Windows Analysis Report
https://www.instagram.com/p/C_LMp4vs2k2/?igsh=MWZ0ajI3dmkxejBoZg==

Overview

General Information

Sample URL: https://www.instagram.com/p/C_LMp4vs2k2/?igsh=MWZ0ajI3dmkxejBoZg==
Analysis ID: 1501332
Infos:

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Program does not show much activity (idle)
Stores files to the Windows start menu directory

Classification

Source: chrome.exe Memory has grown: Private usage: 0MB later: 50MB
Source: chromecache_644.2.dr, chromecache_576.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/-chchjkxRCr/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/5RZXhVZje9T/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/9cisb7Fe7ih/ equals www.facebook.com (Facebook)
Source: chromecache_510.2.dr, chromecache_401.2.dr, chromecache_564.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/A4tfXiHOGrs/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_364.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/CCT5pM3qiNk/ equals www.facebook.com (Facebook)
Source: chromecache_510.2.dr, chromecache_401.2.dr, chromecache_564.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/Ga6vBwdwgUx/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/KRXTwBoPvVj/ equals www.facebook.com (Facebook)
Source: chromecache_625.2.dr, chromecache_375.2.dr, chromecache_354.2.dr, chromecache_364.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_480.2.dr, chromecache_578.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/MDzNl_j9yvg/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_514.2.dr, chromecache_347.2.dr, chromecache_607.2.dr, chromecache_368.2.dr, chromecache_578.2.dr, chromecache_619.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/OKBVmODmb-W/ equals www.facebook.com (Facebook)
Source: chromecache_575.2.dr, chromecache_436.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/V8_l6oUwABQ/ equals www.facebook.com (Facebook)
Source: chromecache_625.2.dr, chromecache_375.2.dr, chromecache_485.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/V9vdYColc4k/ equals www.facebook.com (Facebook)
Source: chromecache_644.2.dr, chromecache_576.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/VZYwkcc3BWr/ equals www.facebook.com (Facebook)
Source: chromecache_544.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/Vkd8AdLnKqZ/ equals www.facebook.com (Facebook)
Source: chromecache_625.2.dr, chromecache_375.2.dr, chromecache_485.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/WRsJ32R7YJG/ equals www.facebook.com (Facebook)
Source: chromecache_602.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/ZMc_bSwzLKC/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_364.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/aJoeSHn7XcN/ equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/cr2jmG-CdKo/ equals www.facebook.com (Facebook)
Source: chromecache_644.2.dr, chromecache_625.2.dr, chromecache_375.2.dr, chromecache_638.2.dr, chromecache_485.2.dr, chromecache_641.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_602.2.dr, chromecache_368.2.dr, chromecache_409.2.dr, chromecache_576.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/t3hOLs8wlXy/ equals www.facebook.com (Facebook)
Source: chromecache_485.2.dr String found in binary or memory: __d("BarcelonaTermsOfUseConstants",[],(function(a,b,c,d,e,f){"use strict";a="https://help.instagram.com/769983657850450";b="https://help.instagram.com/515230437301944";c="https://www.facebook.com/privacy/policy/";d="https://help.instagram.com/581066165581870";e="https://www.instagram.com/legal/privacy/health_privacy_policy/";f.TERMS_OF_USE_URL=a;f.SUPPLEMENTAL_PRIVACY_POLICY_URL=b;f.META_PRIVACY_POLICY_URL=c;f.META_TERMS_OF_USE_URL=d;f.US_HEALTHY_POLICY_URL=e}),66); equals www.facebook.com (Facebook)
Source: chromecache_422.2.dr String found in binary or memory: __d("Chromedome",["fbt"],(function(a,b,c,d,e,f,g,h){function i(){if(document.domain==null)return null;var a=document.domain,b=/^intern\./.test(a);if(b)return null;b=/(^|\.)facebook\.(com|sg)$/.test(a);if(b)return"facebook";b=/(^|\.)instagram\.com$/.test(a);if(b)return"instagram";b=/(^|\.)threads\.net$/.test(a);if(b)return"threads";b=/(^|\.)messenger\.com$/.test(a);return b?"messenger":null}function j(a){if(a==="instagram")return h._("This is a browser feature intended for developers. If someone told you to copy-paste something here to enable an Instagram feature or \"hack\" someone's account, it is a scam and will give them access to your Instagram account.");return a==="threads"?h._("This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Threads feature or \"hack\" someone's account, it is a scam and will give them access to your Threads account."):h._("This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Facebook feature or \"hack\" someone's account, it is a scam and will give them access to your Facebook account.")}function a(a){if(top!==window)return;a=i();if(a==null)return;var b=h._("Stop!");a=j(a);var c=h._("See {url} for more information.",[h._param("url","https://www.facebook.com/selfxss")]),d="font-family:helvetica; font-size:20px; ";[[b,d+"font-size:50px; font-weight:bold; color:red; -webkit-text-stroke:1px black;"],[a,d],[c,d],["",""]].map(function(a){window.setTimeout(console.log.bind(console,"\n%c"+a[0].toString(),a[1]))})}g.start=a}),226); equals www.facebook.com (Facebook)
Source: chromecache_625.2.dr String found in binary or memory: __d("FacebookCookieConsentCustomization",["fbt","ix","JSResourceForInteraction","XCookiesPolicyControllerRouteBuilder","isBaseline4EnabledForLoggedOut","isCNILEnabledForLoggedOut","lazyLoadComponent"],(function(a,b,c,d,e,f,g,h,i){"use strict";var j=c("lazyLoadComponent")(c("JSResourceForInteraction")("FacebookCometCookieConsentDialogDataSettings.react").__setRef("FacebookCookieConsentCustomization"));a=function(){var a,b,d,e=null;c("isBaseline4EnabledForLoggedOut")()||c("isCNILEnabledForLoggedOut")()?(b=i("1954651"),d=i("1954649"),e=h._("More options")):(b=i("856481"),d=i("856481"),e=h._("Manage Data Settings"));a=(a=(a=c("XCookiesPolicyControllerRouteBuilder").buildUri({}).getQualifiedUri())==null?void 0:(a=a.setDomain("www.facebook.com"))==null?void 0:a.toString())!=null?a:"";return{essentialCookiesOnly:!1,faviconDark:d,faviconLight:b,policyUrl:a,productName:"FACEBOOK",secondaryAction:{label:e,viewReference:j}}};b=a;g["default"]=b}),226); equals www.facebook.com (Facebook)
Source: chromecache_441.2.dr String found in binary or memory: __d("MWV2AdminMsgICDC.react",["fbt","MWAdminTextLayout.react","MWXLink.react","react","react-strict-dom"],(function(a,b,c,d,e,f,g,h){"use strict";var i,j=i||d("react"),k="https://www.facebook.com/help/messenger-app/1577627185919537/?helpref=uf_permalink&parent_cms_id=1084673321594605";function a(a){a=a.message;return j.jsx(c("MWAdminTextLayout.react"),{cta:j.jsx(d("react-strict-dom").html.div,{children:j.jsx(c("MWXLink.react"),{href:k,target:"_blank",children:h._("Learn More")})}),message:a})}a.displayName=a.name+" [from "+f.id+"]";g["default"]=a}),226); equals www.facebook.com (Facebook)
Source: chromecache_441.2.dr String found in binary or memory: __d("MWV2ChatTextParserUtils",["EmojiRenderer","EmoticonRenderer","I64","LSContactTypeExact","LSIntEnum","MWChatTextFormatting","MWLSContactTypeExactUtils","MessageProfileRangeTypeUtils","ReQL","ReQLSuspense","UnicodeUtils","XCometVanityURLControllerRouteBuilder","getURLRanges","gkx"],(function(a,b,c,d,e,f,g){"use strict";var h,i,j,k=new RegExp("/^[ \\r\\n\\s]*$/");function a(a){var b=d("EmojiRenderer").parse(a).map(function(a){return{length:a.length,offset:a.offset}}),c=d("EmoticonRenderer").parse(a).map(function(a){return{length:a.chars.length,offset:a.offset}});b=b.concat(c).sort(function(a,b){return a.offset-b.offset|0});if(b.length===0)return!1;var e={contents:0},f={contents:0};c=b.some(function(b){e.contents===b.offset?(e.contents=e.contents+b.length|0,f.contents=e.contents):f.contents=b.offset;var c=a.substring(e.contents,f.contents);e.contents=b.offset+b.length|0;return k.test(c)===!1});b=e.contents!==a.length&&!k.test(a.substring(f.contents));if(c)return!1;else return!b}function b(a,b){b===void 0&&(b=!1);var e=c("getURLRanges")(a),f=[];a=d("MWChatTextFormatting").getFormattingRanges(a,b);e.forEach(function(a){a={entity:{__typename:"Link",uri:a.entity.url},length:a.length,offset:a.offset};f.push(a)});return f.concat(a)}function l(a){if(c("gkx")("23433"))return"/t/"+a;else return"/messages/t/"+a}function m(a,b){try{a=d("ReQLSuspense").first(d("ReQL").fromTableAscending(a.tables.contacts).getKeyRange((h||(h=d("I64"))).of_string(b)),f.id+":115")}catch(b){a=void 0}if(a==null)return l(b);var e=a.contactTypeExact;if((h||(h=d("I64"))).equal(e,(i||(i=d("LSIntEnum"))).ofNumber(c("LSContactTypeExact").FB_USER)))return"https://www.facebook.com"+c("XCometVanityURLControllerRouteBuilder").buildURL({vanity:b});if(!d("MWLSContactTypeExactUtils").isIgContact(e))return l(b);e=a.secondaryName;if(e!=null)return"https://www.instagram.com/"+e+"/";else return l(b)}function e(a,b,c,e,f,g){b=b.split(",");var i=c.split(","),k=e.split(","),n=f.split(",");return b.reduce(function(b,c,e){var f=d("MessageProfileRangeTypeUtils").ofString(n[e]),o=Number(i[e]);e=Number(k[e]);var p=(j||(j=d("UnicodeUtils"))).strlen(g.slice(0,e));p=e-p;e=e-p;f==="t"||f==="a"?b.push({entity:{__typename:"Profile",id:c,uri:l(c)},length:o,offset:e}):f==="p"?b.push({entity:{__typename:"Profile",id:c,uri:m(a,c)},length:o,offset:e}):f==="cc"?b.push({entity:{__typename:"CommunityChannel",threadKey:(h||(h=d("I64"))).of_string(c)},length:o,offset:e}):f==="s"||f==="cu"?b.push({entity:{__typename:"Command"},length:o,offset:e}):f==="ai"&&b.push({entity:{__typename:"Ai"},length:o,offset:e});return b},[])}g.isEmojiOnlyMessage=a;g.findRanges=b;g.findRangesForMentions=e}),98); equals www.facebook.com (Facebook)
Source: chromecache_441.2.dr String found in binary or memory: __d("MWV2ChatUnsentMessage.react",["fbt","I64","MWCMIsAnyCMThread","MWLSThread","MWV2TombstonedMessage.react","MWXPressable.react","MWXText.react","ReQL","ReQLSuspense","XCometGroupAdminActivitiesControllerRouteBuilder","react","useCommunityFolder","useMAWUnsendContentInSecureThread","useReStore"],(function(a,b,c,d,e,f,g,h){"use strict";var i,j,k,l=j||d("react"),m={linkText:{paddingTop:"x1y1aw1k",paddingBottom:"xwib8y2",paddingStart:"x16hj40l",paddingLeft:null,paddingRight:null,paddingEnd:"xsyo7zv",$$css:!0}};function n(a){var b=a.attachment,d=a.isSecureMessage;a=a.message;var e=h._("A contact unsent a message");a=c("useMAWUnsendContentInSecureThread")(a);if(d)d=a;else if(b!=null){a=b.descriptionText;d=a!=null?a:e}else d=e;return l.jsx(c("MWV2TombstonedMessage.react"),{isOutgoing:!1,children:d})}n.displayName=n.name+" [from "+f.id+"]";function o(a){a=a.attachment;if(a!=null){a=a.descriptionText;a=a!=null?a:h._("You unsent a message")}else a=h._("You unsent a message");return l.jsx(c("MWV2TombstonedMessage.react"),{isOutgoing:!0,children:a})}o.displayName=o.name+" [from "+f.id+"]";function p(a){var b=a.attachment;a=a.thread;a=c("useCommunityFolder")(a);if(b!=null){b=b.cta1Title;b=b!=null?b:h._("See details in activity log")}else b=h._("See details in activity log");if(a!=null)return l.jsx(c("MWXPressable.react"),{linkProps:{url:"https://www.facebook.com"+c("XCometGroupAdminActivitiesControllerRouteBuilder").buildURL({idorvanity:(k||(k=d("I64"))).to_string(a.fbGroupId)})},overlayDisabled:!0,xstyle:function(){return[m.linkText]},children:l.jsx(c("MWXText.react"),{color:"blueLink",type:"meta2",children:b})});else return null}p.displayName=p.name+" [from "+f.id+"]";function a(a){var b=a.isSecureMessage,e=a.message;a=a.outgoing;var g=(i||(i=c("useReStore")))(),h=e.messageId,j=e.threadKey,k=d("MWLSThread").useThread(j),m=d("ReQLSuspense").useFirst(function(){return d("ReQL").fromTableAscending(g.tables.attachments).getKeyRange(j,h)},[g,h,j],f.id+":137");if(m!=null){var q=m.cta1Type;q=q!=null?q==="xma_view_activity_log":!1}else q=!1;return l.jsxs(l.Fragment,{children:[a?l.jsx(o,{attachment:m}):l.jsx(n,{attachment:m,isSecureMessage:b,message:e}),k!=null&&q&&c("MWCMIsAnyCMThread")(k.threadType)?l.jsx(p,{attachment:m,thread:k}):null]})}a.displayName=a.name+" [from "+f.id+"]";g.MWV2ChatUnsentMessage=a}),226); equals www.facebook.com (Facebook)
Source: chromecache_351.2.dr String found in binary or memory: __d("PolarisExternalRoutes",["PolarisLocales","URI"],(function(a,b,c,d,e,f,g){"use strict";var h;function a(a){return new(h||(h=c("URI")))(a).addQueryData({locale:c("PolarisLocales").locale}).toString()}b=a("https://help.instagram.com/581066165581870/");d="https://about.instagram.com/blog/";e="https://about.instagram.com";f="https://about.meta.com";var i="https://www.meta.com/smart-glasses/",j="https://developers.facebook.com/docs/instagram",k="https://help.instagram.com",l="https://www.facebook.com/privacy/policy",m="https://privacycenter.instagram.com/policy/",n="https://www.instagram.com/privacy/cookie_settings/",o="/legal/cookies/",p=a("https://help.instagram.com/416323267314424/"),q="https://www.facebook.com/policies/cookies",r="https://privacycenter.instagram.com/policies/cookies/",s="https://privacycenter.instagram.com/policies/cookies/?annotations[0]=explanation%2F3_companies_list",t="https://www.facebook.com/help/instagram/261704639352628",u="https://www.whatsapp.com/legal/commerce-policy/",v="https://about.meta.com/technologies/meta-verified/",w=a("https://help.instagram.com/contact/543840232909258/"),x=a("https://help.instagram.com/contact/598671977756435/"),y=a("https://help.instagram.com/contact/406206379945942/");a=a("https://help.instagram.com/contact/383679321740945");var z="https://help.instagram.com/116024195217477",A="https://www.facebook.com/help/instagram/1164377657035425/",B="https://familycenter.instagram.com/supervision",C="https://familycenter.instagram.com/education",D="https://business.facebook.com/latest/creator_marketplace?source=ig_web_profile&nav_ref=ig_web_profile",E="https://business.facebook.com/latest?nav_ref=ig_web_more_nav_menu",F="https://business.facebook.com/billing_hub/payment_settings?",G="https://m.facebook.com/billing_hub/payment_settings?",H="https://indonesia.fb.com/panduan-digital/",I="https://www.facebook.com/help/cancelcontracts?source=instagram.com",J="https://about.instagram.com/about-us/careers";g.NEW_LEGAL_TERMS_PATH=b;g.INSTAGRAM_PRESS_SITE_PATH=d;g.INSTAGRAM_ABOUT_SITE_PATH=e;g.META_ABOUT_SITE_PATH=f;g.META_RAY_BAN_SITE_PATH=i;g.INSTAGRAM_API_SITE_PATH=j;g.INSTAGRAM_HELP_SITE_PATH=k;g.NEW_PRIVACY_POLICY_PATH=l;g.INSTAGRAM_PRIVACY_POLICY_PATH=m;g.INSTAGRAM_COOKIE_SETTINGS_PATH=n;g.NEW_COOKIE_POLICY_PATH=o;g.NETZDG_URHDAG_RANKING_OF_CONTENT_PATH=p;g.FACEBOOK_COOKIE_POLICY_PATH=q;g.INSTAGRAM_COOKIE_POLICY_PATH_UPDATED=r;g.INSTAGRAM_COOKIE_POLICY_OTHER_COMPANIES_PATH=s;g.FACEBOOK_CONTACT_UPLOADING_AND_NON_USERS=t;g.WHATSAPP_COMMERCE_POLICY_PATH=u;g.META_VERIFIED_MARKETING_PATH=v;g.NETZDG_REPORT_CONTACT_FORM_PATH=w;g.CPA_REPORT_CONTACT_FORM_PATH=x;g.DSA_REPORT_CONTACT_FORM_PATH=y;g.COMMUNITY_VIOLATIONS_GUIDELINES_CONTACT_FORM_PATH=a;g.ACCOUNT_PRIVACY_HELP_PATH=z;g.ACTIVITY_STATUS_HELP_PATH=A;g.FAMILY_CENTER_HOME_PATH=B;g.EDUCATION_HUB_PATH=C;g.CREATOR_MARKETPLACE_PATH=D;g.MORE_NAV_MENU_META_BUSINESS_SUITE_PATH=E;g.BILLING_HUB_DESKTOP_PATH=F;g.BILLING_HUB_MSITE_PATH=G;g.META_IN_INDONESIA_PATH=H;g.C
Source: chromecache_578.2.dr String found in binary or memory: __d("PolarisFBConnectHelpers",["FbSdkConsts","InstagramQueryParamsHelper","PolarisConfig","PolarisConfigConstants","PolarisFBSignupQEHelpers","PolarisIGWebStorage","PolarisLocales","PolarisLoggedOutCtaLogger","PolarisOneTapLoginStorage","PolarisRoutes","PolarisUA","PolarisWebStorage","Promise","Random","asyncToGeneratorRuntime","browserHistory_DO_NOT_USE","cometAsyncFetch","emptyFunction","isStringNullOrEmpty","nullthrows","polarisFBReady","polarisLogAction"],(function(a,b,c,d,e,f,g){"use strict";var h,i=[0,0,0,0,0,0,0,0],j="https://m.facebook.com/dialog/oauth",k="https://www.facebook.com/dialog/oauth",l="https://www.facebook.com/oidc/",m="NewUserInterstitial.profile_picture_url",n="fbAccessToken",o="fbLoginKey",p="fbLoginReturnURL",q="fbPlainToken";function r(a,e){e===void 0&&(e=[]);var f=c("PolarisWebStorage").getSessionStorage(),g=i.reduce(function(a){return a+d("Random").uint32().toString(36)},"");f!=null&&f.setItem(o,g);f="https://www.instagram.com"+d("PolarisRoutes").SIGNUP_PATH;var h="https://www.instagram.com"+d("PolarisRoutes").FACEBOOK_V2_SIGNUP_PATH,j=t(),k=d("PolarisFBSignupQEHelpers").shouldUseOIDCSignupFlow();if(!k){g=(k={},k[o]=g,k[p]=a,k);a={client_id:d("PolarisConfigConstants").instagramFBAppId,locale:c("PolarisLocales").locale,redirect_uri:f,response_type:"code,granted_scopes",scope:e.concat(d("FbSdkConsts").PERMISSIONS.EMAIL).join(","),state:JSON.stringify(g)};k=d("InstagramQueryParamsHelper").appendQueryParams(j,a);d("browserHistory_DO_NOT_USE").redirect(k)}else{f=function(){var a=b("asyncToGeneratorRuntime").asyncToGenerator(function*(){var a=(yield c("cometAsyncFetch")("/oidc/state/",{data:{},method:"POST"}));return a});return function(){return a.apply(this,arguments)}}();f().then(function(a){a=a.state;a={app_id:d("PolarisConfigConstants").instagramFBAppId,redirect_uri:h,response_type:"code",scope:"openid email profile",state:a};a=d("InstagramQueryParamsHelper").appendQueryParams(j,a);d("browserHistory_DO_NOT_USE").redirect(a)})["catch"](function(a){return c("emptyFunction")()})}}function s(){var a=c("PolarisWebStorage").getSessionStorage(),b=null;a!=null&&(b=a.getItem(o),a.removeItem(o));return c("isStringNullOrEmpty")(b)?null:b}function t(){return d("PolarisUA").isMobile()?j:d("PolarisFBSignupQEHelpers").shouldUseOIDCSignupFlow()?l:k}function a(a){var b=s();return b==null||b===""?!1:a===b}function e(){var a;return(a=d("PolarisIGWebStorage").getStorageForUser(d("PolarisConfig").getViewerId()))==null?void 0:a.getItem(n)}function f(a){return u.apply(this,arguments)}function u(){u=b("asyncToGeneratorRuntime").asyncToGenerator(function*(a){var e=(yield new(h||(h=b("Promise")))(function(a,b){c("polarisFBReady").sdkReady(function(){c("polarisFBReady").getLoginStatus(!0).then(function(c){c.status===d("FbSdkConsts").STATUS.CONNECTED?a(c):b()})["catch"](function(a){b(a)})})}));if(a){a=(a=e.authResponse)==null?void 0:a.accessToken;w(a)}return e});return u.apply(this,arguments)}function v(){return new(h||(h=b("Promise")))(function(a,b
Source: chromecache_351.2.dr String found in binary or memory: __d("PolarisLinkshimURI",["PolarisInstapi","URI","promiseDone"],(function(a,b,c,d,e,f,g){"use strict";var h,i=["l.facebook.com","l.instagram.com"],j=["help.instagram.com","www.facebook.com","business.facebook.com"];function k(a){var b;try{b=new(h||(h=c("URI")))(a)}catch(a){return!1}a=b.getDomain();var d=b.getProtocol().toLowerCase();return d!=null&&!d.startsWith("http")?!0:i.includes(a)&&!!b.getQueryData().u||j.includes(a)}function a(a,b,e){e===void 0&&(e=""),k(a)&&b(a),c("promiseDone")(d("PolarisInstapi").apiPost("/api/v1/web/linkshim/link/",{body:{cs:e,u:a}}).then(function(a){b(a.data.uri)}))}g.shouldSkipLinkShim=k;g.asyncGet=a}),98); equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_637.2.dr, chromecache_607.2.dr, chromecache_388.2.dr, chromecache_351.2.dr String found in binary or memory: __d("RealtimeGraphQLRequest",["invariant","RequestStreamCommonRequestStreamCommonTypes","TransportSelectingClientSingleton","nullthrows","regeneratorRuntime"],(function(a,b,c,d,e,f,g,h){"use strict";a=function(){function a(a){var b=this,e=a.method,f=a.doc_id,g=a.is_intern,i=a.extra_headers,j=a.body,k=a.instrumentation_data;a=a.sandbox;this.$12=function(a){switch(a){case d("RequestStreamCommonRequestStreamCommonTypes").FlowStatus.Started:if(b.$10){b.$9!=null||h(0,13576);a=Date.now()-c("nullthrows")(b.$9);b.$7!=null&&b.$7(a)}else b.$10=!0,b.$5!=null&&b.$5();break;case d("RequestStreamCommonRequestStreamCommonTypes").FlowStatus.Stopped:b.$9=Date.now();b.$6!=null&&b.$6(!1,!1);break;default:break}};this.$10=!1;e={method:e,doc_id:f};g===!0&&(e=babelHelpers["extends"]({},e,{www_tier:"intern"}));a!=null&&(e=babelHelpers["extends"]({},e,{www_sandbox:a.replace(/^not-www\.(\d+|\w+)\.(od|sb)\.internalfb\.com$/,"www.$1.$2.facebook.com")}));i!=null&&(e=babelHelpers["extends"]({},e,i));this.$1=e;this.$2=JSON.stringify(j);this.$11=k}var e=a.prototype;e.onResponse=function(a){this.$3=a;return this};e.onError=function(a){this.$4=a;return this};e.onActive=function(a){this.$5=a;return this};e.onPause=function(a){this.$6=a;return this};e.onResume=function(a){this.$7=a;return this};e.onRetryUpdateRequestBody=function(a){this.$8=a;this.$1=babelHelpers["extends"]({},this.$1,{request_stream_retry:"false"});return this};e.send=function(){var a,d;return b("regeneratorRuntime").async(function(e){while(1)switch(e.prev=e.next){case 0:this.$3!=null||h(0,33593);a={onData:c("nullthrows")(this.$3)};this.$4!=null&&(a=babelHelpers["extends"]({},a,{onTermination:this.$4}));a=babelHelpers["extends"]({},a,{onFlowStatus:this.$12});this.$8!=null&&(a=babelHelpers["extends"]({},a,{onRetryUpdateRequestBody:this.$8}));e.next=7;return b("regeneratorRuntime").awrap(c("TransportSelectingClientSingleton").requestStream(this.$1,this.$2,a,this.$11));case 7:d=e.sent;return e.abrupt("return",{cancel:function(){d.cancel()},amendExperimental:function(a){try{d.amendWithoutAck(JSON.stringify(a));return!0}catch(a){return!1}}});case 9:case"end":return e.stop()}},null,this)};return a}();g["default"]=a}),98); equals www.facebook.com (Facebook)
Source: chromecache_597.2.dr, chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: __d("VideoPlayerFallbackLearnMoreLink.react",["fbt","CometLink.react","FDSText.react","gkx","react"],(function(a,b,c,d,e,f,g,h){"use strict";var i,j=i||d("react");function a(){var a=c("gkx")("20836")?"/help/work/1876956335887765/i-cant-view-or-play-videos-on-workplace":"https://www.facebook.com/help/396404120401278/list";return j.jsx(c("FDSText.react"),{color:"primaryOnMedia",type:"headlineEmphasized3",children:j.jsx(c("CometLink.react"),{href:a,target:"_blank",children:h._("Learn more")})})}a.displayName=a.name+" [from "+f.id+"]";g["default"]=a}),226); equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: __d("isPolarisAdLink",["URI"],(function(a,b,c,d,e,f,g){"use strict";var h,i="www.facebook.com",j=/www\.[\w\-]+\.(od|(sandcastle|twshared)(\w+\.)+\w+)?\.?facebook\.com/,k="/ads/ig_redirect/";function a(a){a=new(h||(h=c("URI")))(a);var b=a.getDomain();if(a.getPath()!==k)return!1;return b===i?!0:a.getDomain().match(j)!=null}g["default"]=a}),98); equals www.facebook.com (Facebook)
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: http://fb.me/use-check-prop-types
Source: chromecache_602.2.dr String found in binary or memory: http://fburl.com/js-libs-www
Source: chromecache_354.2.dr, chromecache_480.2.dr String found in binary or memory: http://www.windowsphone.com/s?appid=3222a126-7f20-4273-ab4a-161120b21aea
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: https://about.instagram.com
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: https://about.instagram.com/blog/
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: https://about.meta.com
Source: chromecache_436.2.dr String found in binary or memory: https://accountscenter.instagram.com
Source: chromecache_485.2.dr String found in binary or memory: https://apps.apple.com/app/apple-store/id6446901002?pt=428156&ct=
Source: chromecache_354.2.dr, chromecache_480.2.dr String found in binary or memory: https://apps.apple.com/app/instagram/id
Source: chromecache_480.2.dr String found in binary or memory: https://e2e.instagram.com
Source: chromecache_607.2.dr String found in binary or memory: https://familycenter.instagram.com/accounts/
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_637.2.dr, chromecache_607.2.dr, chromecache_388.2.dr, chromecache_351.2.dr String found in binary or memory: https://fburl.com/comet_preloading
Source: chromecache_354.2.dr, chromecache_480.2.dr, chromecache_629.2.dr String found in binary or memory: https://fburl.com/dialog-provider).
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_637.2.dr, chromecache_607.2.dr, chromecache_388.2.dr, chromecache_351.2.dr String found in binary or memory: https://fburl.com/wiki/m19zmtlh
Source: chromecache_375.2.dr, chromecache_393.2.dr, chromecache_583.2.dr, chromecache_607.2.dr, chromecache_465.2.dr String found in binary or memory: https://fburl.com/wiki/xrzohrqb
Source: chromecache_354.2.dr, chromecache_485.2.dr, chromecache_480.2.dr String found in binary or memory: https://graph.instagram.com/logging_client_events
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: https://graphql.instagram.com/graphql/
Source: chromecache_375.2.dr, chromecache_607.2.dr, chromecache_578.2.dr String found in binary or memory: https://help.instagram.com/126382350847838
Source: chromecache_375.2.dr, chromecache_600.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/155833707900388
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: https://help.instagram.com/176296189679904?ref=tos
Source: chromecache_485.2.dr String found in binary or memory: https://help.instagram.com/1896641480634370/
Source: chromecache_375.2.dr, chromecache_607.2.dr, chromecache_578.2.dr String found in binary or memory: https://help.instagram.com/222826637847963
Source: chromecache_375.2.dr, chromecache_600.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/2387676754836493
Source: chromecache_637.2.dr, chromecache_388.2.dr String found in binary or memory: https://help.instagram.com/2589432474704452
Source: chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/370452623149242
Source: chromecache_375.2.dr, chromecache_607.2.dr, chromecache_578.2.dr String found in binary or memory: https://help.instagram.com/426700567389543/
Source: chromecache_375.2.dr, chromecache_607.2.dr, chromecache_578.2.dr String found in binary or memory: https://help.instagram.com/477434105621119
Source: chromecache_441.2.dr String found in binary or memory: https://help.instagram.com/491565145294150/
Source: chromecache_485.2.dr String found in binary or memory: https://help.instagram.com/515230437301944
Source: chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/519522125107875
Source: chromecache_375.2.dr, chromecache_607.2.dr, chromecache_578.2.dr String found in binary or memory: https://help.instagram.com/535503073130320/
Source: chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/581066165581870
Source: chromecache_607.2.dr, chromecache_578.2.dr, chromecache_351.2.dr String found in binary or memory: https://help.instagram.com/581066165581870/
Source: chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/626057554667531
Source: chromecache_375.2.dr, chromecache_607.2.dr, chromecache_578.2.dr String found in binary or memory: https://help.instagram.com/629037417957828
Source: chromecache_485.2.dr String found in binary or memory: https://help.instagram.com/769983657850450
Source: chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: https://help.instagram.com/cookie_settings
Source: chromecache_354.2.dr, chromecache_485.2.dr, chromecache_480.2.dr String found in binary or memory: https://i.instagram.com
Source: chromecache_619.2.dr String found in binary or memory: https://lexical.dev/docs/error?
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: https://optout.aboutads.info/
Source: chromecache_354.2.dr, chromecache_480.2.dr String found in binary or memory: https://play.google.com/store/apps/details?id=com.instagram.android
Source: chromecache_485.2.dr String found in binary or memory: https://play.google.com/store/apps/details?id=com.instagram.barcelona&referrer=utm_source%3D
Source: chromecache_354.2.dr, chromecache_480.2.dr String found in binary or memory: https://play.google.com/store/apps/details?id=com.instagram.lite
Source: chromecache_485.2.dr String found in binary or memory: https://privacycenter.instagram.com/policies/cookies/?annotations
Source: chromecache_602.2.dr String found in binary or memory: https://scontent.xx.fbcdn.net/hads-ak-prn2/1487645_6012475414660_1439393861_n.png
Source: chromecache_607.2.dr String found in binary or memory: https://www.instagram.com
Source: chromecache_375.2.dr, chromecache_607.2.dr String found in binary or memory: https://www.instagram.com/support/chat/embed/ig/
Source: chromecache_485.2.dr String found in binary or memory: https://www.internalfb.com
Source: chromecache_510.2.dr, chromecache_401.2.dr, chromecache_564.2.dr String found in binary or memory: https://www.internalfb.com/intern/invariant/
Source: chromecache_441.2.dr String found in binary or memory: https://www.messenger.com
Source: chromecache_524.2.dr String found in binary or memory: https://www.messenger.com/desktop/
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: https://www.meta.com/help/connected-experiences/switch-between-profiles/
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr, chromecache_351.2.dr String found in binary or memory: https://www.meta.com/smart-glasses/
Source: chromecache_485.2.dr, chromecache_465.2.dr String found in binary or memory: https://www.threads.net
Source: chromecache_485.2.dr String found in binary or memory: https://www.threads.net/privacy/cookie_settings/
Source: chromecache_625.2.dr String found in binary or memory: https://www.whatsapp.com/legal/cookies/
Source: chromecache_625.2.dr String found in binary or memory: https://www.workplace.com/legal/FB_Work_Cookies
Source: chromecache_625.2.dr String found in binary or memory: https://www.workplace.com/legal/WP_Work_Cookies
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: https://www.youronlinechoices.com/
Source: chromecache_375.2.dr, chromecache_436.2.dr, chromecache_607.2.dr String found in binary or memory: https://youradchoices.ca/
Source: classification engine Classification label: clean1.win@30/479@0/27
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2240 --field-trial-handle=2036,i,15367856811469279219,10978006716539294708,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.instagram.com/p/C_LMp4vs2k2/?igsh=MWZ0ajI3dmkxejBoZg=="
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2240 --field-trial-handle=2036,i,15367856811469279219,10978006716539294708,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs