very long lines (9951), with no line terminators
downloaded
Chrome Cache Entry: 401
PNG image data, 233 x 70, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 402
Unicode text, UTF-8 text, with very long lines (49926), with no line terminators
dropped
Chrome Cache Entry: 404
ASCII text
downloaded
Chrome Cache Entry: 405
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 406
ASCII text, with very long lines (4716)
downloaded
Chrome Cache Entry: 407
Unicode text, UTF-8 text, with very long lines (61316)
downloaded
Chrome Cache Entry: 408
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 409
C++ source, ASCII text
downloaded
Chrome Cache Entry: 410
ASCII text, with very long lines (18434)
downloaded
Chrome Cache Entry: 411
JSON data
dropped
Chrome Cache Entry: 418
ASCII text, with very long lines (7071), with no line terminators
dropped
Chrome Cache Entry: 422
PNG image data, 540 x 540, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 423
gzip compressed data, max compression, from Unix, original size modulo 2^32 304778
downloaded
Chrome Cache Entry: 424
ASCII text, with very long lines (12303)
dropped
Chrome Cache Entry: 425
ASCII text, with very long lines (25669), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 426
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 427
ASCII text, with very long lines (65467)
dropped
Chrome Cache Entry: 428
ASCII text, with very long lines (6741)
downloaded
There are 122 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://returns.gatsbyshoes.co
https://gatsbyshoes.co/
malicious
https://returns.gatsbyshoes.co/returns-portal/login
https://returns.gatsbyshoes.co/returns-portal

Domains

Name
IP
Malicious
conf.config-security.com
104.26.15.69
app.kiwisizing.com
104.26.2.64
winads.eraofecom.org
172.67.191.191
tls13.taboola.map.fastly.net
151.101.193.44
d2fashanjl7d9f.cloudfront.net
18.66.102.121
global.px.quantserve.com
91.228.74.166
redoproductiontenants-lb2-lb-b8582096c61f94b1.elb.us-east-1.amazonaws.com
3.218.90.110
d15evtpwmm5lwp.cloudfront.net
52.222.201.7
essential-apps-analytics.herokuapp.com
46.137.15.86
shops.myshopify.com
23.227.38.74
api2.amplitude.com
54.188.243.167
gatsbyshoes.co
23.227.38.32
d3a7tdfg11nnm7.cloudfront.net
13.224.189.56
geolocation-recommendations.shopifyapps.com
185.146.173.20
whale.camera
172.67.72.209
dualstack.tls13.taboola.map.fastly.net
151.101.193.44
d2djnlq8i6mjem.cloudfront.net
18.66.147.128
gw-monorail-production-gateway-apps-a-us-ce1-xi5.shopifycloud.com
34.54.30.0
api.config-security.com
34.149.60.135
www.google.com
142.250.186.100
klaviyo-onsite.map.fastly.net
151.101.130.133
am-vip001.taboola.com
141.226.228.48
a.nel.cloudflare.com
35.190.80.1
d889emgu1evay.cloudfront.net
13.35.58.40
d1u9wuqimc88kc.cloudfront.net
13.33.216.18
klaviyo-app.map.fastly.net
151.101.2.133
182318.t.hyros.com
75.101.169.34
cdn-sf.vitals.app
172.67.68.29
sc-static.net
3.163.248.4
fonts.shopifycdn.com
185.146.173.20
debutify.com
172.66.43.51
cdn.shopify.com
23.227.60.200
www.googleoptimize.com
142.250.185.174
shop.app
185.146.173.20
api.socialsnowball.io
104.26.7.31
d1bqfsvw61qwj1.cloudfront.net
18.66.147.111
duihxgfnjg37f.cloudfront.net
13.225.78.14
tms.trackingmore.net
104.26.5.207
redoproduction-server-234042900.us-east-1.elb.amazonaws.com
44.206.71.202
appsolve.io
104.26.9.213
d1npnstlfekkfz.cloudfront.net
108.138.2.66
data.getredo.com
unknown
monorail-edge.shopifysvc.com
unknown
psb.taboola.com
unknown
shopify-extension.getredo.com
unknown
shopify-cdn.getredo.com
unknown
rules.quantcount.com
unknown
use.fontawesome.com
unknown
static-tracking.klaviyo.com
unknown
trc-events.taboola.com
unknown
static.klaviyo.com
unknown
returns.gatsbyshoes.co
unknown
cdn-4.convertexperiments.com
unknown
cdn.attn.tv
unknown
secure.quantserve.com
unknown
trc.taboola.com
unknown
returns.getredo.com
unknown
intg.snapchat.com
unknown
cdn.taboola.com
unknown
returns-server.getredo.com
unknown
analytics.tiktok.com
unknown
gatsbyshoes.myshopify.com
unknown
cdn.intelligems.io
unknown
There are 53 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.222.201.106
unknown
United States
151.101.130.133
klaviyo-onsite.map.fastly.net
United States
91.228.74.166
global.px.quantserve.com
United Kingdom
216.58.212.142
unknown
United States
3.218.90.110
redoproductiontenants-lb2-lb-b8582096c61f94b1.elb.us-east-1.amazonaws.com
United States
91.228.74.244
unknown
United Kingdom
104.22.68.196
unknown
United States
108.138.2.134
unknown
United States
13.224.189.56
d3a7tdfg11nnm7.cloudfront.net
United States
108.138.2.66
d1npnstlfekkfz.cloudfront.net
United States
23.201.242.112
unknown
United States
104.26.5.207
tms.trackingmore.net
United States
104.26.9.213
appsolve.io
United States
104.26.15.69
conf.config-security.com
United States
18.66.102.121
d2fashanjl7d9f.cloudfront.net
United States
13.35.58.103
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
151.101.66.133
unknown
United States
13.33.216.18
d1u9wuqimc88kc.cloudfront.net
United States
151.101.193.44
tls13.taboola.map.fastly.net
United States
142.250.185.67
unknown
United States
142.250.186.78
unknown
United States
104.26.6.31
unknown
United States
1.1.1.1
unknown
Australia
2.18.64.15
unknown
European Union
74.125.133.84
unknown
United States
172.67.68.29
cdn-sf.vitals.app
United States
172.67.72.209
whale.camera
United States
3.229.237.62
unknown
United States
13.225.78.14
duihxgfnjg37f.cloudfront.net
United States
151.101.1.44
unknown
United States
142.250.186.106
unknown
United States
239.255.255.250
unknown
Reserved
151.101.65.44
unknown
United States
142.250.186.100
www.google.com
United States
142.250.184.238
unknown
United States
104.26.4.207
unknown
United States
44.206.71.202
redoproduction-server-234042900.us-east-1.elb.amazonaws.com
United States
104.26.7.31
api.socialsnowball.io
United States
18.66.147.111
d1bqfsvw61qwj1.cloudfront.net
United States
34.54.30.0
gw-monorail-production-gateway-apps-a-us-ce1-xi5.shopifycloud.com
United States
192.168.2.17
unknown
unknown
23.227.38.74
shops.myshopify.com
Canada
23.227.60.200
cdn.shopify.com
Canada
172.67.68.178
unknown
United States
23.227.38.32
gatsbyshoes.co
Canada
104.26.2.64
app.kiwisizing.com
United States
216.58.206.35
unknown
United States
3.163.248.4
sc-static.net
United States
172.66.43.51
debutify.com
United States
185.146.173.20
geolocation-recommendations.shopifyapps.com
Sweden
142.250.186.131
unknown
United States
141.226.228.48
am-vip001.taboola.com
Israel
34.149.60.135
api.config-security.com
United States
172.67.72.191
unknown
United States
13.35.58.40
d889emgu1evay.cloudfront.net
United States
18.66.147.128
d2djnlq8i6mjem.cloudfront.net
United States
52.222.201.7
d15evtpwmm5lwp.cloudfront.net
United States
216.58.212.132
unknown
United States
172.217.16.206
unknown
United States
13.225.78.39
unknown
United States
142.250.185.138
unknown
United States
13.224.189.66
unknown
United States
151.101.129.44
unknown
United States
142.250.185.174
www.googleoptimize.com
United States
151.101.2.133
klaviyo-app.map.fastly.net
United States
75.101.169.34
182318.t.hyros.com
United States
104.21.27.152
unknown
United States
46.137.15.86
essential-apps-analytics.herokuapp.com
Ireland
54.188.243.167
api2.amplitude.com
United States
44.237.110.123
unknown
United States
18.66.147.26
unknown
United States
There are 62 hidden IPs, click here to show them.