Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://pear-02.mfgtcvb.eu.org/

Overview

General Information

Sample URL:http://pear-02.mfgtcvb.eu.org/
Analysis ID:1594010
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
HTML page contains obfuscated javascript
Program does not show much activity (idle)

Classification

  • System is w10x64
  • chrome.exe (PID: 6056 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6440 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2216 --field-trial-handle=2144,i,8688760562165855632,6171228347105639683,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 1104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5080 --field-trial-handle=2144,i,8688760562165855632,6171228347105639683,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 4524 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pear-02.mfgtcvb.eu.org/" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://pear-02.mfgtcvb.eu.org/Avira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: https://js.player.cntv.cn/creator/vodplayer.jsHTTP Parser: var a0_0x51f3=['7G179E7AA7A17G179P7A9','ui_webFullScreen','iPhone','zIndex','hasBarrage','barrageApp
Source: https://pear-02.mfgtcvb.eu.org/HTTP Parser: No favicon
Source: https://pear-02.mfgtcvb.eu.org/HTTP Parser: No favicon
Source: https://pear-02.mfgtcvb.eu.org/HTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlHTTP Parser: No favicon
Source: chromecache_488.5.drString found in binary or memory: http://js.data.cctv.com/__aplus_plugin_cctv.js
Source: chromecache_496.5.drString found in binary or memory: http://js.player.cntv.cn/creator/fingerprint2.js
Source: chromecache_488.5.drString found in binary or memory: http://js.player.cntv.cn/creator/h5.worker?v=220805
Source: chromecache_488.5.drString found in binary or memory: http://js.player.cntv.cn/creator/html5player_analysis_lib.js
Source: chromecache_496.5.drString found in binary or memory: http://js.player.cntv.cn/creator/html5player_standard_multi.js
Source: chromecache_488.5.drString found in binary or memory: http://js.player.cntv.cn/creator/liveplayer_controls.js
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbcdali.v.myalicdn.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbcdbd.a.bdydns.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbcdcnc.v.wscdns.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbcdtxy.liveplay.myqcloud.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbndali.v.myalicdn.com/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbndcnc.v.wscdns.com/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbndhwy.cntv.myhwcdn.cn/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_488.5.drString found in binary or memory: http://ldncctvwbndtxy.liveplay.myqcloud.com/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_290.5.drString found in binary or memory: http://ns.attribution.com/ads/1.0/
Source: chromecache_373.5.drString found in binary or memory: http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-1321.jpg
Source: chromecache_373.5.drString found in binary or memory: http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-2714.jpg
Source: chromecache_373.5.drString found in binary or memory: http://p3.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-10.jpg
Source: chromecache_496.5.drString found in binary or memory: http://vdn.apps.cntv.cn/api/getIpadVideoInfo.do?pid=
Source: chromecache_488.5.drString found in binary or memory: http://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: http://videojs.com/
Source: chromecache_488.5.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntv&android_schema=
Source: chromecache_488.5.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntv&ios_scheme=
Source: chromecache_488.5.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntvhd&ios_scheme=
Source: chromecache_488.5.drString found in binary or memory: https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_html5.json
Source: chromecache_488.5.drString found in binary or memory: https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_pcweb.json
Source: chromecache_488.5.drString found in binary or memory: https://app.cctv.com/special/download/ysyy/index.html
Source: chromecache_511.5.dr, chromecache_254.5.drString found in binary or memory: https://dh5.cntv.cdn20.com/asp/h5e/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/main
Source: chromecache_511.5.dr, chromecache_254.5.drString found in binary or memory: https://dhls.cntv.cdn20.com/asp/audio/f/4/d/4/f4d4981c63ad47ad9b0b436df933de91/mp3/main.m3u8
Source: chromecache_511.5.dr, chromecache_254.5.drString found in binary or memory: https://dhls.cntv.cdn20.com/asp/enc/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/mai
Source: chromecache_511.5.dr, chromecache_254.5.drString found in binary or memory: https://dhls.cntv.cdn20.com/asp/hlsaudio/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de9
Source: chromecache_511.5.dr, chromecache_254.5.drString found in binary or memory: https://dhls2.cntv.cdn20.com/asp/enc2/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/m
Source: chromecache_402.5.drString found in binary or memory: https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: https://github.com/kesla/parse-headers/
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: https://github.com/kesla/parse-headers/blob/master/LICENCE
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: https://github.com/mozilla/vtt.js
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: https://github.com/mozilla/vtt.js/blob/main/LICENSE
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: https://github.com/videojs/video.js/blob/main/LICENSE
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDEBmNj55MqwBh1zF4pCLLL241114.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDEYEC3jiFYBBYGSeCvyCsz241114.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/12/31/VIDESd7oTQcka90G4VTWZgsB241231.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2024/12/31/VIDEqiPmhhV9FJLzLiUxE6FZ241231.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/02/VIDEwNriYCH7XWBz3eXegNRX250102.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/09/VIDEh9LOpZUjo6lhCe7SJGhA250109.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDE5gaAOPgF6mPrOeL41gzZ250117.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDEIZ8r8kbLz4eMEleoItKx250117.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDETJQ1QB1byOLu0uUHgckf250117.shtml
Source: chromecache_373.5.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDEZuR08BtkT2E1FiAYrl00250117.shtml
Source: chromecache_511.5.dr, chromecache_254.5.drString found in binary or memory: https://hls.cntv.cdn20.com/asp/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/main.m3u
Source: chromecache_496.5.dr, chromecache_488.5.drString found in binary or memory: https://js.data.cctv.com/__aplus_plugin_cctv.js
Source: chromecache_496.5.drString found in binary or memory: https://js.player.cntv.cn/creator/fingerprint2.js
Source: chromecache_488.5.drString found in binary or memory: https://js.player.cntv.cn/creator/html5player_analysis_lib.js
Source: chromecache_496.5.drString found in binary or memory: https://js.player.cntv.cn/creator/html5player_standard_multi.js
Source: chromecache_488.5.drString found in binary or memory: https://js.player.cntv.cn/creator/liveplayer_controls.js
Source: chromecache_373.5.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/12/31/ab5059c9774d4df5bdfb117a3b72cb9b-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/02/27a715bcf19340beaef23bc6b00e8269-1.jpg
Source: chromecache_254.5.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-180.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-0.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2025/01/17/563d639fabc34db984be1f62f47a82fc-300.jpg
Source: chromecache_270.5.drString found in binary or memory: https://p2.img.cctvpic.com/photoAlbum/templet/common/TPTERE93VfAfo34uSEe8veca211216/headerDown.png?a
Source: chromecache_270.5.drString found in binary or memory: https://p2.img.cctvpic.com/photoAlbum/templet/common/TPTERE93VfAfo34uSEe8veca211216/headerUp.png?a
Source: chromecache_373.5.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2025/01/02/2025010217230787854.png
Source: chromecache_373.5.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2025/01/17/2025011716100791275.png
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-2.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/09/5b9680548e414bf6a722965bc5ccf053-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/09/5b9680548e414bf6a722965bc5ccf053-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/31/ab5059c9774d4df5bdfb117a3b72cb9b-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/d7cdf59e81e84bf0b368eeef3baa341d-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/02/27a715bcf19340beaef23bc6b00e8269-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-300.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/563d639fabc34db984be1f62f47a82fc-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/d7cdf59e81e84bf0b368eeef3baa341d-1.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/03/2025010316300876860.jpg
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/09/2025010917375892850.png
Source: chromecache_373.5.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/14/2025011415411893350.jpg
Source: chromecache_488.5.drString found in binary or memory: https://player.cntv.cn/html5Player/images/
Source: chromecache_488.5.drString found in binary or memory: https://player.cntv.cn/html5Player/images/20190905/cctvnews_loading.gif
Source: chromecache_488.5.drString found in binary or memory: https://player.cntv.cn/html5Player/images/cctv_html5player_loading.gif
Source: chromecache_564.5.drString found in binary or memory: https://tv.cctv.com/cctv4asia/
Source: chromecache_488.5.drString found in binary or memory: https://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=
Source: chromecache_251.5.dr, chromecache_536.5.drString found in binary or memory: https://www.brightcove.com/
Source: classification engineClassification label: mal52.phis.win@20/539@0/25
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2216 --field-trial-handle=2144,i,8688760562165855632,6171228347105639683,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pear-02.mfgtcvb.eu.org/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5080 --field-trial-handle=2144,i,8688760562165855632,6171228347105639683,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2216 --field-trial-handle=2144,i,8688760562165855632,6171228347105639683,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5080 --field-trial-handle=2144,i,8688760562165855632,6171228347105639683,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://pear-02.mfgtcvb.eu.org/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ldncctvwbndali.v.myalicdn.com/ldncctvwbnd/ldcctv1_2/index.m3u80%Avira URL Cloudsafe
http://ldncctvwbndhwy.cntv.myhwcdn.cn/ldncctvwbnd/ldcctv1_2/index.m3u80%Avira URL Cloudsafe
https://global.cctv.com/2025/01/09/VIDEh9LOpZUjo6lhCe7SJGhA250109.shtml0%Avira URL Cloudsafe
https://dhls.cntv.cdn20.com/asp/enc/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/mai0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/14/VIDEBmNj55MqwBh1zF4pCLLL241114.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/31/VIDEqiPmhhV9FJLzLiUxE6FZ241231.shtml0%Avira URL Cloudsafe
http://ldncctvwbcdcnc.v.wscdns.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u80%Avira URL Cloudsafe
http://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=0%Avira URL Cloudsafe
http://ldncctvwbcdali.v.myalicdn.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u80%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDEZuR08BtkT2E1FiAYrl00250117.shtml0%Avira URL Cloudsafe
https://dhls2.cntv.cdn20.com/asp/enc2/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/m0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/14/VIDEYEC3jiFYBBYGSeCvyCsz241114.shtml0%Avira URL Cloudsafe
http://ldncctvwbcdtxy.liveplay.myqcloud.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u80%Avira URL Cloudsafe
https://dh5.cntv.cdn20.com/asp/h5e/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/main0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDEIZ8r8kbLz4eMEleoItKx250117.shtml0%Avira URL Cloudsafe
https://dhls.cntv.cdn20.com/asp/hlsaudio/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de90%Avira URL Cloudsafe
https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtml0%Avira URL Cloudsafe
https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_pcweb.json0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/02/VIDEwNriYCH7XWBz3eXegNRX250102.shtml0%Avira URL Cloudsafe
https://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDETJQ1QB1byOLu0uUHgckf250117.shtml0%Avira URL Cloudsafe
http://ldncctvwbndtxy.liveplay.myqcloud.com/ldncctvwbnd/ldcctv1_2/index.m3u80%Avira URL Cloudsafe
https://global.cctv.com/2024/12/31/VIDESd7oTQcka90G4VTWZgsB241231.shtml0%Avira URL Cloudsafe
https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_html5.json0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDE5gaAOPgF6mPrOeL41gzZ250117.shtml0%Avira URL Cloudsafe
No contacted domains info
NameMaliciousAntivirus DetectionReputation
https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtmlfalse
    unknown
    https://pear-02.mfgtcvb.eu.org/false
      unknown
      https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtmlfalse
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://js.player.cntv.cn/creator/html5player_analysis_lib.jschromecache_488.5.drfalse
          high
          https://p5.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-1.jpgchromecache_373.5.drfalse
            high
            https://global.cctv.com/2024/11/14/VIDEBmNj55MqwBh1zF4pCLLL241114.shtmlchromecache_373.5.drfalse
            • Avira URL Cloud: safe
            unknown
            http://ldncctvwbcdali.v.myalicdn.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8chromecache_488.5.drfalse
            • Avira URL Cloud: safe
            unknown
            http://p3.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-10.jpgchromecache_373.5.drfalse
              high
              http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-1321.jpgchromecache_373.5.drfalse
                high
                https://global.cctv.com/2024/12/31/VIDEqiPmhhV9FJLzLiUxE6FZ241231.shtmlchromecache_373.5.drfalse
                • Avira URL Cloud: safe
                unknown
                https://p2.img.cctvpic.com/photoAlbum/templet/common/TPTERE93VfAfo34uSEe8veca211216/headerUp.png?achromecache_270.5.drfalse
                  high
                  https://global.cctv.com/2025/01/09/VIDEh9LOpZUjo6lhCe7SJGhA250109.shtmlchromecache_373.5.drfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://ldncctvwbndali.v.myalicdn.com/ldncctvwbnd/ldcctv1_2/index.m3u8chromecache_488.5.drfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://p3.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-1.jpgchromecache_373.5.drfalse
                    high
                    https://p2.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-1.jpgchromecache_373.5.drfalse
                      high
                      http://js.player.cntv.cn/creator/fingerprint2.jschromecache_496.5.drfalse
                        high
                        http://ldncctvwbndhwy.cntv.myhwcdn.cn/ldncctvwbnd/ldcctv1_2/index.m3u8chromecache_488.5.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://p2.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-0.jpgchromecache_373.5.drfalse
                          high
                          http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-2714.jpgchromecache_373.5.drfalse
                            high
                            https://p5.img.cctvpic.com/fmspic/2025/01/17/d7cdf59e81e84bf0b368eeef3baa341d-1.jpgchromecache_373.5.drfalse
                              high
                              http://ns.attribution.com/ads/1.0/chromecache_290.5.drfalse
                                high
                                https://p1.img.cctvpic.com/fmspic/2025/01/02/27a715bcf19340beaef23bc6b00e8269-1.jpgchromecache_373.5.drfalse
                                  high
                                  https://p5.img.cctvpic.com/photoworkspace/2025/01/09/2025010917375892850.pngchromecache_373.5.drfalse
                                    high
                                    http://js.data.cctv.com/__aplus_plugin_cctv.jschromecache_488.5.drfalse
                                      high
                                      https://dhls.cntv.cdn20.com/asp/enc/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/maichromecache_511.5.dr, chromecache_254.5.drfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://p4.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-300.jpgchromecache_373.5.drfalse
                                        high
                                        https://p2.img.cctvpic.com/photoworkspace/2025/01/17/2025011716100791275.pngchromecache_373.5.drfalse
                                          high
                                          http://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=chromecache_488.5.drfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntv&android_schema=chromecache_488.5.drfalse
                                            high
                                            https://app.cctv.com/special/download/ysyy/index.htmlchromecache_488.5.drfalse
                                              high
                                              https://p3.img.cctvpic.com/fmspic/2025/01/09/5b9680548e414bf6a722965bc5ccf053-1.jpgchromecache_373.5.drfalse
                                                high
                                                https://github.com/kesla/parse-headers/chromecache_251.5.dr, chromecache_536.5.drfalse
                                                  high
                                                  https://tv.cctv.com/cctv4asia/chromecache_564.5.drfalse
                                                    high
                                                    https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-180.jpgchromecache_254.5.drfalse
                                                      high
                                                      https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-300.jpgchromecache_373.5.drfalse
                                                        high
                                                        https://player.cntv.cn/html5Player/images/20190905/cctvnews_loading.gifchromecache_488.5.drfalse
                                                          high
                                                          https://p5.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-1.jpgchromecache_373.5.drfalse
                                                            high
                                                            https://global.cctv.com/2025/01/17/VIDEZuR08BtkT2E1FiAYrl00250117.shtmlchromecache_373.5.drfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            http://ldncctvwbcdcnc.v.wscdns.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8chromecache_488.5.drfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            http://ldncctvwbcdtxy.liveplay.myqcloud.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8chromecache_488.5.drfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtmlchromecache_373.5.drfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-1.jpgchromecache_373.5.drfalse
                                                              high
                                                              https://p3.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-1.jpgchromecache_373.5.drfalse
                                                                high
                                                                https://global.cctv.com/2024/11/14/VIDEYEC3jiFYBBYGSeCvyCsz241114.shtmlchromecache_373.5.drfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://p2.img.cctvpic.com/fmspic/2025/01/17/563d639fabc34db984be1f62f47a82fc-300.jpgchromecache_373.5.drfalse
                                                                  high
                                                                  https://global.cctv.com/2025/01/17/VIDEIZ8r8kbLz4eMEleoItKx250117.shtmlchromecache_373.5.drfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://dhls.cntv.cdn20.com/asp/hlsaudio/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de9chromecache_511.5.dr, chromecache_254.5.drfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://js.player.cntv.cn/creator/fingerprint2.jschromecache_496.5.drfalse
                                                                    high
                                                                    https://js.player.cntv.cn/creator/html5player_standard_multi.jschromecache_496.5.drfalse
                                                                      high
                                                                      https://dh5.cntv.cdn20.com/asp/h5e/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/mainchromecache_511.5.dr, chromecache_254.5.drfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      http://js.player.cntv.cn/creator/liveplayer_controls.jschromecache_488.5.drfalse
                                                                        high
                                                                        http://videojs.com/chromecache_251.5.dr, chromecache_536.5.drfalse
                                                                          high
                                                                          https://github.com/videojs/video.js/blob/main/LICENSEchromecache_251.5.dr, chromecache_536.5.drfalse
                                                                            high
                                                                            https://dhls2.cntv.cdn20.com/asp/enc2/hls/main/0303000a/3/default/f4d4981c63ad47ad9b0b436df933de91/mchromecache_511.5.dr, chromecache_254.5.drfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            http://js.player.cntv.cn/creator/html5player_standard_multi.jschromecache_496.5.drfalse
                                                                              high
                                                                              https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtmlchromecache_373.5.drfalse
                                                                              • Avira URL Cloud: safe
                                                                              unknown
                                                                              https://github.com/mozilla/vtt.jschromecache_251.5.dr, chromecache_536.5.drfalse
                                                                                high
                                                                                https://p4.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-1.jpgchromecache_373.5.drfalse
                                                                                  high
                                                                                  https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9chromecache_402.5.drfalse
                                                                                    high
                                                                                    https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtmlchromecache_373.5.drfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    https://p2.img.cctvpic.com/photoAlbum/templet/common/TPTERE93VfAfo34uSEe8veca211216/headerDown.png?achromecache_270.5.drfalse
                                                                                      high
                                                                                      https://www.brightcove.com/chromecache_251.5.dr, chromecache_536.5.drfalse
                                                                                        high
                                                                                        https://p5.img.cctvpic.com/fmspic/2025/01/17/563d639fabc34db984be1f62f47a82fc-1.jpgchromecache_373.5.drfalse
                                                                                          high
                                                                                          https://p5.img.cctvpic.com/photoworkspace/2025/01/14/2025011415411893350.jpgchromecache_373.5.drfalse
                                                                                            high
                                                                                            https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_pcweb.jsonchromecache_488.5.drfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://js.data.cctv.com/__aplus_plugin_cctv.jschromecache_496.5.dr, chromecache_488.5.drfalse
                                                                                              high
                                                                                              https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtmlchromecache_373.5.drfalse
                                                                                              • Avira URL Cloud: safe
                                                                                              unknown
                                                                                              https://p2.img.cctvpic.com/photoworkspace/2025/01/02/2025010217230787854.pngchromecache_373.5.drfalse
                                                                                                high
                                                                                                http://vdn.apps.cntv.cn/api/getIpadVideoInfo.do?pid=chromecache_496.5.drfalse
                                                                                                  high
                                                                                                  https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-300.jpgchromecache_373.5.drfalse
                                                                                                    high
                                                                                                    https://p3.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-1.jpgchromecache_373.5.drfalse
                                                                                                      high
                                                                                                      https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-300.jpgchromecache_373.5.drfalse
                                                                                                        high
                                                                                                        https://player.cntv.cn/html5Player/images/chromecache_488.5.drfalse
                                                                                                          high
                                                                                                          https://player.cntv.cn/html5Player/images/cctv_html5player_loading.gifchromecache_488.5.drfalse
                                                                                                            high
                                                                                                            https://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=chromecache_488.5.drfalse
                                                                                                            • Avira URL Cloud: safe
                                                                                                            unknown
                                                                                                            https://github.com/kesla/parse-headers/blob/master/LICENCEchromecache_251.5.dr, chromecache_536.5.drfalse
                                                                                                              high
                                                                                                              https://js.player.cntv.cn/creator/html5player_analysis_lib.jschromecache_488.5.drfalse
                                                                                                                high
                                                                                                                https://p3.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-300.jpgchromecache_373.5.drfalse
                                                                                                                  high
                                                                                                                  https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntv&ios_scheme=chromecache_488.5.drfalse
                                                                                                                    high
                                                                                                                    https://global.cctv.com/2025/01/02/VIDEwNriYCH7XWBz3eXegNRX250102.shtmlchromecache_373.5.drfalse
                                                                                                                    • Avira URL Cloud: safe
                                                                                                                    unknown
                                                                                                                    https://p5.img.cctvpic.com/photoworkspace/2025/01/03/2025010316300876860.jpgchromecache_373.5.drfalse
                                                                                                                      high
                                                                                                                      https://p1.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-1.jpgchromecache_373.5.drfalse
                                                                                                                        high
                                                                                                                        https://global.cctv.com/2024/12/31/VIDESd7oTQcka90G4VTWZgsB241231.shtmlchromecache_373.5.drfalse
                                                                                                                        • Avira URL Cloud: safe
                                                                                                                        unknown
                                                                                                                        https://p5.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-300.jpgchromecache_373.5.drfalse
                                                                                                                          high
                                                                                                                          https://js.player.cntv.cn/creator/liveplayer_controls.jschromecache_488.5.drfalse
                                                                                                                            high
                                                                                                                            https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-1.jpgchromecache_373.5.drfalse
                                                                                                                              high
                                                                                                                              https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_html5.jsonchromecache_488.5.drfalse
                                                                                                                              • Avira URL Cloud: safe
                                                                                                                              unknown
                                                                                                                              https://global.cctv.com/2025/01/17/VIDETJQ1QB1byOLu0uUHgckf250117.shtmlchromecache_373.5.drfalse
                                                                                                                              • Avira URL Cloud: safe
                                                                                                                              unknown
                                                                                                                              https://p4.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-300.jpgchromecache_373.5.drfalse
                                                                                                                                high
                                                                                                                                https://p4.img.cctvpic.com/fmspic/2025/01/17/d7cdf59e81e84bf0b368eeef3baa341d-300.jpgchromecache_373.5.drfalse
                                                                                                                                  high
                                                                                                                                  https://p1.img.cctvpic.com/fmspic/2024/12/31/ab5059c9774d4df5bdfb117a3b72cb9b-1.jpgchromecache_373.5.drfalse
                                                                                                                                    high
                                                                                                                                    http://ldncctvwbndtxy.liveplay.myqcloud.com/ldncctvwbnd/ldcctv1_2/index.m3u8chromecache_488.5.drfalse
                                                                                                                                    • Avira URL Cloud: safe
                                                                                                                                    unknown
                                                                                                                                    https://github.com/mozilla/vtt.js/blob/main/LICENSEchromecache_251.5.dr, chromecache_536.5.drfalse
                                                                                                                                      high
                                                                                                                                      https://p3.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-2.jpgchromecache_373.5.drfalse
                                                                                                                                        high
                                                                                                                                        https://p4.img.cctvpic.com/fmspic/2024/12/31/ab5059c9774d4df5bdfb117a3b72cb9b-300.jpgchromecache_373.5.drfalse
                                                                                                                                          high
                                                                                                                                          https://p5.img.cctvpic.com/fmspic/2025/01/02/27a715bcf19340beaef23bc6b00e8269-300.jpgchromecache_373.5.drfalse
                                                                                                                                            high
                                                                                                                                            https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntvhd&ios_scheme=chromecache_488.5.drfalse
                                                                                                                                              high
                                                                                                                                              https://p1.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-300.jpgchromecache_373.5.drfalse
                                                                                                                                                high
                                                                                                                                                http://js.player.cntv.cn/creator/h5.worker?v=220805chromecache_488.5.drfalse
                                                                                                                                                  high
                                                                                                                                                  https://global.cctv.com/2025/01/17/VIDE5gaAOPgF6mPrOeL41gzZ250117.shtmlchromecache_373.5.drfalse
                                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                                  unknown
                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                  • 75% < No. of IPs
                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                  163.171.147.15
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                  163.171.132.119
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                  104.21.85.11
                                                                                                                                                  unknownUnited States
                                                                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                                                                  163.171.132.42
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                  163.171.133.124
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                  142.250.185.163
                                                                                                                                                  unknownUnited States
                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                  142.250.186.131
                                                                                                                                                  unknownUnited States
                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                  138.113.147.185
                                                                                                                                                  unknownUnited States
                                                                                                                                                  776FR-INRIA-SOPHIAINRIASophia-AntipolisEUfalse
                                                                                                                                                  163.181.131.244
                                                                                                                                                  unknownUnited States
                                                                                                                                                  24429TAOBAOZhejiangTaobaoNetworkCoLtdCNfalse
                                                                                                                                                  115.182.216.38
                                                                                                                                                  unknownChina
                                                                                                                                                  4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
                                                                                                                                                  95.100.110.17
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                  2.21.65.137
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                  1.1.1.1
                                                                                                                                                  unknownAustralia
                                                                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                                                                  119.3.155.97
                                                                                                                                                  unknownChina
                                                                                                                                                  55990HWCSNETHuaweiCloudServicedatacenterCNfalse
                                                                                                                                                  142.250.185.110
                                                                                                                                                  unknownUnited States
                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                  163.171.130.92
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                  142.250.185.238
                                                                                                                                                  unknownUnited States
                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                  2.21.65.135
                                                                                                                                                  unknownEuropean Union
                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                  142.251.173.84
                                                                                                                                                  unknownUnited States
                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                  172.67.200.176
                                                                                                                                                  unknownUnited States
                                                                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                                                                  111.170.15.114
                                                                                                                                                  unknownChina
                                                                                                                                                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                                                                                                                                  239.255.255.250
                                                                                                                                                  unknownReserved
                                                                                                                                                  unknownunknownfalse
                                                                                                                                                  39.107.0.245
                                                                                                                                                  unknownChina
                                                                                                                                                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                                                                                                                                  142.250.186.164
                                                                                                                                                  unknownUnited States
                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                  IP
                                                                                                                                                  192.168.2.7
                                                                                                                                                  Joe Sandbox version:42.0.0 Malachite
                                                                                                                                                  Analysis ID:1594010
                                                                                                                                                  Start date and time:2025-01-18 00:20:16 +01:00
                                                                                                                                                  Joe Sandbox product:CloudBasic
                                                                                                                                                  Overall analysis duration:0h 4m 17s
                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                  Report type:full
                                                                                                                                                  Cookbook file name:browseurl.jbs
                                                                                                                                                  Sample URL:http://pear-02.mfgtcvb.eu.org/
                                                                                                                                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                  Number of analysed new started processes analysed:16
                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                  Technologies:
                                                                                                                                                  • HCA enabled
                                                                                                                                                  • EGA enabled
                                                                                                                                                  • AMSI enabled
                                                                                                                                                  Analysis Mode:default
                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                  Detection:MAL
                                                                                                                                                  Classification:mal52.phis.win@20/539@0/25
                                                                                                                                                  EGA Information:Failed
                                                                                                                                                  HCA Information:
                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                  • Skipping network analysis since amount of network traffic is too extensive
                                                                                                                                                  • VT rate limit hit for: http://pear-02.mfgtcvb.eu.org/
                                                                                                                                                  No simulations