Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://888.mixly.us.kg/

Overview

General Information

Sample URL:http://888.mixly.us.kg/
Analysis ID:1608870
Infos:

Detection

Score:52
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
HTML page contains obfuscated javascript
Program does not show much activity (idle)

Classification

  • System is w10x64
  • chrome.exe (PID: 1416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 6404 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2236,i,5013916874469833490,17558059062716982547,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 1092 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4416 --field-trial-handle=2236,i,5013916874469833490,17558059062716982547,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 6620 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://888.mixly.us.kg/" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://888.mixly.us.kg/Avira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: https://js.player.cntv.cn/creator/vodplayer.jsHTTP Parser: var a0_0x51f3=['7G179E7AA7A17G179P7A9','ui_webFullScreen','iPhone','zIndex','hasBarrage','barrageApp
Source: https://888.mixly.us.kg/HTTP Parser: No favicon
Source: https://888.mixly.us.kg/HTTP Parser: No favicon
Source: https://888.mixly.us.kg/HTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/06/VIDE4NnTbvNJwk77JqSWZTlH250206.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/06/VIDE4NnTbvNJwk77JqSWZTlH250206.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/06/VIDE4NnTbvNJwk77JqSWZTlH250206.shtmlHTTP Parser: No favicon
Source: https://global.cctv.com/2025/02/06/VIDE4NnTbvNJwk77JqSWZTlH250206.shtmlHTTP Parser: No favicon
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: http://jsfiddle.net/NDYV8/16/
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: http://jsfiddle.net/NDYV8/19/
Source: chromecache_413.3.dr, chromecache_358.3.drString found in binary or memory: http://ns.attribution.com/ads/1.0/
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-1321.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-2714.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: http://p3.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-10.jpg
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: http://videojs.com/
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: http://www.lalit.org/lab/javascript-css-font-detect/
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: http://www.stucox.com/blog/you-cant-detect-a-touchscreen/
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=781447
Source: chromecache_578.3.dr, chromecache_551.3.drString found in binary or memory: https://dh5.cntv.cdn20.com/asp/h5e/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac29/main
Source: chromecache_578.3.dr, chromecache_551.3.drString found in binary or memory: https://dhls.cntv.cdn20.com/asp/audio/5/d/6/0/5d60cdb5cdcd40af8c46095a5ffcac29/mp3/main.m3u8
Source: chromecache_578.3.dr, chromecache_551.3.drString found in binary or memory: https://dhls.cntv.cdn20.com/asp/enc/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac29/mai
Source: chromecache_578.3.dr, chromecache_551.3.drString found in binary or memory: https://dhls.cntv.cdn20.com/asp/hlsaudio/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac2
Source: chromecache_578.3.dr, chromecache_551.3.drString found in binary or memory: https://dhls2.cntv.cdn20.com/asp/enc2/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac29/m
Source: chromecache_391.3.drString found in binary or memory: https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: https://github.com/Modernizr/Modernizr/blob/master/feature-detects/canvas/winding.js
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: https://github.com/Modernizr/Modernizr/issues/548
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: https://github.com/Valve/fingerprintjs2
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: https://github.com/Valve/fingerprintjs2/issues/66
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: https://github.com/kesla/parse-headers/
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: https://github.com/kesla/parse-headers/blob/master/LICENCE
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: https://github.com/mozilla/vtt.js
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: https://github.com/mozilla/vtt.js/blob/main/LICENSE
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: https://github.com/videojs/video.js/blob/main/LICENSE
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE00WMMkTMawWEVvRjeFZU241103.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE57d1ZMADGjMY4qWDGIyO241103.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDE7cTPs5HjXhNm6gsZC2uP241103.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDEP2AJP05wlu9b7g0OukSg241103.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/03/VIDEWKeerOcVwNSv1EbdTjfo241103.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/07/VIDE69ABse1ynS8TqypFrVJ4241107.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/12/VIDEX2hrwzAbfCEBmt41fZCP241112.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDERKeZQdhygtIyHX3PY8bt241114.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDEYEC3jiFYBBYGSeCvyCsz241114.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2024/11/14/VIDElfQQtIgzzzwOpHw29yh5241114.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/22/VIDEWSB4KwKIPeminssHFtKB241122.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/11/27/VIDE6R8sdOnaoJD4liCwbbAV241127.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/12/03/VIDE3VlPHb0GJ5BFmH6B8wid241203.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/12/10/VIDEnlrIFgWWq1iIcIafDYTj241210.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/12/17/VIDEipwD6cDS7BKqqfLsDlLi241217.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/12/27/VIDEY2rRHuTmjW2AbJdqXaXa241227.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2024/12/31/VIDESd7oTQcka90G4VTWZgsB241231.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2025/01/07/VIDEkEw5xA8clKYmw6eON0OG250107.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDE6KRxOqFYk1XvD6xgMA4D250117.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDETJQ1QB1byOLu0uUHgckf250117.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/17/VIDEZuR08BtkT2E1FiAYrl00250117.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/21/VIDEYsMj0ldiQrXFAaKvoWCU250121.shtml
Source: chromecache_474.3.drString found in binary or memory: https://global.cctv.com/2025/01/22/VIDE44vchVcs64COSXEqPRjJ250122.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDETaz8pHjMo4ElMiRLIpBW250127.shtml
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDEY6pbLQGPgjOK6F0I3bdb250127.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/01/27/VIDEhzTVgmmoo3xnpeosudRs250127.shtml
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtml
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/02/06/VIDE4NnTbvNJwk77JqSWZTlH250206.shtml
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://global.cctv.com/2025/02/06/VIDEMUqmqt1U3q19yeOMQpXp250206.shtml
Source: chromecache_578.3.dr, chromecache_551.3.drString found in binary or memory: https://hls.cntv.cdn20.com/asp/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac29/main.m3u
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2023/01/17/2a6d1ccc3852408392ff08706460e48e-41287973-2.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/11/03/76b7a926be8147cb8ca6022366979a18-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/11/12/35bf524c7a0c4a5dbae59fbe22f3653c-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/11/27/5543c06b05bb4596b9bb8f411aeaa82f-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/01/27/203ce7c7867d4ac1814bbec34e92d849-300.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p1.img.cctvpic.com/fmspic/2025/02/04/f39f74da3ba14825b75a6431b3c79bc4-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p1.img.cctvpic.com/photoworkspace/2024/11/22/2024112210150936333.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p1.img.cctvpic.com/photoworkspace/2025/01/27/2025012717220529870.png
Source: chromecache_474.3.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/11/03/571357eb4be947d4ab13181cb7d7558e-300.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2024/12/17/2cafba71f31a4a30b209d04472fc4b4f-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2025/01/22/be19a3ef37a04c8d86b2b4a3c1273578-1.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p2.img.cctvpic.com/fmspic/2025/02/06/54e50efbfd3941c997327042b2a326c0-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2024/12/03/2024120314061337900.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2024/12/27/2024122714504016973.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p2.img.cctvpic.com/photoworkspace/2025/01/17/2025011716100791275.png
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-46506577-0.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-46506577-2.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/03/1cb1af9252224be98bd243af4592d594-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/03/1cb1af9252224be98bd243af4592d594-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/03/22f4a69a46e840fc812ac3cc98871ca4-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/07/6c7c887889ce4740bfed02a125f9d37d-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/11/12/35bf524c7a0c4a5dbae59fbe22f3653c-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/03/9aa26225e7f746ecb26783a5535f4d4f-1.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-1.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/17/2cafba71f31a4a30b209d04472fc4b4f-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/27/4d7c20ef7ed7402087b9dc56fcb5d59e-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/27/4d7c20ef7ed7402087b9dc56fcb5d59e-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-300.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/22/be19a3ef37a04c8d86b2b4a3c1273578-300.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/27/203ce7c7867d4ac1814bbec34e92d849-1.jpg
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/27/81b6d8a1bcb544b7a503630e8acebf42-1.jpg
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/01/27/81b6d8a1bcb544b7a503630e8acebf42-300.jpg
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/fmspic/2025/02/04/f39f74da3ba14825b75a6431b3c79bc4-300.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/photoworkspace/2025/01/21/2025012117463081616.png
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/photoworkspace/2025/01/27/2025012714583875799.jpg
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p3.img.cctvpic.com/photoworkspace/2025/02/06/2025020613581254371.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-36082649-2.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2023/01/17/2a6d1ccc3852408392ff08706460e48e-41287973-0.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/11/03/22f4a69a46e840fc812ac3cc98871ca4-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/11/03/76b7a926be8147cb8ca6022366979a18-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/11/27/5543c06b05bb4596b9bb8f411aeaa82f-300.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/10/b96e596d1a46421585833f943386f1b4-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2024/12/10/b96e596d1a46421585833f943386f1b4-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/14/1bba66b961e246d3b9baeaf3a166164f-300.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-300.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/82edbd2f9ee048f2b4e3e582302c630c-300.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-1.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/27/44d682753d8c41e8b92be983afc03d53-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/01/27/44d682753d8c41e8b92be983afc03d53-300.jpg
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/fmspic/2025/02/06/5d60cdb5cdcd40af8c46095a5ffcac29-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p4.img.cctvpic.com/photoworkspace/2025/01/22/2025012211055516232.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p4.img.cctvpic.com/photoworkspace/2025/02/06/2025020617085244836.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-36082649-0.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/03/0324a65ff83e470ab93d76c97b1b6108-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/03/0324a65ff83e470ab93d76c97b1b6108-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/03/571357eb4be947d4ab13181cb7d7558e-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/11/07/6c7c887889ce4740bfed02a125f9d37d-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/03/9aa26225e7f746ecb26783a5535f4d4f-300.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-1.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-1.jpg
Source: chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-300.jpg
Source: chromecache_392.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/01/17/82edbd2f9ee048f2b4e3e582302c630c-1.jpg
Source: chromecache_551.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/02/06/5d60cdb5cdcd40af8c46095a5ffcac29-180.jpg
Source: chromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drString found in binary or memory: https://p5.img.cctvpic.com/fmspic/2025/02/06/5d60cdb5cdcd40af8c46095a5ffcac29-300.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2024/11/07/2024110711142612707.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2024/11/13/2024111311252714720.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2024/11/27/2024112715090749784.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/03/2025010316300876860.jpg
Source: chromecache_474.3.drString found in binary or memory: https://p5.img.cctvpic.com/photoworkspace/2025/01/14/2025011415411893350.jpg
Source: chromecache_464.3.drString found in binary or memory: https://tv.cctv.com/cctv4asia/
Source: chromecache_258.3.dr, chromecache_527.3.drString found in binary or memory: https://www.brightcove.com/
Source: chromecache_479.3.dr, chromecache_354.3.drString found in binary or memory: https://www.browserleaks.com/canvas#how-does-it-work
Source: classification engineClassification label: mal52.phis.win@20/546@0/30
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2236,i,5013916874469833490,17558059062716982547,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://888.mixly.us.kg/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4416 --field-trial-handle=2236,i,5013916874469833490,17558059062716982547,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2236,i,5013916874469833490,17558059062716982547,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4416 --field-trial-handle=2236,i,5013916874469833490,17558059062716982547,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://888.mixly.us.kg/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://global.cctv.com/2024/12/17/VIDEipwD6cDS7BKqqfLsDlLi241217.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtml0%Avira URL Cloudsafe
https://dhls.cntv.cdn20.com/asp/hlsaudio/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac20%Avira URL Cloudsafe
https://global.cctv.com/2024/11/14/VIDElfQQtIgzzzwOpHw29yh5241114.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDEZuR08BtkT2E1FiAYrl00250117.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/03/VIDEP2AJP05wlu9b7g0OukSg241103.shtml0%Avira URL Cloudsafe
https://dhls2.cntv.cdn20.com/asp/enc2/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac29/m0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/14/VIDEYEC3jiFYBBYGSeCvyCsz241114.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/12/VIDEX2hrwzAbfCEBmt41fZCP241112.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/27/VIDETaz8pHjMo4ElMiRLIpBW250127.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/03/VIDE7cTPs5HjXhNm6gsZC2uP241103.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/17/VIDE6KRxOqFYk1XvD6xgMA4D250117.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/03/VIDEWKeerOcVwNSv1EbdTjfo241103.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/03/VIDE3VlPHb0GJ5BFmH6B8wid241203.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/12/10/VIDEnlrIFgWWq1iIcIafDYTj241210.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2024/11/03/VIDE57d1ZMADGjMY4qWDGIyO241103.shtml0%Avira URL Cloudsafe
https://global.cctv.com/2025/01/27/VIDEY6pbLQGPgjOK6F0I3bdb250127.shtml0%Avira URL Cloudsafe
No contacted domains info
NameMaliciousAntivirus DetectionReputation
https://global.cctv.com/2025/02/04/VIDEybiYWadtnrWnvvCyjGsI250204.shtmlfalse
    unknown
    https://888.mixly.us.kg/false
      unknown
      https://global.cctv.com/2025/02/06/VIDE4NnTbvNJwk77JqSWZTlH250206.shtmlfalse
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        https://p5.img.cctvpic.com/fmspic/2024/12/31/66b031436eb54a248a76dd64408cc6ea-1.jpgchromecache_474.3.drfalse
          high
          https://dhls.cntv.cdn20.com/asp/hlsaudio/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac2chromecache_578.3.dr, chromecache_551.3.drfalse
          • Avira URL Cloud: safe
          unknown
          https://p4.img.cctvpic.com/fmspic/2024/11/27/5543c06b05bb4596b9bb8f411aeaa82f-300.jpgchromecache_474.3.drfalse
            high
            http://p3.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-10.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
              high
              https://p1.img.cctvpic.com/fmspic/2024/11/03/76b7a926be8147cb8ca6022366979a18-300.jpgchromecache_474.3.drfalse
                high
                https://p1.img.cctvpic.com/fmspic/2025/01/27/203ce7c7867d4ac1814bbec34e92d849-300.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                  high
                  https://p3.img.cctvpic.com/fmspic/2024/12/27/4d7c20ef7ed7402087b9dc56fcb5d59e-1.jpgchromecache_474.3.drfalse
                    high
                    https://p2.img.cctvpic.com/fmspic/2024/12/17/2cafba71f31a4a30b209d04472fc4b4f-300.jpgchromecache_474.3.drfalse
                      high
                      http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-1321.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                        high
                        https://bugzilla.mozilla.org/show_bug.cgi?id=781447chromecache_479.3.dr, chromecache_354.3.drfalse
                          high
                          https://p3.img.cctvpic.com/fmspic/2025/01/22/be19a3ef37a04c8d86b2b4a3c1273578-300.jpgchromecache_474.3.drfalse
                            high
                            https://p3.img.cctvpic.com/fmspic/2024/12/06/a5bf28aeeacb4a03840f7ec928314db2-1.jpgchromecache_392.3.drfalse
                              high
                              http://jsfiddle.net/NDYV8/16/chromecache_479.3.dr, chromecache_354.3.drfalse
                                high
                                https://p3.img.cctvpic.com/fmspic/2024/11/12/35bf524c7a0c4a5dbae59fbe22f3653c-300.jpgchromecache_474.3.drfalse
                                  high
                                  https://p2.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-1.jpgchromecache_392.3.drfalse
                                    high
                                    https://dhls2.cntv.cdn20.com/asp/enc2/hls/main/0303000a/3/default/5d60cdb5cdcd40af8c46095a5ffcac29/mchromecache_578.3.dr, chromecache_551.3.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://p3.img.cctvpic.com/fmspic/2025/01/27/81b6d8a1bcb544b7a503630e8acebf42-1.jpgchromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drfalse
                                      high
                                      https://p2.img.cctvpic.com/fmspic/2025/02/06/54e50efbfd3941c997327042b2a326c0-1.jpgchromecache_392.3.drfalse
                                        high
                                        http://p2.img.cctvpic.com/fmspic/2015/04/21/3c54a67ca29244bf940716d57d3b4cd3-2714.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                          high
                                          http://ns.attribution.com/ads/1.0/chromecache_413.3.dr, chromecache_358.3.drfalse
                                            high
                                            https://p5.img.cctvpic.com/fmspic/2024/11/03/571357eb4be947d4ab13181cb7d7558e-1.jpgchromecache_474.3.drfalse
                                              high
                                              https://p4.img.cctvpic.com/fmspic/2024/12/06/a70f6aa0f7ff44f996febb1b4a7bd85f-300.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                high
                                                https://global.cctv.com/2024/12/17/VIDEipwD6cDS7BKqqfLsDlLi241217.shtmlchromecache_474.3.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://p2.img.cctvpic.com/photoworkspace/2025/01/17/2025011716100791275.pngchromecache_388.3.dr, chromecache_392.3.drfalse
                                                  high
                                                  https://p5.img.cctvpic.com/fmspic/2025/01/17/82edbd2f9ee048f2b4e3e582302c630c-1.jpgchromecache_392.3.drfalse
                                                    high
                                                    http://www.stucox.com/blog/you-cant-detect-a-touchscreen/chromecache_479.3.dr, chromecache_354.3.drfalse
                                                      high
                                                      https://p5.img.cctvpic.com/fmspic/2025/02/06/5d60cdb5cdcd40af8c46095a5ffcac29-180.jpgchromecache_551.3.drfalse
                                                        high
                                                        http://jsfiddle.net/NDYV8/19/chromecache_479.3.dr, chromecache_354.3.drfalse
                                                          high
                                                          https://p5.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-36082649-0.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                            high
                                                            https://p4.img.cctvpic.com/fmspic/2025/01/17/82edbd2f9ee048f2b4e3e582302c630c-300.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                              high
                                                              https://github.com/kesla/parse-headers/chromecache_258.3.dr, chromecache_527.3.drfalse
                                                                high
                                                                https://tv.cctv.com/cctv4asia/chromecache_464.3.drfalse
                                                                  high
                                                                  https://p5.img.cctvpic.com/fmspic/2025/01/17/0692dae40c5240cdb45cab03a78bb4b5-300.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                    high
                                                                    https://p5.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-1.jpgchromecache_474.3.drfalse
                                                                      high
                                                                      https://global.cctv.com/2025/01/17/VIDEZuR08BtkT2E1FiAYrl00250117.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://global.cctv.com/2024/11/14/VIDElfQQtIgzzzwOpHw29yh5241114.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://global.cctv.com/2024/12/06/VIDEQL44pOaZa5DwRnaWJZWK241206.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://p5.img.cctvpic.com/fmspic/2024/11/03/0324a65ff83e470ab93d76c97b1b6108-300.jpgchromecache_474.3.drfalse
                                                                        high
                                                                        https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-1.jpgchromecache_392.3.drfalse
                                                                          high
                                                                          https://p4.img.cctvpic.com/photoworkspace/2025/01/22/2025012211055516232.jpgchromecache_474.3.drfalse
                                                                            high
                                                                            https://global.cctv.com/2024/11/14/VIDEYEC3jiFYBBYGSeCvyCsz241114.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://global.cctv.com/2024/11/03/VIDEP2AJP05wlu9b7g0OukSg241103.shtmlchromecache_474.3.drfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://p3.img.cctvpic.com/fmspic/2024/11/07/6c7c887889ce4740bfed02a125f9d37d-300.jpgchromecache_474.3.drfalse
                                                                              high
                                                                              https://global.cctv.com/2024/11/12/VIDEX2hrwzAbfCEBmt41fZCP241112.shtmlchromecache_474.3.drfalse
                                                                              • Avira URL Cloud: safe
                                                                              unknown
                                                                              https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-46506577-0.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                high
                                                                                https://p5.img.cctvpic.com/fmspic/2025/02/06/5d60cdb5cdcd40af8c46095a5ffcac29-300.jpgchromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                  high
                                                                                  http://www.opensource.org/licenses/mit-license.php)chromecache_479.3.dr, chromecache_354.3.drfalse
                                                                                    high
                                                                                    http://videojs.com/chromecache_258.3.dr, chromecache_527.3.drfalse
                                                                                      high
                                                                                      https://github.com/videojs/video.js/blob/main/LICENSEchromecache_258.3.dr, chromecache_527.3.drfalse
                                                                                        high
                                                                                        https://p3.img.cctvpic.com/fmspic/2024/11/03/22f4a69a46e840fc812ac3cc98871ca4-1.jpgchromecache_474.3.drfalse
                                                                                          high
                                                                                          https://p3.img.cctvpic.com/fmspic/2024/12/27/4d7c20ef7ed7402087b9dc56fcb5d59e-300.jpgchromecache_474.3.drfalse
                                                                                            high
                                                                                            https://p3.img.cctvpic.com/photoworkspace/2025/01/21/2025012117463081616.pngchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                              high
                                                                                              https://global.cctv.com/2025/01/17/VIDE2ZAnd1zluFZdshrPRUU6250117.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                              • Avira URL Cloud: safe
                                                                                              unknown
                                                                                              https://p4.img.cctvpic.com/fmspic/2024/11/03/22f4a69a46e840fc812ac3cc98871ca4-300.jpgchromecache_474.3.drfalse
                                                                                                high
                                                                                                https://github.com/mozilla/vtt.jschromecache_258.3.dr, chromecache_527.3.drfalse
                                                                                                  high
                                                                                                  https://global.cctv.com/2024/11/03/VIDE7cTPs5HjXhNm6gsZC2uP241103.shtmlchromecache_474.3.drfalse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  https://global.cctv.com/2025/01/17/VIDE6KRxOqFYk1XvD6xgMA4D250117.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  https://p3.img.cctvpic.com/fmspic/2025/01/27/81b6d8a1bcb544b7a503630e8acebf42-300.jpgchromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                    high
                                                                                                    https://p4.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-1.jpgchromecache_392.3.drfalse
                                                                                                      high
                                                                                                      https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9chromecache_391.3.drfalse
                                                                                                        high
                                                                                                        https://github.com/Modernizr/Modernizr/blob/master/feature-detects/canvas/winding.jschromecache_479.3.dr, chromecache_354.3.drfalse
                                                                                                          high
                                                                                                          https://global.cctv.com/2024/12/06/VIDE43PMmdH3ky44ODjXy0k5241206.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          https://p5.img.cctvpic.com/fmspic/2024/12/03/9aa26225e7f746ecb26783a5535f4d4f-300.jpgchromecache_474.3.drfalse
                                                                                                            high
                                                                                                            https://p1.img.cctvpic.com/fmspic/2025/02/04/f39f74da3ba14825b75a6431b3c79bc4-1.jpgchromecache_392.3.drfalse
                                                                                                              high
                                                                                                              https://p5.img.cctvpic.com/photoworkspace/2024/11/27/2024112715090749784.jpgchromecache_474.3.drfalse
                                                                                                                high
                                                                                                                https://www.brightcove.com/chromecache_258.3.dr, chromecache_527.3.drfalse
                                                                                                                  high
                                                                                                                  https://global.cctv.com/2025/01/14/VIDEQHPeuQn9iGmZk4ZLpfch250114.shtmlchromecache_474.3.drfalse
                                                                                                                    high
                                                                                                                    https://p4.img.cctvpic.com/fmspic/2024/12/10/b96e596d1a46421585833f943386f1b4-1.jpgchromecache_474.3.drfalse
                                                                                                                      high
                                                                                                                      https://p5.img.cctvpic.com/photoworkspace/2025/01/14/2025011415411893350.jpgchromecache_474.3.drfalse
                                                                                                                        high
                                                                                                                        https://p1.img.cctvpic.com/photoworkspace/2025/01/27/2025012717220529870.pngchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                          high
                                                                                                                          https://global.cctv.com/2024/11/03/VIDEWKeerOcVwNSv1EbdTjfo241103.shtmlchromecache_474.3.drfalse
                                                                                                                          • Avira URL Cloud: safe
                                                                                                                          unknown
                                                                                                                          https://p3.img.cctvpic.com/fmspic/2023/11/13/830615d74a2147e6a8a093ea74568003-46506577-2.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                            high
                                                                                                                            https://global.cctv.com/2025/01/27/VIDETaz8pHjMo4ElMiRLIpBW250127.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                            • Avira URL Cloud: safe
                                                                                                                            unknown
                                                                                                                            https://global.cctv.com/2024/12/04/VIDE3SuMJLq97GA7XRe3ztIl241204.shtmlchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                            • Avira URL Cloud: safe
                                                                                                                            unknown
                                                                                                                            https://p1.img.cctvpic.com/fmspic/2023/01/17/2a6d1ccc3852408392ff08706460e48e-41287973-2.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                              high
                                                                                                                              https://p1.img.cctvpic.com/fmspic/2024/11/27/5543c06b05bb4596b9bb8f411aeaa82f-1.jpgchromecache_474.3.drfalse
                                                                                                                                high
                                                                                                                                https://p1.img.cctvpic.com/fmspic/2025/01/07/f4d4981c63ad47ad9b0b436df933de91-300.jpgchromecache_474.3.drfalse
                                                                                                                                  high
                                                                                                                                  https://p3.img.cctvpic.com/fmspic/2024/12/04/3974a1337c0844e9b691520072659264-1.jpgchromecache_392.3.drfalse
                                                                                                                                    high
                                                                                                                                    https://p4.img.cctvpic.com/photoworkspace/2025/02/06/2025020617085244836.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                      high
                                                                                                                                      https://p4.img.cctvpic.com/fmspic/2025/01/17/5b745e2639fb452da06d91712d7207a1-300.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                        high
                                                                                                                                        https://p3.img.cctvpic.com/fmspic/2025/01/27/203ce7c7867d4ac1814bbec34e92d849-1.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                          high
                                                                                                                                          https://p5.img.cctvpic.com/fmspic/2024/11/07/6c7c887889ce4740bfed02a125f9d37d-1.jpgchromecache_474.3.drfalse
                                                                                                                                            high
                                                                                                                                            https://global.cctv.com/2024/11/03/VIDE57d1ZMADGjMY4qWDGIyO241103.shtmlchromecache_474.3.drfalse
                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                            unknown
                                                                                                                                            https://github.com/kesla/parse-headers/blob/master/LICENCEchromecache_258.3.dr, chromecache_527.3.drfalse
                                                                                                                                              high
                                                                                                                                              https://p3.img.cctvpic.com/fmspic/2024/11/03/1cb1af9252224be98bd243af4592d594-300.jpgchromecache_474.3.drfalse
                                                                                                                                                high
                                                                                                                                                https://p4.img.cctvpic.com/fmspic/2022/02/01/188b2481e7ff471aa7bf75c81bf218da-36082649-2.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                                  high
                                                                                                                                                  http://www.lalit.org/lab/javascript-css-font-detect/chromecache_479.3.dr, chromecache_354.3.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://p5.img.cctvpic.com/photoworkspace/2024/11/13/2024111311252714720.jpgchromecache_474.3.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://p3.img.cctvpic.com/fmspic/2025/01/17/98eec5744f634da69d19b50596a79b1a-300.jpgchromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://p3.img.cctvpic.com/fmspic/2024/12/03/9aa26225e7f746ecb26783a5535f4d4f-1.jpgchromecache_474.3.drfalse
                                                                                                                                                          high
                                                                                                                                                          https://github.com/Valve/fingerprintjs2/issues/66chromecache_479.3.dr, chromecache_354.3.drfalse
                                                                                                                                                            high
                                                                                                                                                            https://global.cctv.com/2024/12/10/VIDEnlrIFgWWq1iIcIafDYTj241210.shtmlchromecache_474.3.drfalse
                                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                                            unknown
                                                                                                                                                            https://global.cctv.com/2025/01/27/VIDEY6pbLQGPgjOK6F0I3bdb250127.shtmlchromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                                            unknown
                                                                                                                                                            https://p3.img.cctvpic.com/photoworkspace/2025/01/27/2025012714583875799.jpgchromecache_474.3.dr, chromecache_388.3.dr, chromecache_392.3.drfalse
                                                                                                                                                              high
                                                                                                                                                              https://p5.img.cctvpic.com/photoworkspace/2025/01/03/2025010316300876860.jpgchromecache_474.3.drfalse
                                                                                                                                                                high
                                                                                                                                                                https://global.cctv.com/2024/12/03/VIDE3VlPHb0GJ5BFmH6B8wid241203.shtmlchromecache_474.3.drfalse
                                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                                unknown
                                                                                                                                                                https://p4.img.cctvpic.com/fmspic/2024/11/03/76b7a926be8147cb8ca6022366979a18-1.jpgchromecache_474.3.drfalse
                                                                                                                                                                  high
                                                                                                                                                                  • No. of IPs < 25%
                                                                                                                                                                  • 25% < No. of IPs < 50%
                                                                                                                                                                  • 50% < No. of IPs < 75%
                                                                                                                                                                  • 75% < No. of IPs
                                                                                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                  104.21.48.1
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                                                                                  163.171.147.15
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                                  163.171.132.119
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                                  142.250.186.67
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                                  138.113.27.66
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  776FR-INRIA-SOPHIAINRIASophia-AntipolisEUfalse
                                                                                                                                                                  163.171.132.42
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                                  59.37.89.184
                                                                                                                                                                  unknownChina
                                                                                                                                                                  134764CT-FOSHAN-IDCCHINANETGuangdongprovincenetworkCNfalse
                                                                                                                                                                  172.217.23.110
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                                  163.181.92.250
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  24429TAOBAOZhejiangTaobaoNetworkCoLtdCNfalse
                                                                                                                                                                  39.107.0.195
                                                                                                                                                                  unknownChina
                                                                                                                                                                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                                                                                                                                                  104.115.82.10
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                                  104.115.82.16
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                                  163.181.131.243
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  24429TAOBAOZhejiangTaobaoNetworkCoLtdCNfalse
                                                                                                                                                                  163.181.131.244
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  24429TAOBAOZhejiangTaobaoNetworkCoLtdCNfalse
                                                                                                                                                                  138.113.147.185
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  776FR-INRIA-SOPHIAINRIASophia-AntipolisEUfalse
                                                                                                                                                                  115.182.216.38
                                                                                                                                                                  unknownChina
                                                                                                                                                                  4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
                                                                                                                                                                  2.21.65.137
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                                  1.1.1.1
                                                                                                                                                                  unknownAustralia
                                                                                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                                                                                  163.171.128.148
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                                  108.177.15.84
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                                  104.21.32.1
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                                                                                  163.171.130.92
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  54994QUANTILNETWORKSUSfalse
                                                                                                                                                                  2.21.65.135
                                                                                                                                                                  unknownEuropean Union
                                                                                                                                                                  20940AKAMAI-ASN1EUfalse
                                                                                                                                                                  59.110.133.46
                                                                                                                                                                  unknownChina
                                                                                                                                                                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                                                                                                                                                  142.250.181.227
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                                  239.255.255.250
                                                                                                                                                                  unknownReserved
                                                                                                                                                                  unknownunknownfalse
                                                                                                                                                                  142.250.185.196
                                                                                                                                                                  unknownUnited States
                                                                                                                                                                  15169GOOGLEUSfalse
                                                                                                                                                                  140.143.180.217
                                                                                                                                                                  unknownChina
                                                                                                                                                                  45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompafalse
                                                                                                                                                                  IP
                                                                                                                                                                  192.168.2.6
                                                                                                                                                                  192.168.2.5
                                                                                                                                                                  Joe Sandbox version:42.0.0 Malachite
                                                                                                                                                                  Analysis ID:1608870
                                                                                                                                                                  Start date and time:2025-02-07 01:22:50 +01:00
                                                                                                                                                                  Joe Sandbox product:CloudBasic
                                                                                                                                                                  Overall analysis duration:0h 3m 47s
                                                                                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                                                                                  Report type:full
                                                                                                                                                                  Cookbook file name:browseurl.jbs
                                                                                                                                                                  Sample URL:http://888.mixly.us.kg/
                                                                                                                                                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                  Number of analysed new started processes analysed:11
                                                                                                                                                                  Number of new started drivers analysed:0
                                                                                                                                                                  Number of existing processes analysed:0
                                                                                                                                                                  Number of existing drivers analysed:0
                                                                                                                                                                  Number of injected processes analysed:0
                                                                                                                                                                  Technologies:
                                                                                                                                                                  • HCA enabled
                                                                                                                                                                  • EGA enabled
                                                                                                                                                                  • AMSI enabled
                                                                                                                                                                  Analysis Mode:default
                                                                                                                                                                  Analysis stop reason:Timeout
                                                                                                                                                                  Detection:MAL
                                                                                                                                                                  Classification:mal52.phis.win@20/546@0/30
                                                                                                                                                                  EGA Information:Failed
                                                                                                                                                                  HCA Information:
                                                                                                                                                                  • Successful, ratio: 100%
                                                                                                                                                                  • Number of executed functions: 0
                                                                                                                                                                  • Number of non-executed functions: 0
                                                                                                                                                                  • Exclude process from analysis (whitelisted): dllhost.exe, audiodg.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                                                                                                                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                  • Skipping network analysis since amount of network traffic is too extensive
                                                                                                                                                                  • VT rate limit hit for: http://888.mixly.us.kg/
                                                                                                                                                                  No simulations