IOC Report
http://cidian.youdao.com/apps/update5/dictupdate.xml?ver=2160&_=1728466616213&product=deskdict&client=deskdict&id=14b7d35e0249fc065&vendor=fanyiweb_navigation&in=YoudaoDict_fanyiweb_navigation&appVer=11.0.0.0&abTest=&model=VMware7_1&screen=2560*1440&OsVersion=10.0.19045&network=none&mid=windows10.0.

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 15:32:57 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 15:32:56 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 15:32:56 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 15:32:56 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 15:32:56 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 296
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 297
HTML document, ASCII text
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (693)
downloaded
Chrome Cache Entry: 299
ASCII text, with very long lines (2049)
dropped
Chrome Cache Entry: 300
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 301
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 302
PNG image data, 192 x 120, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 303
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 305
ASCII text, with very long lines (2287)
downloaded
Chrome Cache Entry: 307
PNG image data, 275 x 175, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 308
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (311), with CRLF line terminators
downloaded
Chrome Cache Entry: 310
Web Open Font Format (Version 2), TrueType, length 31568, version 1.0
downloaded
Chrome Cache Entry: 311
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF, CR line terminators
downloaded
Chrome Cache Entry: 312
Unicode text, UTF-8 text, with very long lines (4105)
downloaded
Chrome Cache Entry: 313
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 315
PNG image data, 1344 x 289, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (3274), with no line terminators
downloaded
Chrome Cache Entry: 317
PNG image data, 128 x 35, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 318
PNG image data, 1280 x 800, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 319
ASCII text, with very long lines (7958)
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (4328)
dropped
Chrome Cache Entry: 321
PNG image data, 192 x 120, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 322
ASCII text
downloaded
Chrome Cache Entry: 323
PNG image data, 1072 x 230, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 324
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 325
Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
downloaded
Chrome Cache Entry: 326
ASCII text, with very long lines (723)
downloaded
Chrome Cache Entry: 327
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 328
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 329
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (932)
downloaded
Chrome Cache Entry: 331
ASCII text, with very long lines (1302)
downloaded
Chrome Cache Entry: 332
PNG image data, 275 x 175, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 334
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 335
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 336
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Picasa], baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 337
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (974)
downloaded
Chrome Cache Entry: 339
ASCII text, with very long lines (2287)
downloaded
Chrome Cache Entry: 340
PNG image data, 854 x 147, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 341
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 342
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (779)
downloaded
Chrome Cache Entry: 344
PNG image data, 192 x 120, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 345
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 346
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 347
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 348
ASCII text, with very long lines (26035)
downloaded
Chrome Cache Entry: 349
ASCII text, with very long lines (1272)
downloaded
Chrome Cache Entry: 350
ASCII text, with very long lines (25676)
downloaded
Chrome Cache Entry: 351
ASCII text, with very long lines (4009)
downloaded
Chrome Cache Entry: 352
PNG image data, 60 x 60, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 353
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Picasa], baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 354
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 355
PNG image data, 275 x 175, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 356
PNG image data, 960 x 280, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 357
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 358
PNG image data, 959 x 7, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 359
ASCII text, with very long lines (1195)
downloaded
Chrome Cache Entry: 360
PNG image data, 622 x 26, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 361
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Picasa], baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 362
PNG image data, 214 x 55, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 366
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 367
PNG image data, 959 x 1, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 368
PNG image data, 1280 x 800, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 369
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 370
ASCII text
downloaded
Chrome Cache Entry: 371
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 372
PNG image data, 960 x 140, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 373
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 374
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 375
ASCII text, with very long lines (525)
downloaded
Chrome Cache Entry: 377
ASCII text, with very long lines (7774)
downloaded
Chrome Cache Entry: 378
ASCII text, with very long lines (3447)
downloaded
Chrome Cache Entry: 379
PNG image data, 275 x 175, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 380
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 381
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 382
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 384
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 385
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=2, software=Picasa], baseline, precision 8, 48x48, components 3
downloaded
Chrome Cache Entry: 386
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 387
ASCII text
downloaded
Chrome Cache Entry: 388
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 48x48, components 3
downloaded
Chrome Cache Entry: 389
PNG image data, 1280 x 800, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 390
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 391
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=2, software=Picasa], baseline, precision 8, 48x48, components 3
downloaded
Chrome Cache Entry: 392
PNG image data, 1344 x 289, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 393
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 394
JSON data
dropped
Chrome Cache Entry: 395
ASCII text
downloaded
Chrome Cache Entry: 396
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Picasa], baseline, precision 8, 275x175, components 3
downloaded
Chrome Cache Entry: 397
PNG image data, 275 x 175, 8-bit/color RGB, non-interlaced
downloaded
There are 89 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://cidian.youdao.com/apps/update5/dictupdate.xml?ver=2160&_=1728466616213&product=deskdict&client=deskdict&id=14b7d35e0249fc065&vendor=fanyiweb_navigation&in=YoudaoDict_fanyiweb_navigation&appVer=11.0.0.0&abTest=&model=VMware7_1&screen=2560*1440&OsVersion=10.0.19045&network=none&mid=windows10.0.19045
https://chromewebstore.google.com/detail/%E7%BD%91%E6%98%93%E6%9C%89%E9%81%93%E7%BF%BB%E8%AF%91/eopjamdnofihpioajgfdikhhbobonhbb
https://cidian.youdao.com/chromeplus/?keyfrom=3.1update

Domains

Name
IP
Malicious
scone-pa.clients6.google.com
142.250.185.234
plus.l.google.com
172.217.16.206
play.google.com
142.250.184.206
www3.l.google.com
142.250.186.46
chromewebstore.google.com
142.250.186.78
www.google.com
142.250.185.228
oversea.dict.ntes53.netease.com
47.89.225.38
googlehosted.l.googleusercontent.com
172.217.23.97
clients2.googleusercontent.com
unknown
dict-subsidiary.youdao.com
unknown
cidian.youdao.com
unknown
chrome.google.com
unknown
lh3.googleusercontent.com
unknown
apis.google.com
unknown
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.46
www3.l.google.com
United States
142.250.185.228
www.google.com
United States
192.168.2.17
unknown
unknown
216.58.206.78
unknown
United States
172.217.23.97
googlehosted.l.googleusercontent.com
United States
142.250.185.163
unknown
United States
47.88.31.216
unknown
United States
142.250.184.206
play.google.com
United States
142.250.186.74
unknown
United States
142.250.185.67
unknown
United States
142.250.186.78
chromewebstore.google.com
United States
216.58.212.136
unknown
United States
34.104.35.123
unknown
United States
1.1.1.1
unknown
Australia
172.217.16.206
plus.l.google.com
United States
172.217.16.129
unknown
United States
74.125.71.84
unknown
United States
142.250.185.234
scone-pa.clients6.google.com
United States
47.89.225.38
oversea.dict.ntes53.netease.com
United States
142.250.186.106
unknown
United States
142.250.185.170
unknown
United States
239.255.255.250
unknown
Reserved
172.217.18.106
unknown
United States
142.250.185.195
unknown
United States
142.250.186.142
unknown
United States
216.58.212.163
unknown
United States
172.217.16.195
unknown
United States
142.250.186.65
unknown
United States
There are 18 hidden IPs, click here to show them.