IOC Report
https://wistia.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 05:40:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 05:40:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 05:40:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 05:40:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 05:40:47 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 234
HTML document, Unicode text, UTF-8 text, with very long lines (8928)
dropped
Chrome Cache Entry: 236
HTML document, Unicode text, UTF-8 text, with very long lines (11684)
dropped
Chrome Cache Entry: 237
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 238
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 2500x1406, components 3
downloaded
Chrome Cache Entry: 239
Unicode text, UTF-8 text, with very long lines (26941), with no line terminators
downloaded
Chrome Cache Entry: 240
MPEG transport stream data
dropped
Chrome Cache Entry: 241
MPEG transport stream data
downloaded
Chrome Cache Entry: 242
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 245
Unicode text, UTF-8 text, with very long lines (26099), with no line terminators
downloaded
Chrome Cache Entry: 246
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 247
JSON data
downloaded
Chrome Cache Entry: 248
CSV text
downloaded
Chrome Cache Entry: 250
ASCII text, with very long lines (955), with no line terminators
downloaded
Chrome Cache Entry: 251
Unicode text, UTF-8 text, with very long lines (49252)
downloaded
Chrome Cache Entry: 253
CSV text
downloaded
Chrome Cache Entry: 256
Unicode text, UTF-8 text, with very long lines (17923), with no line terminators
downloaded
Chrome Cache Entry: 257
JSON data
dropped
Chrome Cache Entry: 259
M3U playlist, ASCII text
dropped
Chrome Cache Entry: 261
JSON data
downloaded
Chrome Cache Entry: 263
ASCII text, with very long lines (14578), with no line terminators
downloaded
Chrome Cache Entry: 264
gzip compressed data, was "sp.js", last modified: Tue Apr 20 16:54:13 2021, from Unix, original size modulo 2^32 113865
downloaded
Chrome Cache Entry: 265
Unicode text, UTF-8 text, with very long lines (35811), with no line terminators
downloaded
Chrome Cache Entry: 266
HTML document, Unicode text, UTF-8 text, with very long lines (13142)
downloaded
Chrome Cache Entry: 267
HTML document, Unicode text, UTF-8 text, with very long lines (6956)
downloaded
Chrome Cache Entry: 268
Unicode text, UTF-8 text, with very long lines (35229), with no line terminators
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (9416)
downloaded
Chrome Cache Entry: 270
HTML document, Unicode text, UTF-8 text, with very long lines (14418)
dropped
Chrome Cache Entry: 271
Unicode text, UTF-8 text, with very long lines (33710), with no line terminators
downloaded
Chrome Cache Entry: 272
Unicode text, UTF-8 text, with very long lines (32221), with no line terminators
downloaded
Chrome Cache Entry: 273
ASCII text, with very long lines (5955)
downloaded
Chrome Cache Entry: 443
ASCII text, with very long lines (53244), with no line terminators
downloaded
Chrome Cache Entry: 446
Web Open Font Format (Version 2), CFF, length 43188, version 2.131
downloaded
Chrome Cache Entry: 447
Unicode text, UTF-8 text, with very long lines (11176)
downloaded
Chrome Cache Entry: 448
MPEG transport stream data
dropped
Chrome Cache Entry: 449
HTML document, Unicode text, UTF-8 text, with very long lines (16681)
dropped
Chrome Cache Entry: 450
ASCII text, with very long lines (15094)
downloaded
Chrome Cache Entry: 455
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 456
ASCII text, with very long lines (15041)
downloaded
Chrome Cache Entry: 457
CSV text
downloaded
Chrome Cache Entry: 458
ASCII text, with very long lines (1468), with no line terminators
downloaded
Chrome Cache Entry: 460
JSON data
dropped
Chrome Cache Entry: 463
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 465
ASCII text, with very long lines (952), with no line terminators
downloaded
Chrome Cache Entry: 468
JSON data
dropped
Chrome Cache Entry: 470
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 474
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 475
ASCII text, with very long lines (65470)
downloaded
Chrome Cache Entry: 476
Unicode text, UTF-8 text, with very long lines (26279), with no line terminators
downloaded
Chrome Cache Entry: 477
ASCII text, with very long lines (56373), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 479
ASCII text, with very long lines (65474)
downloaded
Chrome Cache Entry: 480
HTML document, ASCII text, with very long lines (628), with no line terminators
downloaded
Chrome Cache Entry: 482
ASCII text, with very long lines (17563)
downloaded
Chrome Cache Entry: 486
CSV text
downloaded
Chrome Cache Entry: 488
ASCII text, with very long lines (5391), with no line terminators
downloaded
Chrome Cache Entry: 491
HTML document, Unicode text, UTF-8 text, with very long lines (19414)
dropped
Chrome Cache Entry: 495
ASCII text, with very long lines (5796)
downloaded
Chrome Cache Entry: 496
CSV text
downloaded
Chrome Cache Entry: 500
TrueType Font data, 16 tables, 1st "GDEF", 32 names, Microsoft, language 0x409, Copyright 2020 The Inter Project Authors (https://github.com/rsms/inter)Inter SemiBoldRegular3.0
downloaded
Chrome Cache Entry: 501
ASCII text, with very long lines (46268)
downloaded
Chrome Cache Entry: 503
Unicode text, UTF-8 text, with very long lines (23410), with no line terminators
downloaded
Chrome Cache Entry: 504
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 506
ASCII text, with very long lines (23371)
downloaded
Chrome Cache Entry: 509
ASCII text, with very long lines (12509), with no line terminators
downloaded
Chrome Cache Entry: 511
SVG Scalable Vector Graphics image
dropped
There are 61 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://wistia.com
https://10381301.fls.doubleclick.net/activityi;dc_pre=COPV-93umIUDFSAcdgYd2qEJ2g;src=10381301;type=conve0;cat=allpa0;ord=455095406348;npa=0;auiddc=967179300.1711694449;ps=1;pcor=259813580;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;gtm=45fe43r0z878021145za201;gcd=13l3l3l3l1;dma=0;epver=2;~oref=https%3A%2F%2Fwistia.com%2F?
https://wistia.com/
https://match.adsrvr.org/track/cmf/rubicon?gdpr=0
https://match.adsrvr.org/track/upb/?adv=9zh5f4r&ref=https%3A%2F%2Fwistia.com%2F&upid=gbxsjnb&upv=1.1.0
about:blank
https://match.adsrvr.org/track/cmf/generic?ttd_pid=rightmedia
https://match.adsrvr.org/track/cmf/google?g_uuid=&gdpr=0&gdpr_consent=&ttd_tdid=f85562e9-043c-4cd8-bcf1-33efad45c18a&google_gid=CAESENUDqES_kpHwsLIZDb3mAFk&google_cver=1
https://td.doubleclick.net/td/fls/rul/activityi;fledge=1;src=10381301;type=conve0;cat=allpa0;ord=455095406348;npa=0;auiddc=967179300.1711694449;ps=1;pcor=259813580;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;gtm=45fe43r0z878021145za201;gcd=13l3l3l3l1;dma=0;epver=2;~oref=https%3A%2F%2Fwistia.com%2F?

Domains

Name
IP
Malicious
d2rpa84eq2akk3.cloudfront.net
18.165.98.104
d3orhvfyxudxxq.cloudfront.net
18.165.83.58
dart.l.doubleclick.net
172.253.62.149
hb.yahoo.net
23.15.9.48
d2iok8515ir7ba.cloudfront.net
13.35.90.200
cta-service-cms2.hubspot.com
104.16.117.116
dg2iu7dxxehbo.cloudfront.net
18.67.60.119
adservice.google.com
172.253.62.154
platform.twitter.map.fastly.net
146.75.28.157
stats.g.doubleclick.net
142.251.167.154
events.fivetran.com
34.139.124.58
cname-wistia-app-production.wistia.com
99.84.191.44
partnerlinks.io
104.18.31.133
pagestates-tracking.crazyegg.com
18.165.98.104
insight.adsrvr.org
35.71.131.137
scontent.xx.fbcdn.net
157.240.229.1
t.co
104.244.42.197
track.hubspot.com
104.16.118.116
global-v4.clearbit.com
54.235.212.140
d36ufq1ap5wy15.cloudfront.net
13.249.39.125
wistia.com
151.101.129.91
cm.g.doubleclick.net
172.253.63.155
gscwidgets2.b-cdn.net
37.19.207.34
tracking.g2crowd.com
172.64.144.225
www.google.com
172.253.122.147
app.clearbit.com
3.132.189.106
grsm.io
104.18.11.212
match.adsrvr.org
52.223.40.198
star-mini.c10r.facebook.com
31.13.66.35
js.hs-banner.com
104.18.34.229
s.twitter.com
104.244.42.131
ad.doubleclick.net
142.251.179.148
js.hubspot.com
104.16.117.116
js-na1.hs-scripts.com
104.16.189.89
d1p8wauaa7285.cloudfront.net
18.67.76.79
googleads.g.doubleclick.net
142.251.167.157
d1wkvjvkgmsn1g.cloudfront.net
99.86.227.127
assets-tracking.crazyegg.com
18.67.65.8
td.doubleclick.net
172.253.63.154
js.partnerstack.com
104.18.7.218
perf-na1.hsforms.com
104.18.176.125
us.intercomhelpcenter.com
172.64.148.108
tracking.crazyegg.com
3.134.182.71
static.ads-twitter.com
unknown
script.crazyegg.com
unknown
l.getsitecontrol.com
unknown
js.adsrvr.org
unknown
pixel.rubiconproject.com
unknown
images.ctfassets.net
unknown
embed-ssl.wistia.com
unknown
connect.facebook.net
unknown
px.ads.linkedin.com
unknown
fast.wistia.net
unknown
fast.wistia.com
unknown
support.wistia.com
unknown
embed-cloudfront.wistia.com
unknown
x.clearbitjs.com
unknown
10381301.fls.doubleclick.net
unknown
distillery.wistia.com
unknown
www.facebook.com
unknown
www.linkedin.com
unknown
analytics.twitter.com
unknown
snap.licdn.com
unknown
pipedream.wistia.com
unknown
app.wistia.com
unknown
There are 55 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.253.62.154
adservice.google.com
United States
204.79.197.200
unknown
United States
172.64.148.108
us.intercomhelpcenter.com
United States
18.67.65.8
assets-tracking.crazyegg.com
United States
146.75.28.157
platform.twitter.map.fastly.net
Sweden
151.101.129.91
wistia.com
United States
172.253.63.155
cm.g.doubleclick.net
United States
142.251.111.105
unknown
United States
104.16.118.116
track.hubspot.com
United States
34.139.124.58
events.fivetran.com
United States
69.173.151.100
unknown
United States
18.67.76.28
unknown
United States
18.165.83.58
d3orhvfyxudxxq.cloudfront.net
United States
142.251.179.148
ad.doubleclick.net
United States
172.253.62.149
dart.l.doubleclick.net
United States
99.86.227.61
unknown
United States
35.71.131.137
insight.adsrvr.org
United States
13.249.39.125
d36ufq1ap5wy15.cloudfront.net
United States
1.1.1.1
unknown
Australia
23.15.9.48
hb.yahoo.net
United States
18.165.83.89
unknown
United States
172.253.63.149
unknown
United States
104.244.42.131
s.twitter.com
United States
157.240.229.35
unknown
United States
172.253.122.147
www.google.com
United States
104.19.148.8
unknown
United States
18.67.65.42
unknown
United States
142.251.16.106
unknown
United States
13.107.42.14
unknown
United States
172.253.63.154
td.doubleclick.net
United States
239.255.255.250
unknown
Reserved
104.17.207.249
unknown
United States
151.101.193.91
unknown
United States
3.132.189.106
app.clearbit.com
United States
18.165.98.104
d2rpa84eq2akk3.cloudfront.net
United States
52.223.40.198
match.adsrvr.org
United States
104.18.31.133
partnerlinks.io
United States
172.253.115.84
unknown
United States
104.18.176.125
perf-na1.hsforms.com
United States
13.35.90.200
d2iok8515ir7ba.cloudfront.net
United States
142.250.31.102
unknown
United States
192.168.2.16
unknown
unknown
99.84.191.3
unknown
United States
142.251.167.102
unknown
United States
142.251.167.148
unknown
United States
142.251.167.94
unknown
United States
18.67.76.43
unknown
United States
37.19.207.34
gscwidgets2.b-cdn.net
Ukraine
172.64.144.225
tracking.g2crowd.com
United States
104.18.11.212
grsm.io
United States
52.20.167.62
unknown
United States
142.251.163.94
unknown
United States
104.18.7.218
js.partnerstack.com
United States
142.251.167.97
unknown
United States
3.138.218.16
unknown
United States
18.67.60.119
dg2iu7dxxehbo.cloudfront.net
United States
104.16.189.89
js-na1.hs-scripts.com
United States
142.251.167.154
stats.g.doubleclick.net
United States
54.235.212.140
global-v4.clearbit.com
United States
104.244.42.69
unknown
United States
31.13.66.35
star-mini.c10r.facebook.com
Ireland
142.250.31.156
unknown
United States
3.134.182.71
tracking.crazyegg.com
United States
23.199.63.147
unknown
United States
104.244.42.67
unknown
United States
104.18.34.229
js.hs-banner.com
United States
142.251.167.157
googleads.g.doubleclick.net
United States
142.251.167.113
unknown
United States
104.244.42.197
t.co
United States
157.240.229.1
scontent.xx.fbcdn.net
United States
104.19.147.8
unknown
United States
142.251.163.138
unknown
United States
99.86.227.127
d1wkvjvkgmsn1g.cloudfront.net
United States
18.67.76.79
d1p8wauaa7285.cloudfront.net
United States
151.101.2.132
unknown
United States
104.16.117.116
cta-service-cms2.hubspot.com
United States
18.165.98.71
unknown
United States
99.84.191.44
cname-wistia-app-production.wistia.com
United States
There are 68 hidden IPs, click here to show them.