IOC Report
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Sep 5 11:27:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 132
JSON data
dropped
Chrome Cache Entry: 133
PNG image data, 528 x 528, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 134
HTML document, Unicode text, UTF-8 text, with very long lines (20403)
downloaded
Chrome Cache Entry: 135
PNG image data, 532 x 532, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 136
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 137
PNG image data, 2880 x 952, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 138
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 139
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 140
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 141
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 142
PNG image data, 528 x 528, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 144
PNG image data, 2880 x 952, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 145
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 147
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 149
PNG image data, 532 x 532, 8-bit/color RGB, non-interlaced
dropped
There are 15 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1916,i,694644445453319614,14567216347516798064,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
https://site.ntesmail.com/umi.7010d9a0.css
47.246.46.227
https://site.ntesmail.com/static/contact_bg.2c30255a.png
47.246.46.227
https://tailwindcss.com
unknown
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
https://site.ntesmail.com/umi.1961b306.js
47.246.46.227
https://waimao.office.163.com/site/favicon.png
139.95.8.252
https://sentry2.lx.netease.com/api/16/envelope/?sentry_key=c1c4787cd71a4b3eb8c70bc6f2e1b2e0&sentry_version=7&sentry_client=sentry.javascript.browser%2F7.69.0
59.111.243.39
https://site.ntesmail.com/static/hot.643d43d1.svg
47.246.46.227
https://site.ntesmail.com/static/alibaba.84fa3c8d.svg
47.246.46.227
https://waimao.office.163.com/site/api/pub/site/track?opType=OPEN_PRODUCT_DETAILS&mid=8e88ea30-34d0-4984-8658-fa597e8623e4&productId=1184757&cid=site%255C_ngxvLcIm8CN043WgmaKV5L8RaPSew%255C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
139.95.8.252
https://waimao.office.163.com/site/api/pub/site/track?opType=TRACK_DATA&mid=8e88ea30-34d0-4984-8658-fa597e8623e4&productId=1184757&cid=site%255C_ngxvLcIm8CN043WgmaKV5L8RaPSew%255C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&sendType=first
139.95.8.252
https://waimao.office.163.com/site/api/pub/site/track?opType=TRACK_DATA&mid=8e88ea30-34d0-4984-8658-fa597e8623e4&productId=1184757&cid=site%255C_ngxvLcIm8CN043WgmaKV5L8RaPSew%255C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&sendType=other
139.95.8.252
https://qiye.163.com/sirius/privacy_waimao/index.html
unknown
https://qiye.163.com/sirius/agreement_waimao/index.html
unknown
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sentry2.lx.netease.com
59.111.243.39
www.google.com
142.250.185.132
site.ntesmail.com.w.cdngslb.com
47.246.46.227
cowork-storage.nosdn.127.net.w.cdngslb.com
163.181.92.229
hwweb.qiye.ntes53.netease.com
139.95.8.252
waimao.office.163.com
unknown
cowork-storage.nosdn.127.net
unknown
site.ntesmail.com
unknown

IPs

IP
Domain
Country
Malicious
163.181.92.229
cowork-storage.nosdn.127.net.w.cdngslb.com
United States
59.111.243.39
sentry2.lx.netease.com
China
192.168.2.16
unknown
unknown
142.250.185.132
www.google.com
United States
47.246.24.224
unknown
United States
139.95.8.252
hwweb.qiye.ntes53.netease.com
United States
239.255.255.250
unknown
Reserved
47.246.46.227
site.ntesmail.com.w.cdngslb.com
United States

DOM / HTML

URL
Malicious
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR
https://site.ntesmail.com/product/1184757.html?mid=8e88ea30-34d0-4984-8658-fa597e8623e4&bid=yKt9XNNayY6RSE0qNd-iOW-ITnKtRMrSmlFD82EPrWTl2AEuuQNDG3I4hI1dqYvXSf9sVu1aC4OB8qO77Xqqlw&cid=site%5C_ngxvLcIm8CN043WgmaKV5L8RaPSew%5C_ZtFhCGFVcL5br4ylTP5Zdst1weTlirIWGR