Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://cf-1.6aenihvs.eu.org/

Overview

General Information

Sample URL:http://cf-1.6aenihvs.eu.org/
Analysis ID:1607933
Infos:

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
HTML page contains obfuscated javascript
Program does not show much activity (idle)

Classification

  • System is w10x64
  • chrome.exe (PID: 4504 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5448 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,13873040142991852159,5074864389846909092,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3592 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6108 --field-trial-handle=1980,i,13873040142991852159,5074864389846909092,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6520 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cf-1.6aenihvs.eu.org/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://cf-1.6aenihvs.eu.org/Avira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: https://js.player.cntv.cn/creator/vodplayer.jsHTTP Parser: var a0_0x51f3=['7G179E7AA7A17G179P7A9','ui_webFullScreen','iPhone','zIndex','hasBarrage','barrageApp
Source: https://cf-1.6aenihvs.eu.org/HTTP Parser: No favicon
Source: https://cf-1.6aenihvs.eu.org/HTTP Parser: No favicon
Source: https://cf-1.6aenihvs.eu.org/HTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: chromecache_480.2.drString found in binary or memory: http://cbox.cntv.cn/epg/ctlist/
Source: chromecache_480.2.drString found in binary or memory: http://js.data.cctv.com/__aplus_plugin_cctv.js
Source: chromecache_508.2.drString found in binary or memory: http://js.player.cntv.cn/creator/fingerprint2.js
Source: chromecache_480.2.drString found in binary or memory: http://js.player.cntv.cn/creator/hlsp2p.js
Source: chromecache_480.2.drString found in binary or memory: http://js.player.cntv.cn/creator/html5player_analysis_lib.js
Source: chromecache_508.2.drString found in binary or memory: http://js.player.cntv.cn/creator/html5player_standard_multi.js
Source: chromecache_480.2.drString found in binary or memory: http://js.player.cntv.cn/creator/liveplayer_controls.js
Source: chromecache_347.2.drString found in binary or memory: http://jsfiddle.net/NDYV8/16/
Source: chromecache_347.2.drString found in binary or memory: http://jsfiddle.net/NDYV8/19/
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbcdali.v.myalicdn.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbcdbd.a.bdydns.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbcdcnc.v.wscdns.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbcdhwy.cntv.myhwcdn.cn/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbcdks.v.kcdnvip.com/ldncctvwbcd/cdrmldcctv1_1/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbndali.v.myalicdn.com/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbndks.v.kcdnvip.com/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_480.2.drString found in binary or memory: http://ldncctvwbndtxy.liveplay.myqcloud.com/ldncctvwbnd/ldcctv1_2/index.m3u8
Source: chromecache_409.2.drString found in binary or memory: http://ns.attribution.com/ads/1.0/
Source: chromecache_508.2.drString found in binary or memory: http://vdn.apps.cntv.cn/api/getIpadVideoInfo.do?pid=
Source: chromecache_534.2.drString found in binary or memory: http://videojs.com/
Source: chromecache_347.2.drString found in binary or memory: http://www.lalit.org/lab/javascript-css-font-detect/
Source: chromecache_347.2.drString found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
Source: chromecache_347.2.drString found in binary or memory: http://www.stucox.com/blog/you-cant-detect-a-touchscreen/
Source: chromecache_480.2.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntv&android_schema=
Source: chromecache_480.2.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntv&ios_scheme=
Source: chromecache_480.2.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntvhd&android_schema=
Source: chromecache_480.2.drString found in binary or memory: https://a.app.qq.com/o/simple.jsp?pkgname=cn.cntvhd&ios_scheme=
Source: chromecache_480.2.drString found in binary or memory: https://api.live.cntv.cn/livestatic/zs/livestatic_config/unity_html5.json
Source: chromecache_480.2.drString found in binary or memory: https://app.cctv.com/special/download/ysyy/index.html
Source: chromecache_347.2.drString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=781447
Source: chromecache_347.2.drString found in binary or memory: https://github.com/Modernizr/Modernizr/blob/master/feature-detects/canvas/winding.js
Source: chromecache_347.2.drString found in binary or memory: https://github.com/Modernizr/Modernizr/issues/548
Source: chromecache_347.2.drString found in binary or memory: https://github.com/Valve/fingerprintjs2
Source: chromecache_347.2.drString found in binary or memory: https://github.com/Valve/fingerprintjs2/issues/66
Source: chromecache_534.2.drString found in binary or memory: https://github.com/kesla/parse-headers/
Source: chromecache_534.2.drString found in binary or memory: https://github.com/kesla/parse-headers/blob/master/LICENCE
Source: chromecache_534.2.drString found in binary or memory: https://github.com/mozilla/vtt.js
Source: chromecache_534.2.drString found in binary or memory: https://github.com/mozilla/vtt.js/blob/main/LICENSE
Source: chromecache_534.2.drString found in binary or memory: https://github.com/videojs/video.js/blob/main/LICENSE
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE00WMMkTMawWEVvRjeFZU241103.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE4XqSquU13fLqXI5SKtjv241103.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE57d1ZMADGjMY4qWDGIyO241103.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE7cTPs5HjXhNm6gsZC2uP241103.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDEP2AJP05wlu9b7g0OukSg241103.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDEWKeerOcVwNSv1EbdTjfo241103.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/07/VIDE69ABse1ynS8TqypFrVJ4241107.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/12/VIDEX2hrwzAbfCEBmt41fZCP241112.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDEBmNj55MqwBh1zF4pCLLL241114.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDENpswoMNdXlF271NVJAxj241114.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDERKeZQdhygtIyHX3PY8bt241114.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDElfQQtIgzzzwOpHw29yh5241114.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/22/VIDEWSB4KwKIPeminssHFtKB241122.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/11/27/VIDE6R8sdOnaoJD4liCwbbAV241127.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/12/03/VIDE3VlPHb0GJ5BFmH6B8wid241203.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/12/10/VIDEnlrIFgWWq1iIcIafDYTj241210.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/12/17/VIDEipwD6cDS7BKqqfLsDlLi241217.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/12/27/VIDEY2rRHuTmjW2AbJdqXaXa241227.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2024/12/31/VIDESd7oTQcka90G4VTWZgsB241231.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/09/VIDEh9LOpZUjo6lhCe7SJGhA250109.shtml
Source: chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDE6KRxOqFYk1XvD6xgMA4D250117.shtml
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2025/01/22/VIDE44vchVcs64COSXEqPRjJ250122.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDESocifs5BGaEld0Ns0T65250127.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDETaz8pHjMo4ElMiRLIpBW250127.shtml
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDEY6pbLQGPgjOK6F0I3bdb250127.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDEhzTVgmmoo3xnpeosudRs250127.shtml
Source: chromecache_487.2.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDEiZGO8GnR4wDbFPUGlN9F250127.shtml
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtml
Source: chromecache_480.2.drString found in binary or memory: https://itunes.apple.com/cn/app/%E5%A4%AE%E8%A7%86%E5%BD%B1%E9%9F%B3hd-%E6%B5%B7%E9%87%8F%E5%A4%AE%E
Source: chromecache_480.2.drString found in binary or memory: https://itunes.apple.com/cn/app/cntv-zhong-guo-wang-luo-dian/id331259725?mt=8
Source: chromecache_480.2.dr, chromecache_508.2.drString found in binary or memory: https://js.data.cctv.com/__aplus_plugin_cctv.js
Source: chromecache_508.2.drString found in binary or memory: https://js.player.cntv.cn/creator/fingerprint2.js
Source: chromecache_480.2.drString found in binary or memory: https://js.player.cntv.cn/creator/h5.worker?v=220805
Source: chromecache_480.2.drString found in binary or memory: https://js.player.cntv.cn/creator/html5player_analysis_lib.js
Source: chromecache_508.2.drString found in binary or memory: https://js.player.cntv.cn/creator/html5player_standard_multi.js
Source: chromecache_480.2.drString found in binary or memory: https://js.player.cntv.cn/creator/liveplayer_controls.js
Source: chromecache_487.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/08/16/d43251451b924aeea4cab8c40473f044-49727049-0.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/11/03/76b7a926be8147cb8ca6022366979a18-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/11/12/35bf524c7a0c4a5dbae59fbe22f3653c-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/11/27/5543c06b05bb4596b9bb8f411aeaa82f-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/27/203ce7c7867d4ac1814bbec34e92d849-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/27/b9c4c8cfa4204c0f982d5501f539597b-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/02/04/f39f74da3ba14825b75a6431b3c79bc4-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p1.img.cctvpic.com/photoworkspace/2024/11/22/2024112210150936333.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p1.img.cctvpic.com/photoworkspace/2025/01/27/2025012717220529870.png
Source: chromecache_487.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-0.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/11/03/571357eb4be947d4ab13181cb7d7558e-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/11/03/f4f91fe8181f4fa98ed230ca7ae49d18-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/11/03/f4f91fe8181f4fa98ed230ca7ae49d18-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/12/17/2cafba71f31a4a30b209d04472fc4b4f-300.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2025/01/22/be19a3ef37a04c8d86b2b4a3c1273578-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2025/01/27/f2e56408ec324fec8e760d5b4e86de32-1.jpg
Source: chromecache_334.2.drString found in binary or memory: https://p2.img.cctvpic.com/photoAlbum/templet/common/TPTERE93VfAfo34uSEe8veca211216/headerDown.png?a
Source: chromecache_334.2.drString found in binary or memory: https://p2.img.cctvpic.com/photoAlbum/templet/common/TPTERE93VfAfo34uSEe8veca211216/headerUp.png?a
Source: chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2024/12/03/2024120314061337900.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2024/12/27/2024122714504016973.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2025/01/17/2025011716100791275.png
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2022/06/07/b6b326d032d642caae6e56046b668892-37918161-2.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-46506577-0.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-46506577-2.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/03/1cb1af9252224be98bd243af4592d594-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/03/1cb1af9252224be98bd243af4592d594-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/03/22f4a69a46e840fc812ac3cc98871ca4-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/07/6c7c887889ce4740bfed02a125f9d37d-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/12/35bf524c7a0c4a5dbae59fbe22f3653c-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/03/9aa26225e7f746ecb26783a5535f4d4f-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/17/2cafba71f31a4a30b209d04472fc4b4f-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/27/4d7c20ef7ed7402087b9dc56fcb5d59e-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/27/4d7c20ef7ed7402087b9dc56fcb5d59e-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/09/5b9680548e414bf6a722965bc5ccf053-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/09/5b9680548e414bf6a722965bc5ccf053-300.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/22/be19a3ef37a04c8d86b2b4a3c1273578-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/27/203ce7c7867d4ac1814bbec34e92d849-1.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/27/81b6d8a1bcb544b7a503630e8acebf42-1.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/27/81b6d8a1bcb544b7a503630e8acebf42-300.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/02/04/f39f74da3ba14825b75a6431b3c79bc4-300.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p3.img.cctvpic.com/photoworkspace/2025/01/27/2025012714583875799.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-36082649-2.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/08/16/d43251451b924aeea4cab8c40473f044-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/08/16/d43251451b924aeea4cab8c40473f044-49727049-2.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/11/03/22f4a69a46e840fc812ac3cc98871ca4-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/11/03/76b7a926be8147cb8ca6022366979a18-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/11/27/5543c06b05bb4596b9bb8f411aeaa82f-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/10/b96e596d1a46421585833f943386f1b4-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/10/b96e596d1a46421585833f943386f1b4-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/82edbd2f9ee048f2b4e3e582302c630c-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/27/44d682753d8c41e8b92be983afc03d53-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/27/44d682753d8c41e8b92be983afc03d53-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/27/b9c4c8cfa4204c0f982d5501f539597b-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/27/f2e56408ec324fec8e760d5b4e86de32-300.jpg
Source: chromecache_487.2.dr, chromecache_476.2.drString found in binary or memory: https://p4.img.cctvpic.com/photoworkspace/2025/01/22/2025012211055516232.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-36082649-0.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/03/0324a65ff83e470ab93d76c97b1b6108-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/03/0324a65ff83e470ab93d76c97b1b6108-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/03/571357eb4be947d4ab13181cb7d7558e-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/07/6c7c887889ce4740bfed02a125f9d37d-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/03/9aa26225e7f746ecb26783a5535f4d4f-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-300.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-1.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-300.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/82edbd2f9ee048f2b4e3e582302c630c-1.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2024/11/07/2024110711142612707.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2024/11/13/2024111311252714720.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2024/11/27/2024112715090749784.jpg
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/03/2025010316300876860.jpg
Source: chromecache_487.2.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/09/2025010917375892850.png
Source: chromecache_476.2.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/14/2025011415411893350.jpg
Source: chromecache_480.2.drString found in binary or memory: https://player.cntv.cn/html5Player/images/
Source: chromecache_480.2.drString found in binary or memory: https://player.cntv.cn/html5Player/images/20190905/cctvnews_loading.gif
Source: chromecache_480.2.drString found in binary or memory: https://player.cntv.cn/html5Player/images/cctv_html5player_loading.gif
Source: chromecache_552.2.drString found in binary or memory: https://tv.cctv.com/cctv4asia/
Source: chromecache_480.2.drString found in binary or memory: https://vdnad.apps.cntv.cn/api/getIpadInfoAd.do?pid=
Source: chromecache_534.2.drString found in binary or memory: https://www.brightcove.com/
Source: chromecache_347.2.drString found in binary or memory: https://www.browserleaks.com/canvas#how-does-it-work
Source: classification engineClassification label: mal52.phis.win@20/553@0/29
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,13873040142991852159,5074864389846909092,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://cf-1.6aenihvs.eu.org/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6108 --field-trial-handle=1980,i,13873040142991852159,5074864389846909092,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,13873040142991852159,5074864389846909092,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6108 --field-trial-handle=1980,i,13873040142991852159,5074864389846909092,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.