Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 132
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 133
|
PNG image data, 528 x 528, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 134
|
HTML document, Unicode text, UTF-8 text, with very long lines (20403)
|
downloaded
|
||
Chrome Cache Entry: 135
|
PNG image data, 532 x 532, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 136
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 137
|
PNG image data, 2880 x 952, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 138
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 139
|
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 140
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 141
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 142
|
PNG image data, 528 x 528, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 143
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 144
|
PNG image data, 2880 x 952, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 145
|
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 146
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 147
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 148
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 149
|
PNG image data, 532 x 532, 8-bit/color RGB, non-interlaced
|
dropped
|
There are 15 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1916,i,694644445453319614,14567216347516798064,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
|
|||
https://site.ntesmail.com/umi.7010d9a0.css
|
47.246.46.227
|
||
https://site.ntesmail.com/static/contact_bg.2c30255a.png
|
47.246.46.227
|
||
https://tailwindcss.com
|
unknown
|
||
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
|
|||
https://site.ntesmail.com/umi.1961b306.js
|
47.246.46.227
|
||
https://waimao.office.163.com/site/favicon.png
|
139.95.8.252
|
||
https://sentry2.lx.netease.com/api/16/envelope/?sentry_key=c1c4787cd71a4b3eb8c70bc6f2e1b2e0&sentry_version=7&sentry_client=sentry.javascript.browser%2F7.69.0
|
59.111.243.39
|
||
https://site.ntesmail.com/static/hot.643d43d1.svg
|
47.246.46.227
|
||
https://site.ntesmail.com/static/alibaba.84fa3c8d.svg
|
47.246.46.227
|
||
https://waimao.office.163.com/site/api/pub/site/track?opType=OPEN_PRODUCT_DETAILS&mid=8e88ea30-34d0-4984-8658-fa597e8623e4&productId=1184757&cid=site%255C_ngxvLcIm8CN043WgmaKV5L8RaPSew%255C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
|
139.95.8.252
|
||
https://waimao.office.163.com/site/api/pub/site/track?opType=TRACK_DATA&mid=8e88ea30-34d0-4984-8658-fa597e8623e4&productId=1184757&cid=site%255C_ngxvLcIm8CN043WgmaKV5L8RaPSew%255C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&sendType=first
|
139.95.8.252
|
||
https://waimao.office.163.com/site/api/pub/site/track?opType=TRACK_DATA&mid=8e88ea30-34d0-4984-8658-fa597e8623e4&productId=1184757&cid=site%255C_ngxvLcIm8CN043WgmaKV5L8RaPSew%255C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&sendType=other
|
139.95.8.252
|
||
https://qiye.163.com/sirius/privacy_waimao/index.html
|
unknown
|
||
https://qiye.163.com/sirius/agreement_waimao/index.html
|
unknown
|
There are 4 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
sentry2.lx.netease.com
|
59.111.243.39
|
||
www.google.com
|
142.250.185.132
|
||
site.ntesmail.com.w.cdngslb.com
|
47.246.46.227
|
||
cowork-storage.nosdn.127.net.w.cdngslb.com
|
163.181.92.229
|
||
hwweb.qiye.ntes53.netease.com
|
139.95.8.252
|
||
waimao.office.163.com
|
unknown
|
||
cowork-storage.nosdn.127.net
|
unknown
|
||
site.ntesmail.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
163.181.92.229
|
cowork-storage.nosdn.127.net.w.cdngslb.com
|
United States
|
||
59.111.243.39
|
sentry2.lx.netease.com
|
China
|
||
192.168.2.16
|
unknown
|
unknown
|
||
142.250.185.132
|
www.google.com
|
United States
|
||
47.246.24.224
|
unknown
|
United States
|
||
139.95.8.252
|
hwweb.qiye.ntes53.netease.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
47.246.46.227
|
site.ntesmail.com.w.cdngslb.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
|
||
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
|