IOC Report
https://we.tl/t-lpjqBdcXlG

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 08:32:34 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 08:32:34 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:56:51 2023, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 08:32:33 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 08:32:34 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 08:32:33 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 255
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 256
ASCII text, with very long lines (487)
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (61817), with no line terminators
downloaded
Chrome Cache Entry: 259
HTML document, ASCII text, with very long lines (514)
downloaded
Chrome Cache Entry: 260
PNG image data, 634 x 601, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 261
JSON data
dropped
Chrome Cache Entry: 262
ASCII text, with very long lines (65089)
downloaded
Chrome Cache Entry: 263
Web Open Font Format, TrueType, length 31120, version 1.6554
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (42170)
downloaded
Chrome Cache Entry: 265
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 266
Web Open Font Format (Version 2), TrueType, length 27440, version 1.0
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (4103), with no line terminators
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (4103), with no line terminators
dropped
Chrome Cache Entry: 269
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
downloaded
Chrome Cache Entry: 270
ASCII text, with very long lines (25927), with no line terminators
dropped
Chrome Cache Entry: 271
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 272
ASCII text
dropped
Chrome Cache Entry: 273
ASCII text, with very long lines (56579), with no line terminators
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (15336)
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 276
ASCII text, with very long lines (26464), with no line terminators
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (50817), with no line terminators
dropped
Chrome Cache Entry: 278
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 279
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 280
Unicode text, UTF-8 text, with very long lines (35788), with CRLF line terminators
dropped
Chrome Cache Entry: 281
ASCII text, with very long lines (25927), with no line terminators
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 283
ASCII text, with very long lines (9935), with no line terminators
downloaded
Chrome Cache Entry: 284
ASCII text
downloaded
Chrome Cache Entry: 285
ASCII text, with very long lines (20232)
dropped
Chrome Cache Entry: 286
PNG image data, 634 x 601, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 287
ASCII text, with very long lines (9935), with no line terminators
dropped
Chrome Cache Entry: 288
JSON data
dropped
Chrome Cache Entry: 289
Web Open Font Format (Version 2), TrueType, length 35884, version 1.0
downloaded
Chrome Cache Entry: 290
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 291
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 292
HTML document, ASCII text
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 294
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 295
ASCII text, with very long lines (61817), with no line terminators
dropped
Chrome Cache Entry: 296
Web Open Font Format (Version 2), TrueType, length 25564, version 1.6554
downloaded
Chrome Cache Entry: 297
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 298
ASCII text, with very long lines (9022), with no line terminators
downloaded
Chrome Cache Entry: 299
Web Open Font Format (Version 2), TrueType, length 35496, version 2.0
downloaded
Chrome Cache Entry: 300
ASCII text, with very long lines (3673)
dropped
Chrome Cache Entry: 301
ASCII text, with very long lines (9022), with no line terminators
dropped
Chrome Cache Entry: 302
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 303
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (5552)
dropped
Chrome Cache Entry: 305
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 307
ASCII text
dropped
Chrome Cache Entry: 308
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 309
PNG image data, 237 x 244, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 310
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 312
JSON data
dropped
Chrome Cache Entry: 313
ASCII text, with very long lines (50817), with no line terminators
downloaded
Chrome Cache Entry: 314
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (11507), with no line terminators
dropped
Chrome Cache Entry: 316
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (26464), with no line terminators
dropped
Chrome Cache Entry: 318
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 319
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 320
PNG image data, 628 x 628, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 321
JSON data
dropped
Chrome Cache Entry: 322
ASCII text
downloaded
Chrome Cache Entry: 323
ASCII text, with very long lines (1472), with no line terminators
downloaded
Chrome Cache Entry: 324
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 325
Unicode text, UTF-8 text, with very long lines (11346), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 326
ASCII text, with very long lines (44642), with no line terminators
downloaded
Chrome Cache Entry: 327
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 328
HTML document, ASCII text
downloaded
Chrome Cache Entry: 329
Web Open Font Format (Version 2), TrueType, length 27984, version 1.0
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 331
JSON data
dropped
Chrome Cache Entry: 332
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 333
ASCII text, with very long lines (34384)
downloaded
Chrome Cache Entry: 334
ASCII text, with very long lines (26406), with no line terminators
downloaded
Chrome Cache Entry: 335
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 336
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 337
Web Open Font Format (Version 2), TrueType, length 26436, version 1.6554
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (19015), with no line terminators
dropped
Chrome Cache Entry: 339
PNG image data, 190 x 200, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 340
ASCII text
dropped
Chrome Cache Entry: 341
Web Open Font Format (Version 2), TrueType, length 28644, version 1.0
downloaded
Chrome Cache Entry: 342
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 343
HTML document, Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 344
ASCII text, with very long lines (19015), with no line terminators
downloaded
Chrome Cache Entry: 345
gzip compressed data, was "main.97c41ef3.js", last modified: Fri Aug 23 15:57:59 2024, from Unix, original size modulo 2^32 83598
downloaded
Chrome Cache Entry: 346
Web Open Font Format, TrueType, length 43188, version 0.0
downloaded
Chrome Cache Entry: 347
JSON data
dropped
Chrome Cache Entry: 348
ASCII text, with very long lines (4779), with no line terminators
dropped
Chrome Cache Entry: 349
Unicode text, UTF-8 text, with very long lines (65491), with no line terminators
downloaded
Chrome Cache Entry: 350
ASCII text, with very long lines (42170)
dropped
Chrome Cache Entry: 351
JSON data
dropped
Chrome Cache Entry: 352
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 353
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 354
JSON data
downloaded
Chrome Cache Entry: 355
ASCII text, with very long lines (44642), with no line terminators
dropped
Chrome Cache Entry: 356
ASCII text, with very long lines (10407), with no line terminators
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 358
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 359
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 360
gzip compressed data, was "main.97c41ef3.js", last modified: Fri Aug 23 15:57:59 2024, from Unix, original size modulo 2^32 83598
dropped
Chrome Cache Entry: 361
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 362
Web Open Font Format, TrueType, length 32124, version 1.6554
downloaded
Chrome Cache Entry: 363
HTML document, ASCII text, with very long lines (565), with no line terminators
downloaded
Chrome Cache Entry: 364
ASCII text, with very long lines (9217)
downloaded
Chrome Cache Entry: 365
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 366
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 367
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 368
HTML document, ASCII text
downloaded
Chrome Cache Entry: 369
PNG image data, 237 x 244, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 370
ASCII text, with very long lines (11507), with no line terminators
downloaded
Chrome Cache Entry: 371
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 372
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 373
ASCII text, with very long lines (10407), with no line terminators
dropped
Chrome Cache Entry: 374
ASCII text, with very long lines (4779), with no line terminators
downloaded
Chrome Cache Entry: 375
PNG image data, 628 x 628, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 376
Unicode text, UTF-8 text, with very long lines (11346), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 377
ASCII text, with very long lines (26406), with no line terminators
dropped
Chrome Cache Entry: 378
Unicode text, UTF-8 text, with very long lines (65491), with no line terminators
dropped
Chrome Cache Entry: 379
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 380
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 381
ASCII text, with very long lines (65089)
dropped
Chrome Cache Entry: 382
ASCII text, with very long lines (15336)
dropped
Chrome Cache Entry: 383
PNG image data, 190 x 200, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 384
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 385
ASCII text, with very long lines (4425), with no line terminators
downloaded
Chrome Cache Entry: 386
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 387
ASCII text, with very long lines (4614), with CRLF line terminators
downloaded
Chrome Cache Entry: 388
JSON data
downloaded
Chrome Cache Entry: 389
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 390
ASCII text, with very long lines (4425), with no line terminators
dropped
Chrome Cache Entry: 391
ASCII text, with very long lines (4614), with CRLF line terminators
dropped
Chrome Cache Entry: 392
ASCII text, with very long lines (487)
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 394
ASCII text
downloaded
Chrome Cache Entry: 395
JSON data
downloaded
Chrome Cache Entry: 396
Unicode text, UTF-8 text, with very long lines (35788), with CRLF line terminators
downloaded
Chrome Cache Entry: 397
ASCII text, with very long lines (9217)
dropped
Chrome Cache Entry: 398
ASCII text, with very long lines (20232)
downloaded
Chrome Cache Entry: 399
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 400
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 401
JSON data
dropped
Chrome Cache Entry: 402
HTML document, Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 404
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 405
ASCII text, with very long lines (34384)
dropped
Chrome Cache Entry: 406
ASCII text, with very long lines (56579), with no line terminators
downloaded
Chrome Cache Entry: 407
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 408
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 409
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 410
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 412
JSON data
downloaded
Chrome Cache Entry: 413
HTML document, ASCII text, with very long lines (589)
downloaded
There are 156 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2524 --field-trial-handle=2056,i,3303298557692941838,14967038446866508319,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://we.tl/t-lpjqBdcXlG"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6240 --field-trial-handle=2056,i,3303298557692941838,14967038446866508319,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://we.tl/t-lpjqBdcXlG
https://ib.adnxs.com/getuid?https%3a%2f%2fmatch.adsrvr.org%2ftrack%2fcmf%2fappnexus%3fttd%3d1%26anid%3d%24UID&ttd_tdid=16078ca1-21fd-44ff-8462-0846cc370c97
185.89.211.116
https://cdn.brandmetrics.com/scripts/bundle/65568.js?sid=7f2d78d4-f913-42d1-8d60-7c59cb6b6daf&toploc=wetransfer.com&&slang=US
104.26.0.90
https://cdn.brandmetrics.com
unknown
https://di.rlcdn.com/api/segment?pid=712597&pdata=sid%3D%2Cuid%3D3be49999-8ad7-4bf8-ac12-a7f949704b75
35.244.174.68
https://stats.g.doubleclick.net/g/collect
unknown
https://cdn.wetransfer.com/_next/static/chunks/9200.140ecd3d50fcc245.js
143.204.98.85
https://api.pico.bendingspoonsapps.com/v4/web-events
34.102.204.67
https://prod-cdn.wetransfer.net/packs/js/wallpaper-api-2.10.2.js
18.164.52.74
https://wetransfer.com/
unknown
https://cdn.wetransfer.com/_next/static/chunks/4301.b6563063d0e63ec0.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/5711-bdbed558b83e5255.js
143.204.98.85
https://public.profitwell.com/js/profitwell.js?auth=1a33eb12b20b92f6b89c398e023e2ca1
13.32.121.46
https://s.pinimg.com/ct/lib/main.97c41ef3.js
151.101.192.84
https://collector.brandmetrics.com
unknown
https://ekstrom.wetransfer.net/wallpapers/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401
52.48.5.216
https://cdn.wetransfer.com/_next/static/chunks/2edb282b.45c56c19221816df.js
143.204.98.85
https://cm.g.doubleclick.net/pixel?google_nid=TheTradeDesk&google_cm&google_sc&google_hm=MTYwNzhjYTE
unknown
https://ekstrom.wetransfer.net/v1/customizations/transfers/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401
52.48.5.216
https://cdn.wetransfer.com/_next/static/media/GTSuperWT-Regular.d1473b9e.woff2
143.204.98.85
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/GT-Super-WT-Regular.807dcb08d194101be093.woff2
65.9.66.2
https://www.google.com
unknown
https://cdn.wetransfer.com/_next/static/chunks/2046.ad4704ab9501c826.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/pages/downloads/%5BtransferId%5D/%5BrecipientId%5D-85271343060b81ba.js
143.204.98.85
https://donny.wetransfer.com/i.gif?e=eyJ2IjoiMS4xMiIsImF2Ijo1NTIwNzksImF0Ijo5NTksImJ0IjowLCJjbSI6NzE3MDMzOCwiY2giOjM0OTAyLCJjayI6e30sImNyIjo2OTE3MDg3NSwiZGkiOiIxOTVlYjg0MWMyMTk0NWM0OWJiZDM4YmYxMDA4MWIyYSIsImRqIjowLCJpaSI6IjU0MGVjMmU2ODZhODRlYmViNmRlOGQ1M2ExYWMxYjIyIiwiZG0iOjMsImZjIjoxMjc4MTk4OTgsImZsIjozNjIwMTY0OCwiaXAiOiIxNzMuMjU0LjI1MC43MiIsIm53IjoxMDIyMCwicGMiOjAsIm9wIjowLCJtcCI6MCwiZWMiOjAsImdtIjowLCJlcCI6bnVsbCwicHIiOjIyNzc4OSwicnQiOjEsInJzIjo1MDAsInNhIjoiNTUiLCJzYiI6ImktMDgxMzYzZjY3NTQ1NmZkZDYiLCJzcCI6MjM4NzAyLCJzdCI6MTA1NTkyMiwidWsiOiJzcC0zYmU0OTk5OS04YWQ3LTRiZjgtYWMxMi1hN2Y5NDk3MDRiNzUiLCJ6biI6MTk5MDcxLCJ0cyI6MTczMDE5NDQxODI2NCwicG4iOiJpZnJhbWUiLCJnciI6dHJ1ZSwiZ2MiOnRydWUsImdDIjp0cnVlLCJncyI6Im5vbmUiLCJkYyI6MSwidHoiOiJBbWVyaWNhL05ld19Zb3JrIiwiYmEiOjEsImZxIjowfQ&s=lcRobYndjAZIiffWepE3xszMhE8&product=web
54.228.158.30
https://cdn.wetransfer.com/_next/static/chunks/6175.4dd2f27c39159132.js
143.204.98.85
https://cm.g.doubleclick.net/pixel?google_nid=TheTradeDesk&google_cm&google_sc&google_hm=MTYwNzhjYTEtMjFmZC00NGZmLTg0NjItMDg0NmNjMzcwYzk3&gdpr=0&gdpr_consent=&ttd_tdid=16078ca1-21fd-44ff-8462-0846cc370c97
142.250.185.98
https://connect.facebook.net/en_US/fbevents.js
157.240.0.6
https://donny.wetransfer.com/i.gif?e=eyJ2IjoiMS4xMiIsImF2Ijo1NTIwNzksImF0Ijo5NTksImJ0IjowLCJjbSI6NzE3MDMzOCwiY2giOjM0OTAyLCJjayI6e30sImNyIjo2OTE3MDg3NSwiZGkiOiJkMjhhYmE4NDYwMWM0YTE3YTI3ZjhjZTIxZWFmZTBiNCIsImRqIjowLCJpaSI6ImU2Y2I4ZDQ1Y2NlZTQ3MmZhOTc1NDkxODkxZmEyZjkxIiwiZG0iOjMsImZjIjoxMjc4MTk4OTgsImZsIjozNjIwMTY0OCwiaXAiOiIxNzMuMjU0LjI1MC43MiIsIm53IjoxMDIyMCwicGMiOjAsIm9wIjowLCJtcCI6MCwiZWMiOjAsImdtIjowLCJlcCI6bnVsbCwicHIiOjIyNzc4OSwicnQiOjEsInJzIjo1MDAsInNhIjoiNTUiLCJzYiI6ImktMGUyOTgzZGU5MjQ1YmVjZGIiLCJzcCI6MjU0ODM1LCJzdCI6MTA1NTkyMiwidWsiOiJzcC0zYmU0OTk5OS04YWQ3LTRiZjgtYWMxMi1hN2Y5NDk3MDRiNzUiLCJ6biI6MTk5MDcxLCJ0cyI6MTczMDE5NDM4OTQyNCwicG4iOiJpZnJhbWUiLCJnciI6dHJ1ZSwiZ2MiOnRydWUsImdDIjp0cnVlLCJncyI6Im5vbmUiLCJkYyI6MSwidHoiOiJBbWVyaWNhL05ld19Zb3JrIiwiYmEiOjEsImZxIjowfQ&s=5sznTgJUyhssePEcSIhJF5zaISk&product=web
54.228.158.30
https://donny.wetransfer.com/i.gif?e=eyJ2IjoiMS4xMiIsImF2Ijo1NTIwNzksImF0Ijo5NTksImJ0IjowLCJjbSI6NzE3MDMzOCwiY2giOjM0OTAyLCJjayI6e30sImNyIjo2OTE3MDc3NCwiZGkiOiJlZDAwMTU5NTIyM2U0NDFjODk2MDBlYzQyNzEyYzdmYiIsImRqIjowLCJpaSI6IjQyNWNkYjU1Zjk2NDQ2MTU4NWU5ZjYyMzM2Yzk0YWQ1IiwiZG0iOjMsImZjIjoxMjc4MTgxMzcsImZsIjoxNjI1MTQzOCwiaXAiOiIxNzMuMjU0LjI1MC43MiIsIm53IjoxMDIyMCwicGMiOjAsIm9wIjowLCJtcCI6MCwiZWMiOjAsImdtIjowLCJlcCI6bnVsbCwicHIiOjIyNzc4OSwicnQiOjEsInJzIjo1MDAsInNhIjoiNTUiLCJzYiI6ImktMDlhYzg3NzFlNzFiMjMxZmYiLCJzcCI6MzA1NTczLCJzdCI6MTA1NTkyMiwidWsiOiJzcC0zYmU0OTk5OS04YWQ3LTRiZjgtYWMxMi1hN2Y5NDk3MDRiNzUiLCJ6biI6MTk5MDcyLCJ0cyI6MTczMDE5NDQyMTg0MSwicG4iOiJpZnJhbWUiLCJnciI6dHJ1ZSwiZ2MiOnRydWUsImdDIjp0cnVlLCJncyI6Im5vbmUiLCJkYyI6MSwidHoiOiJBbWVyaWNhL05ld19Zb3JrIiwiYmEiOjEsImZxIjowfQ&s=odXF6bNAV_dbOcYX4HuvJfGO3gM&product=web
54.228.158.30
https://analytics-v2.wetransfer.com/2/httpapi
13.32.27.113
https://js.adsrvr.org/up_loader.1.1.0.js
18.172.103.101
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/mcguffin-thumbs.f78d46772ddd43b2dd77.png
65.9.66.2
https://cdn.wetransfer.com/_next/static/chunks/1627.f2cf297cefb46766.js
143.204.98.85
http://www.amazon.com/b/?&node=7253015011.
unknown
https://tagging.wetransfer.com/gtag/js?id=G-0M019DTWVR&l=dataLayer&cx=c&sign=c576e87f92520d31e73a186e59163610de22acb6a9adc0b1b1ff3bb8f128f004_20241029
18.245.46.95
https://cdn.wetransfer.com/_next/static/chunks/7242.626ab9db967b0d6e.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/webpack-008bc65f2853ef6f.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/css/72842cb7879526db.css
143.204.98.85
https://nolan.wetransfer.net/apps/desktop-web-renderer/0.5.21/index.html?_origin=https://wetransfer.com&_placement=creative-frame-127819898:36201648:1730194389128
108.138.26.29
https://www.google.com/adsense
unknown
https://cdn.wetransfer.com/_next/static/media/ActiefGrotesque_W_Regular.458577e8.woff
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/3178.c5532f9bbf1ec305.js
143.204.98.85
https://bsp-proxy.wetransfer.net/orion/v3/identity/settings
54.217.172.44
https://match.adsrvr.org/track/cmf/rubicon?gdpr=0
52.223.40.198
https://nolan.wetransfer.net/apps/desktop-web-renderer/0.5.21/index.html?_origin=https://wetransfer.com&_placement=creative-frame-127819898:36201648:1730194417960
108.138.26.29
https://cdn.wetransfer.com/_next/static/media/ActiefGrotesque-Medium.1acd899d.woff2
143.204.98.85
https://match.adsrvr.org/track/cmf/google?g_uuid=&gdpr=0&gdpr_consent=&ttd_tdid=16078ca1-21fd-44ff-8462-0846cc370c97&google_gid=CAESENYzhIDJCnRPJGEEJBcRzwU&google_cver=1
52.223.40.198
https://ib.adnxs.com/getuid?https%3a%2f%2fmatch.adsrvr.org%2ftrack%2fcmf%2fappnexus%3fttd%3d1%26anid
unknown
https://we.tl/t-lpjqBdcXlG
18.66.147.26
https://cdn.wetransfer.com/_next/static/chunks/pages/_app-17dc211d41aa7d50.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/b6b16427.ae33c8de5057d107.js
143.204.98.85
https://cdn-api.ethyca.com/location
unknown
https://e-10220.adzerk.net/api/v2
3.209.79.2
https://ct.pinterest.com/stats/
unknown
https://privacy-wetransfer.us.fides.ethyca.com
unknown
https://cct.google/taggy/agent.js
unknown
https://connect.facebook.net/
unknown
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/bottom-left.dd954f3c2df353c6b22e.png
65.9.66.2
https://cdn.wetransfer.com/_next/static/css/c2b152c63e85a470.css
143.204.98.85
https://match.adsrvr.org/track/cmf/appnexus?ttd=1&anid=1524433199296573154&ttd_tdid=16078ca1-21fd-44ff-8462-0846cc370c97
52.223.40.198
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/ActiefGrotesque_W_Md.23817d3ab6c377c0a652.woff2
65.9.66.2
https://wetransfer.com/favicon.ico
143.204.98.85
https://wetransfer.com/27788ef632cf2665162609dec7218bcad6421071/config.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/27788ef632cf2665162609dec7218bcad6421071/_buildManifest.js
143.204.98.85
https://tagging.wetransfer.com/gtm.js?id=GTM-NS54WBW
18.245.46.95
https://ara.paa-reporting-advertising.amazon/aat?pid=9b73dfcd-001f-400a-b379-8258969df4a1&event=PageView&ts=1730194375805&uuid=cf128c32-4c53-4a1f-8428-3f285db0fb9c
18.245.46.38
https://cdn.brandmetrics.com/tag/a79d0565d5244a0f813e40f2c4832d09/wetransfer.js?slang=US
104.26.0.90
https://cdn.wetransfer.com/_next/static/chunks/8745.99c4767c7b8f13b4.js
143.204.98.85
https://cdn.jsdelivr.net/npm/@snowplow/javascript-tracker@3.23.0/dist/sp.min.js
151.101.129.229
https://www.datadoghq-browser-agent.com/eu1/v5/datadog-rum-slim.js
13.33.219.205
https://js.adsrvr.org/universal_pixel.1.1.0.js
18.172.103.101
http://bit.ly/sp-js)
unknown
https://connect.facebook.net/signals/config/1904796869803472?v=2.9.174&r=stable&domain=wetransfer.com&hme=ead923021ccd3483ef3b9b04703d0a78b943fbdc01e8d7cec21c5059f1f4a5e9&ex_m=70%2C121%2C107%2C111%2C61%2C4%2C100%2C69%2C16%2C97%2C89%2C51%2C54%2C172%2C175%2C187%2C183%2C184%2C186%2C29%2C101%2C53%2C77%2C185%2C167%2C170%2C180%2C181%2C188%2C131%2C41%2C189%2C190%2C34%2C143%2C15%2C50%2C194%2C193%2C133%2C18%2C40%2C1%2C43%2C65%2C66%2C67%2C71%2C93%2C17%2C14%2C96%2C92%2C91%2C108%2C52%2C110%2C39%2C109%2C30%2C94%2C26%2C168%2C171%2C140%2C86%2C56%2C84%2C33%2C73%2C0%2C95%2C32%2C28%2C82%2C83%2C88%2C47%2C46%2C87%2C37%2C11%2C12%2C13%2C6%2C7%2C25%2C22%2C23%2C57%2C62%2C64%2C75%2C102%2C27%2C76%2C9%2C8%2C80%2C48%2C21%2C104%2C103%2C105%2C98%2C10%2C20%2C3%2C38%2C74%2C19%2C5%2C90%2C81%2C44%2C35%2C85%2C2%2C36%2C63%2C42%2C106%2C45%2C79%2C68%2C112%2C60%2C59%2C31%2C99%2C58%2C55%2C49%2C78%2C72%2C24%2C113
157.240.0.6
https://cdn.wetransfer.com/_next/static/media/ActiefGrotesque_W_Medium.7e37a161.woff
143.204.98.85
https://wepresent.wetransfer.com/
unknown
https://auth-session-caching.wetransfer.net/v1/login-status
34.240.255.32
https://nolan.wetransfer.net/apps/desktop-wallpaper/0.1.60/main.f69b88bbae19314d.js
108.138.26.29
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/bundle.870273c9c7528c74ee4d.js
65.9.66.2
https://cdn.wetransfer.com/_next/static/media/ActiefGrotesque-Bold.10832e10.woff2
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/5835-32f7380333f788d6.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/955cc3f7.c7503578db87f6be.js
143.204.98.85
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/top-right.d22a71959ab417e17ce8.png
65.9.66.2
https://snowplow.wetransfer.com/com.snowplowanalytics.snowplow/tp2
52.48.47.179
https://cdn.wetransfer.com/_next/static/media/GT-Super-WT-Super.3397811e.woff
143.204.98.85
https://privacy.wetransfer.com/fides.js?property_id=FDS-4GUYPU&geolocation=US-PA
18.245.86.40
https://cdn.wetransfer.com/_next/static/media/ActiefGrotesque-Regular.f4e76979.woff2
143.204.98.85
https://wetransfer.com/api/graphql
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/8091.f50443897f289a4c.js
143.204.98.85
https://s.pinimg.com/ct/core.js
151.101.192.84
https://c.amazon-adsystem.com/aat/amzn.js
18.173.210.128
https://s.amazon-adsystem.com/iu3?pid=9b73dfcd-001f-400a-b379-8258969df4a1&event=PageView&ts=1730194375805&uuid=cf128c32-4c53-4a1f-8428-3f285db0fb9c&dcc=t
98.82.157.231
https://cdn.wetransfer.com/_next/static/chunks/4642.c8969ba2f440785e.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/1322.ad7a8f357fd5be2c.js
143.204.98.85
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/ActiefGrotesque_W_Rg.63479c54248fa038db83.woff2
65.9.66.2
https://cdn.wetransfer.com/_next/static/chunks/e893f787.529ff2dd2d297b89.js
143.204.98.85
https://nolan.wetransfer.net/apps/desktop-web-renderer/0.5.21/main.1e7c25a9b2cdf73f.js
108.138.26.29
https://backgrounds.wetransfer.net/creator/wetransfer/2203-WTO/static-6/1_QMdy6g/index.html?_origin=https://nolan.wetransfer.net&_placement=desktop-web-renderer
65.9.66.2
https://ct.pinterest.com/user/?event=pagevisit&tid=2612705757018&cb=1730194377587&dep=5%2CEVENT_TAGS_ABSENT
151.101.64.84
https://cdn.wetransfer.com/_next/static/chunks/8272.4cfe7705816ce283.js
143.204.98.85
https://cdn.wetransfer.com/_next/static/chunks/1141.695fbcf2c8f08029.js
143.204.98.85
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
jsdelivr.map.fastly.net
151.101.129.229
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
52.48.47.179
dg2iu7dxxehbo.cloudfront.net
18.172.103.101
backgrounds.wetransfer.net
65.9.66.2
fp2e7a.wpc.phicdn.net
192.229.221.95
insight.adsrvr.org
35.71.131.137
scontent.xx.fbcdn.net
157.240.0.6
cm.g.doubleclick.net
142.250.185.98
www.google.com
142.250.185.228
ara.paa-reporting-advertising.amazon
18.245.46.38
wetransfer.fides-cdn.ethyca.com
18.245.86.40
cdn.brandmetrics.com
104.26.0.90
bsp-proxy.wetransfer.net
54.217.172.44
match.adsrvr.org
52.223.40.198
star-mini.c10r.facebook.com
157.240.0.35
lebowski.wetransfer.com
54.194.89.98
we.tl
18.66.147.26
s.amazon-adsystem.com
98.82.157.231
e-prod-alb-s105-us-east-1-01.adzerk.net
3.209.79.2
s-part-0017.t-0009.t-msedge.net
13.107.246.45
dna8twue3dlxq.cloudfront.net
13.32.121.46
api.pico.bendingspoonsapps.com
34.102.204.67
ax-0001.ax-msedge.net
150.171.28.10
prod-cdn.wetransfer.net
18.164.52.74
d1ykf07e75w7ss.cloudfront.net
18.173.210.128
analytics-v2.wetransfer.com
13.32.27.113
prod.pinterest.global.map.fastly.net
151.101.64.84
di.rlcdn.com
35.244.174.68
googleads.g.doubleclick.net
142.250.185.162
donny.wetransfer.com
54.228.158.30
dualstack.pinterest.map.fastly.net
151.101.192.84
www.datadoghq-browser-agent.com
13.33.219.205
cdn.wetransfer.com
143.204.98.85
ekstrom.wetransfer.net
52.48.5.216
wetransfer.com
143.204.98.85
auth-session-caching.wetransfer.net
34.240.255.32
experiments.wetransfer.com
13.33.187.85
tagging.wetransfer.com
18.245.46.95
ib.anycast.adnxs.com
185.89.211.116
nolan.wetransfer.net
108.138.26.29
cdn.jsdelivr.net
unknown
snowplow.wetransfer.com
unknown
ct.pinterest.com
unknown
z.moatads.com
unknown
www.facebook.com
unknown
js.adsrvr.org
unknown
c.amazon-adsystem.com
unknown
privacy.wetransfer.com
unknown
pixel.rubiconproject.com
unknown
connect.facebook.net
unknown
public.profitwell.com
unknown
collector.brandmetrics.com
unknown
s.pinimg.com
unknown
ib.adnxs.com
unknown
e-10220.adzerk.net
unknown
There are 45 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
unknown
United States
142.250.185.228
www.google.com
United States
151.101.0.84
unknown
United States
52.48.47.179
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
United States
192.168.2.9
unknown
unknown
13.32.121.46
dna8twue3dlxq.cloudfront.net
United States
185.89.211.116
ib.anycast.adnxs.com
Germany
34.102.204.67
api.pico.bendingspoonsapps.com
United States
143.204.98.97
unknown
United States
143.204.98.51
unknown
United States
54.228.158.30
donny.wetransfer.com
United States
34.240.255.32
auth-session-caching.wetransfer.net
United States
157.240.252.13
unknown
United States
35.71.131.137
insight.adsrvr.org
United States
13.32.27.113
analytics-v2.wetransfer.com
United States
34.249.124.146
unknown
United States
104.26.0.90
cdn.brandmetrics.com
United States
108.138.26.29
nolan.wetransfer.net
United States
54.194.89.98
lebowski.wetransfer.com
United States
13.32.27.46
unknown
United States
157.240.0.35
star-mini.c10r.facebook.com
United States
3.209.79.2
e-prod-alb-s105-us-east-1-01.adzerk.net
United States
13.33.187.50
unknown
United States
108.138.6.136
unknown
United States
239.255.255.250
unknown
Reserved
35.244.174.68
di.rlcdn.com
United States
18.245.46.38
ara.paa-reporting-advertising.amazon
United States
52.223.40.198
match.adsrvr.org
United States
151.101.192.84
dualstack.pinterest.map.fastly.net
United States
18.245.86.40
wetransfer.fides-cdn.ethyca.com
United States
151.101.129.229
jsdelivr.map.fastly.net
United States
18.172.103.101
dg2iu7dxxehbo.cloudfront.net
United States
151.101.64.84
prod.pinterest.global.map.fastly.net
United States
54.155.202.146
unknown
United States
157.240.0.6
scontent.xx.fbcdn.net
United States
18.173.210.128
d1ykf07e75w7ss.cloudfront.net
United States
18.164.52.74
prod-cdn.wetransfer.net
United States
143.204.98.71
unknown
United States
98.82.157.231
s.amazon-adsystem.com
United States
13.33.187.85
experiments.wetransfer.com
United States
150.171.28.10
ax-0001.ax-msedge.net
United States
142.250.185.162
googleads.g.doubleclick.net
United States
13.32.27.4
unknown
United States
98.82.154.76
unknown
United States
54.217.172.44
bsp-proxy.wetransfer.net
United States
108.138.26.102
unknown
United States
18.245.86.74
unknown
United States
150.171.27.10
unknown
United States
18.245.46.95
tagging.wetransfer.com
United States
52.48.5.216
ekstrom.wetransfer.net
United States
143.204.98.85
cdn.wetransfer.com
United States
13.33.219.205
www.datadoghq-browser-agent.com
United States
13.32.121.58
unknown
United States
18.245.46.13
unknown
United States
65.9.66.2
backgrounds.wetransfer.net
United States
18.245.46.98
unknown
United States
157.240.251.35
unknown
United States
18.66.147.26
we.tl
United States
142.250.185.98
cm.g.doubleclick.net
United States
There are 49 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
https://wetransfer.com/downloads/ae0e5b3a9d4434e96bf93f1cdb13d21420241029085401/750100?t_exp=1730451241&t_lsid=18ea449b-df2b-4d11-b715-a6c71a0a66d0&t_network=link&t_s=download_link&t_ts=1730192085
There are 2 hidden doms, click here to show them.