IOC Report
http://www.wayfair.com/the-wayfair-app?pid=Email&c=Triggered&af_sub5=AppEmail&refid=7d34ad67-4987-430c-a5bd-5dacc342b623

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 15:00:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 15:00:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 15:00:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 15:00:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 31 15:00:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 265
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (487)
dropped
Chrome Cache Entry: 268
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 273
ASCII text, with very long lines (5364), with no line terminators
downloaded
Chrome Cache Entry: 274
ASCII text, with very long lines (533), with no line terminators
downloaded
Chrome Cache Entry: 277
GIF image data, version 87a, 1 x 1
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (4965), with no line terminators
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 281
ASCII text, with very long lines (62928), with no line terminators
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (2626), with no line terminators
downloaded
Chrome Cache Entry: 284
ASCII text
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (9225), with no line terminators
dropped
Chrome Cache Entry: 287
ASCII text, with very long lines (758)
downloaded
Chrome Cache Entry: 288
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 293
HTML document, ASCII text, with very long lines (815)
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (49270)
downloaded
Chrome Cache Entry: 296
Web Open Font Format (Version 2), TrueType, length 30348, version 1.0
downloaded
Chrome Cache Entry: 298
JSON data
dropped
Chrome Cache Entry: 299
ASCII text, with very long lines (2347), with no line terminators
dropped
Chrome Cache Entry: 303
ASCII text, with very long lines (8086)
dropped
Chrome Cache Entry: 304
ASCII text, with very long lines (65458)
dropped
Chrome Cache Entry: 306
ASCII text, with very long lines (37193)
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 308
ASCII text, with very long lines (22995), with no line terminators
downloaded
Chrome Cache Entry: 309
ASCII text, with very long lines (17782), with no line terminators
dropped
Chrome Cache Entry: 311
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 314
ASCII text, with very long lines (569)
dropped
Chrome Cache Entry: 315
HTML document, ASCII text, with very long lines (589)
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (7726)
downloaded
Chrome Cache Entry: 318
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 320
gzip compressed data, original size modulo 2^32 512146
downloaded
Chrome Cache Entry: 321
ASCII text, with very long lines (5045), with no line terminators
downloaded
Chrome Cache Entry: 322
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (3969)
downloaded
Chrome Cache Entry: 324
RIFF (little-endian) data, Web/P image, VP8 encoding, 720x408, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 326
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 328
Unicode text, UTF-8 text, with very long lines (17655)
dropped
Chrome Cache Entry: 329
ASCII text, with very long lines (479)
downloaded
Chrome Cache Entry: 330
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 332
ASCII text, with very long lines (65458)
dropped
Chrome Cache Entry: 335
ASCII text, with very long lines (3969)
downloaded
Chrome Cache Entry: 336
HTML document, ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 337
ASCII text, with very long lines (65456)
dropped
Chrome Cache Entry: 338
ASCII text, with very long lines (9217)
downloaded
Chrome Cache Entry: 340
gzip compressed data, from Unix, original size modulo 2^32 43473
dropped
Chrome Cache Entry: 341
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 342
ASCII text, with very long lines (53968), with no line terminators
downloaded
Chrome Cache Entry: 343
JSON data
downloaded
Chrome Cache Entry: 344
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 346
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (10244), with no line terminators
downloaded
Chrome Cache Entry: 349
ASCII text, with very long lines (26113)
downloaded
Chrome Cache Entry: 350
ASCII text, with very long lines (4955), with no line terminators
downloaded
Chrome Cache Entry: 353
ASCII text, with very long lines (5044), with no line terminators
dropped
Chrome Cache Entry: 354
Web Open Font Format (Version 2), TrueType, length 29636, version 1.0
downloaded
Chrome Cache Entry: 355
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 356
PNG image data, 360 x 360, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 359
ASCII text, with very long lines (2757)
dropped
Chrome Cache Entry: 361
ASCII text, with very long lines (65458)
dropped
Chrome Cache Entry: 362
Unicode text, UTF-8 text, with very long lines (63657)
downloaded
Chrome Cache Entry: 363
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 364
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 2000x312, components 3
dropped
Chrome Cache Entry: 367
ASCII text, with very long lines (354), with no line terminators
dropped
Chrome Cache Entry: 369
ASCII text, with very long lines (723)
downloaded
Chrome Cache Entry: 370
JSON data
dropped
Chrome Cache Entry: 371
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 372
ASCII text, with very long lines (799)
downloaded
Chrome Cache Entry: 373
ASCII text, with very long lines (12559), with no line terminators
dropped
Chrome Cache Entry: 374
ASCII text, with very long lines (25087), with no line terminators
dropped
Chrome Cache Entry: 376
ASCII text, with very long lines (354), with no line terminators
dropped
Chrome Cache Entry: 379
ASCII text, with very long lines (5028), with no line terminators
downloaded
Chrome Cache Entry: 380
ASCII text, with very long lines (2343)
dropped
Chrome Cache Entry: 381
ASCII text, with very long lines (5245), with no line terminators
dropped
Chrome Cache Entry: 384
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 385
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 387
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 388
ASCII text, with very long lines (8868)
dropped
Chrome Cache Entry: 389
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 391
ASCII text, with very long lines (17927), with no line terminators
dropped
Chrome Cache Entry: 393
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 394
gzip compressed data, truncated
dropped
Chrome Cache Entry: 395
ASCII text, with very long lines (4965), with no line terminators
downloaded
Chrome Cache Entry: 396
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 397
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 398
ASCII text, with very long lines (9454)
dropped
Chrome Cache Entry: 399
ASCII text, with very long lines (12537)
dropped
Chrome Cache Entry: 400
ASCII text, with very long lines (15413)
dropped
Chrome Cache Entry: 402
ASCII text, with very long lines (42209), with no line terminators
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (49270)
dropped
Chrome Cache Entry: 407
gzip compressed data, was "tmpjha2tmpq", last modified: Wed Oct 30 18:39:44 2024, max compression, original size modulo 2^32 292742
dropped
Chrome Cache Entry: 408
JSON data
dropped
There are 90 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://www.wayfair.com/the-wayfair-app?pid=Email&c=Triggered&af_sub5=AppEmail&refid=7d34ad67-4987-430c-a5bd-5dacc342b623
https://www.wayfair.com/the-wayfair-app?pid=Email&c=Triggered&af_sub5=AppEmail&refid=7d34ad67-4987-430c-a5bd-5dacc342b623
https://www.wayfair.com/the-wayfair-app?

Domains

Name
IP
Malicious
d3nocrch4qti4v.cloudfront.net
18.239.47.225
eu-aa.online-metrix.net
91.235.132.129
cadmus2.script.ac
104.18.23.145
stats.g.doubleclick.net
64.233.166.155
collector-px3vk96i6i.perimeterx.net
35.190.10.96
dualstack.tls13.taboola.map.fastly.net
151.101.129.44
h-signifyd.online-metrix.net
91.235.133.113
cdn3.forter.com
13.225.78.57
cm.g.doubleclick.net
142.250.185.98
www.google.com
142.250.185.68
d.impactradius-event.com
35.186.249.72
cdn0.forter.com
54.243.108.33
attribution.eks.adswizz.com
54.77.181.155
match.adsrvr.org
35.71.131.137
star-mini.c10r.facebook.com
157.240.251.35
google.com
172.217.16.206
ampcid.google.com
142.250.186.78
ec2-52-23-111-175.compute-1.amazonaws.com
52.23.111.175
edge.fullstory.com
35.201.112.186
events-router-v8tt.zeet-audiohook-gcp-us-east.zeet.app
34.145.223.123
stk.px-cloud.net
34.107.199.61
d2wpodxytd2amw.cloudfront.net
13.225.78.31
dualstack.reddit.map.fastly.net
151.101.129.140
d2o5idwacg3gyw.cloudfront.net
18.239.82.16
prod.pinterest.global.map.fastly.net
151.101.0.84
reddit.map.fastly.net
151.101.193.140
googleads.g.doubleclick.net
142.250.186.66
duihxgfnjg37f.cloudfront.net
13.225.78.14
td.doubleclick.net
142.250.185.162
fcmatch.google.com
142.250.185.174
rtb.adgrx.com
52.215.155.11
trkn.us
95.101.111.156
h.online-metrix.net
91.235.132.130
d34r8q7sht0t9k.cloudfront.net
18.244.20.227
wayfair.map.fastly.net
151.101.193.148
dg2iu7dxxehbo.cloudfront.net
18.172.103.101
cdn123.forter.com
18.245.31.49
w2txo5aaz5xynbkcp743rzu4riudqnbpeuxabghd85a8dcd64d62a7dfam1.e.aa.online-metrix.net
91.235.134.131
f86be5977dba498685812fb867539513-29e1a833e2dd.cdn.forter.com
3.234.25.89
d332pxdz2f5on5.cloudfront.net
108.138.26.78
spdc-global.pbp.gysm.yahoodns.net
54.171.122.26
www.wayfair.map.fastly.net
151.101.1.252
cdn.prod.gcp.sift.com
34.96.67.224
k8s-gateways-gwlh2-8b9819a160-1697331022.us-east-1.elb.amazonaws.com
34.201.90.126
insight.adsrvr.org
52.223.40.198
t.wayfair.map.fastly.net
151.101.1.253
scontent.xx.fbcdn.net
157.240.0.6
idsync.rlcdn.com
35.244.174.68
h64.online-metrix.net
192.225.158.1
gcp.api.sc-gw.com
35.190.43.134
aa.online-metrix.net
91.235.132.129
ipv4.podscribe.com
54.173.114.202
cdn9.forter.com
3.160.150.32
pixel.tapad.com
34.111.113.62
s.pxltgr.com
18.201.168.80
fcmatch.youtube.com
172.217.16.142
k8s-gateways-gwlh1-a7d3a27fb9-307271065.us-east-1.elb.amazonaws.com
44.197.29.181
hexagon-analytics.com
34.102.232.42
ax-0001.ax-msedge.net
150.171.27.10
rs.fullstory.com
35.186.194.58
img.riskified.com
52.2.192.23
29e1a833e2dd.cdn4.forter.com
18.245.86.4
dcjdc5qmbbux7.cloudfront.net
13.224.189.98
analytics.google.com
216.58.206.46
verifi.podscribe.com
52.22.152.64
ib.anycast.adnxs.com
185.89.210.122
img.byspotify.com
34.120.89.57
crcldu.com
104.18.1.150
alb.reddit.com
unknown
tr.snapchat.com
unknown
secure.adnxs.com
unknown
assets.wfcdn.com
unknown
nel.wayfair.io
unknown
cdn.attn.tv
unknown
js.adsrvr.org
unknown
www.redditstatic.com
unknown
listen.audiohook.com
unknown
imgs.signifyd.com
unknown
pixel.rubiconproject.com
unknown
trc.taboola.com
unknown
www.wayfair.com
unknown
connect.facebook.net
unknown
px.ads.linkedin.com
unknown
adresults-60-adswizz.attribution.adswizz.com
unknown
dc.ads.linkedin.com
unknown
www.mczbf.com
unknown
sp.analytics.yahoo.com
unknown
w3-reporting-nel.reddit.com
unknown
ct.pinterest.com
unknown
client.perimeterx.net
unknown
js.cnnx.link
unknown
cdn.siftscience.com
unknown
cdn-scripts.signifyd.com
unknown
pixel-config.reddit.com
unknown
pt.ispot.tv
unknown
beacon.riskified.com
unknown
www.facebook.com
unknown
c.riskified.com
unknown
www.linkedin.com
unknown
wayfair-us.attn.tv
unknown
There are 90 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
151.101.0.84
prod.pinterest.global.map.fastly.net
United States
104.18.42.218
unknown
United States
35.186.194.58
rs.fullstory.com
United States
18.244.20.200
unknown
United States
91.235.133.113
h-signifyd.online-metrix.net
Netherlands
151.101.193.148
wayfair.map.fastly.net
United States
185.89.210.153
unknown
Germany
142.250.185.100
unknown
United States
142.250.185.226
unknown
United States
216.58.206.59
unknown
United States
13.224.189.98
dcjdc5qmbbux7.cloudfront.net
United States
3.160.150.32
cdn9.forter.com
United States
18.239.82.122
unknown
United States
23.215.23.189
unknown
United States
151.101.193.140
reddit.map.fastly.net
United States
151.101.65.140
unknown
United States
34.145.223.123
events-router-v8tt.zeet-audiohook-gcp-us-east.zeet.app
United States
34.227.253.14
unknown
United States
34.120.89.57
img.byspotify.com
United States
151.101.129.253
unknown
United States
35.71.131.137
match.adsrvr.org
United States
172.217.16.142
fcmatch.youtube.com
United States
142.250.186.78
ampcid.google.com
United States
1.1.1.1
unknown
Australia
3.253.196.31
unknown
United States
74.125.133.84
unknown
United States
142.250.185.232
unknown
United States
13.225.78.14
duihxgfnjg37f.cloudfront.net
United States
216.58.206.46
analytics.google.com
United States
104.18.43.135
unknown
United States
172.64.148.35
unknown
United States
64.233.166.155
stats.g.doubleclick.net
United States
239.255.255.250
unknown
Reserved
18.239.36.90
unknown
United States
108.138.26.78
d332pxdz2f5on5.cloudfront.net
United States
35.244.174.68
idsync.rlcdn.com
United States
216.58.212.162
unknown
United States
52.2.192.23
img.riskified.com
United States
34.102.232.42
hexagon-analytics.com
United States
91.235.132.130
h.online-metrix.net
Netherlands
142.250.185.206
unknown
United States
172.217.18.14
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.168
unknown
United States
142.250.181.234
unknown
United States
157.240.0.6
scontent.xx.fbcdn.net
United States
54.173.114.202
ipv4.podscribe.com
United States
18.65.39.123
unknown
United States
142.250.185.162
td.doubleclick.net
United States
91.235.134.131
w2txo5aaz5xynbkcp743rzu4riudqnbpeuxabghd85a8dcd64d62a7dfam1.e.aa.online-metrix.net
Netherlands
172.217.18.110
unknown
United States
52.215.155.11
rtb.adgrx.com
United States
18.239.82.16
d2o5idwacg3gyw.cloudfront.net
United States
142.250.110.84
unknown
United States
52.23.111.175
ec2-52-23-111-175.compute-1.amazonaws.com
United States
35.190.43.134
gcp.api.sc-gw.com
United States
18.245.33.25
unknown
United States
151.101.1.140
unknown
United States
150.171.27.10
ax-0001.ax-msedge.net
United States
142.250.185.174
fcmatch.google.com
United States
157.240.253.1
unknown
United States
104.18.1.150
crcldu.com
United States
151.101.129.140
dualstack.reddit.map.fastly.net
United States
142.250.186.66
googleads.g.doubleclick.net
United States
142.250.185.98
cm.g.doubleclick.net
United States
52.22.152.64
verifi.podscribe.com
United States
2.18.64.26
unknown
European Union
54.77.181.155
attribution.eks.adswizz.com
United States
151.101.1.253
t.wayfair.map.fastly.net
United States
151.101.1.252
www.wayfair.map.fastly.net
United States
18.201.168.80
s.pxltgr.com
United States
34.96.67.224
cdn.prod.gcp.sift.com
United States
54.211.253.197
unknown
United States
95.101.111.156
trkn.us
European Union
18.239.47.225
d3nocrch4qti4v.cloudfront.net
United States
95.101.111.153
unknown
European Union
18.245.86.69
unknown
United States
142.250.186.35
unknown
United States
142.250.185.68
www.google.com
United States
3.33.220.150
unknown
United States
54.243.108.33
cdn0.forter.com
United States
142.250.184.194
unknown
United States
185.89.210.122
ib.anycast.adnxs.com
Germany
54.171.122.26
spdc-global.pbp.gysm.yahoodns.net
United States
13.225.78.57
cdn3.forter.com
United States
13.107.42.14
unknown
United States
142.250.186.187
unknown
United States
142.250.186.100
unknown
United States
54.246.144.89
unknown
United States
142.250.184.238
unknown
United States
52.223.40.198
insight.adsrvr.org
United States
35.190.10.96
collector-px3vk96i6i.perimeterx.net
United States
18.244.20.227
d34r8q7sht0t9k.cloudfront.net
United States
18.172.103.101
dg2iu7dxxehbo.cloudfront.net
United States
18.239.67.100
unknown
United States
52.204.87.38
unknown
United States
216.58.206.78
unknown
United States
69.173.144.139
unknown
United States
104.18.23.145
cadmus2.script.ac
United States
69.173.144.138
unknown
United States
There are 90 hidden IPs, click here to show them.