Click to jump to signature section
Source: https://ntp2.mywavehome.net/ | Joe Sandbox AI: Score: 7 Reasons: The brand 'Amazon' is well-known and typically associated with the domain 'amazon.com'., The URL 'ntp2.mywavehome.net' does not match the legitimate domain 'amazon.com'., The domain 'mywavehome.net' does not have any known association with Amazon., The presence of a subdomain 'ntp2' and the unrelated primary domain 'mywavehome.net' are suspicious., No input fields were provided, making it difficult to assess the purpose of the site. DOM: 1.1.pages.csv |
Source: 0.46.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://103766.click.validclick.net/cad.php?utm_so... This script exhibits several high-risk behaviors, including the use of obfuscated URLs and potential data exfiltration. The script loads an external script from a domain ('admd.ink') that is not a known, reputable domain, which increases the risk of malicious activity. Additionally, the script passes sensitive parameters like 'ak', 'ci', 's1', 's2', and 's3' in the URL, which could be used to transmit user data to untrusted parties. Overall, the combination of these factors suggests a high-risk script that requires further investigation. |
Source: https://ntp2.mywavehome.net/ | HTTP Parser: Total embedded image size: 12642 |
Source: https://ntp2.mywavehome.net/ | HTTP Parser: Base64 decoded: 01199ff44b79f74b7200ef4fd9e40405 |
Source: https://ntp2.mywavehome.net/ | HTTP Parser: No favicon |
Source: https://ntp2.mywavehome.net/ | HTTP Parser: No favicon |
Source: https://ntp2.mywavehome.net/ | HTTP Parser: No favicon |
Source: https://ntp2.mywavehome.net/ | HTTP Parser: No favicon |
Source: https://103766.click.validclick.net/cad.php?utm_source=103766&utm_medium=118593_NONE000&mc=Iy07PDclNCIvOCU-MiUtIio5NTEmNyEjM3lpanA5dWhhdSJidWV8Z3Z8bHF3d2gyPzMgOSIgOisyNiQqJSIyPzMhMiAvPysyNiEsIS0_PzghLyQsMytgcGBpYSAnKnVmdjl4ZHBya3o3cXVlOiRlYHAkfGJsYXFhYnZhZmtlcjorOSsyNSMqKy88PDMnMC0jMyswKiAvPCs6NiwgOS4jM1xnfn11fnsnMCwhIT9OYH9sa2NqMlRcJTMhLyciKUZhaiItKTpwMzY4IVZpeX1tU3F7WXN8KjciNjkqPzEgT1xNX1YkJW54anI5TnRrb3swMllgd218ZDgoOCYmNDopPCooVmN3YGVwJiQ7MzoqJCAyNTgrQkdaMys4Pi4pKCA5NDokOCQjM3lpanA5dWhhdSJidWV8Z3Z8bHF3d2g%2C&adv=20378&country=USA&fqp=1&affiliate=veve&given_xmlfeed=AdvertiserCPC&given_search_ref=https://ww55.affinity.net/&given_subid=NONE000&given_aff_id=118593&given_feed_id=2853&aff_clickid=&subid=NONE000 | HTTP Parser: No favicon |
Source: https://www.amazon.com/?&tag=usdeexplicits-20 | HTTP Parser: No favicon |
Source: https://www.amazon.com/errors/validateCaptcha?amzn=AFXynIyWGCijBRPPbHGlwQ%3D%3D&amzn-r=%2F%3F%26tag%3Dusdeexplicits-20&field-keywords= | HTTP Parser: No favicon |
Source: https://www.amazon.com/errors/validateCaptcha?amzn=J1B%2FuxJoz0P20yEGK8h3wA%3D%3D&amzn-r=%2F%3F%26tag%3Dusdeexplicits-20&field-keywords= | HTTP Parser: No favicon |
Source: https://www.amazon.com/errors/validateCaptcha?amzn=SVnvcOC1T%2BYzuhKVUA24wg%3D%3D&amzn-r=%2F%3F%26tag%3Dusdeexplicits-20&field-keywords= | HTTP Parser: No favicon |
Source: https://www.amazon.com/errors/validateCaptcha?amzn=vHjYshdIKS04Jd%2FnqQ8VAA%3D%3D&amzn-r=%2F%3F%26tag%3Dusdeexplicits-20&field-keywords= | HTTP Parser: No favicon |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49715 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49773 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50082 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50346 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:50458 version: TLS 1.2 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | HTTP traffic: Redirect from: ww10.affinity.net to https://amzn-adsystem.com/?aid=118593&ref=veve.com&dest=https%3a%2f%2fwww.amazon.com |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | HTTP traffic: Redirect from: amzn-adsystem.com to https://click.validclick.net/rdr2.php?aff_id=118593&cmp=103766&from_amzn=1&ref=veve.com&url=https://amazon.com&dest=https%3a%2f%2fwww.amazon.com%3f |
Source: global traffic | DNS traffic detected: number of DNS queries: 105 |
Source: Network traffic | Suricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.6:50149 -> 18.184.206.66:443 |
Source: Network traffic | Suricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.6:50312 -> 173.198.250.30:443 |
Source: Network traffic | Suricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.6:50331 -> 104.22.10.122:443 |
Source: Network traffic | Suricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.6:50338 -> 104.22.10.122:443 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.132.25.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1Host: ntp2.mywavehome.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /_nuxt/entry.DiUaY6J1.css HTTP/1.1Host: ntp2.mywavehome.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://ntp2.mywavehome.netsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://ntp2.mywavehome.net/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: AWSALB=rJMuVgidpjcgO5nIEpPtouGEogzu1bXafFdW94RKBGGceeiB9zZysmCIoAMY4K7aX3oITOZbfI4eym0VaR2r8GGPx1QjIe6P3466SE/1f0gelxrJLVB3MjQroklh; AWSALBCORS=rJMuVgidpjcgO5nIEpPtouGEogzu1bXafFdW94RKBGGceeiB9zZysmCIoAMY4K7aX3oITOZbfI4eym0VaR2r8GGPx1QjIe6P3466SE/1f0gelxrJLVB3MjQroklh; AWSALBTG=juZeFh3quDRQeizOgTAYZbonoOh6LGSUjTv5srbMqR1LGLMu26nODNrnJI/SpTGzzoEJh/6VRLvptasDOgejBkianMbmlAd2f+7vZuFmxSNmH/Y0ssTkxZu/bEU2uS7guT7/FJZT1V6+mMFcc3/hLEXrHvRTv1fawpuOpMsj3xja; 21 Feb 2025 15:05:32 GMT; AWSALBTGCORS=juZeFh3quDRQeizOgTAYZbonoOh6LGSUjTv5srbMqR1LGLMu26nODNrnJI/SpTGzzoEJh/6VRLvptasDOgejBkianMbmlAd2f+7vZuFmxSNmH/Y0ssTkxZu/bEU2uS7guT7/FJZT1V6+mMFcc3/hLEXrHvRTv1fawpuOpMsj3xja; data=%7B%22UserId%22%3A%2218e060c2-d0aa-4d77-9dde-17bdcbbde4bf%22%2C%22TrackingId%22%3Anull%2C%22Keyword%22%3A%22%22%2C%22UserClass%22%3A%2220250214%22%2C%22GGLNT%22%3Anull%2C%22GCLID%22%3Anull%2C%22AdProvider%22%3A%22appfocus1%22%2C%22Source%22%3A%22%22%2C%22Implementation%22%3A%22wav%22%7D; 26 Feb 2025 15:05:32 GMT; pageflags=%7B%22flagsDataString%22%3A%22%5B%5C%22v207%3Actrl%5C%22%2C%5C%22stub165%3Aon%5C%22%2C%5C%22capNotif%3Aon%5C%22%2C%5C%22sponsoredGroup%3Aon%5C%22%2C%5C%22bigStub%3Aon%5C%22%2C%5C%22t2-92%3Aon%5C%22%2C%5C%22vuentp%3Aon%5C%22%2C%5C%22wavwbnui%3Aon%5C%22%2C%5C%22oldNTPLayout%3Aedge%5C%22%2C%5C%22newsFeed%3Aon%5C%22%2C%5C%22responsiveScreens%3Aon%5C%22%2C%5C%22fourTiles%3Aon%5C%22%2C%5C%22ntpOpenSearch%3Aon%5C%22%2C%5C%22darkmode%3Aon%5C%22%2C%5C%22nadm%3Aon%5C%22%2C%5C%22newTblaTag%3Aon%5C%22%2C%5C%22typtest%3Aon%5C%22%2C%5C%22outbrain%3Aon%5C%22%2C%5C%22dailyInts%3Actrl%5C%22%2C%5C%22wavtymessage%3Aon%5C%22%2C%5C%22benTestWav%3Aon%5C%22%5D%22%2C%22debugSegments%22%3A%22%22%2C%22tests%22%3A%7B%22isEdgeLayout%22%3Afalse%2C%22isEdgeLayoutv2%22%3Afalse%2C%22isFireFoxLayout%22%3Afalse%2C%22isFatigueLayout%22%3Afalse%2C%22isFatigueLayoutDefault%22%3Afalse%2C%22isFatigueLayoutAlt%22%3Afalse%2C%22isC |