IOC Report
http://aa5aa5aa5aa5aa44.app/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
gzip compressed data, from Unix, original size modulo 2^32 20181
downloaded
Chrome Cache Entry: 101
Unicode text, UTF-8 text, with very long lines (65476), with no line terminators
dropped
Chrome Cache Entry: 102
gzip compressed data, from Unix, original size modulo 2^32 3821
dropped
Chrome Cache Entry: 103
gzip compressed data, from Unix, original size modulo 2^32 111187
downloaded
Chrome Cache Entry: 104
gzip compressed data, from Unix, original size modulo 2^32 195653
downloaded
Chrome Cache Entry: 105
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 106
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, extended sequential, precision 8, 368x368, components 3
dropped
Chrome Cache Entry: 107
gzip compressed data, from Unix, original size modulo 2^32 1051722
downloaded
Chrome Cache Entry: 108
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, extended sequential, precision 8, 368x368, components 3
downloaded
Chrome Cache Entry: 109
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 110
gzip compressed data, from Unix, original size modulo 2^32 95671
downloaded
Chrome Cache Entry: 111
gzip compressed data, from Unix, original size modulo 2^32 5229
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (572)
downloaded
Chrome Cache Entry: 113
gzip compressed data, from Unix, original size modulo 2^32 20181
dropped
Chrome Cache Entry: 114
gzip compressed data, from Unix, original size modulo 2^32 109906
dropped
Chrome Cache Entry: 115
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 116
PNG image data, 240 x 83, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 117
Unicode text, UTF-8 text, with very long lines (65476), with no line terminators
downloaded
Chrome Cache Entry: 118
gzip compressed data, from Unix, original size modulo 2^32 29529945
downloaded
Chrome Cache Entry: 119
gzip compressed data, from Unix, original size modulo 2^32 3821
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (10194), with no line terminators
dropped
Chrome Cache Entry: 72
gzip compressed data, from Unix, original size modulo 2^32 29529945
dropped
Chrome Cache Entry: 73
gzip compressed data, from Unix, original size modulo 2^32 208214
dropped
Chrome Cache Entry: 74
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 75
gzip compressed data, from Unix, original size modulo 2^32 2138
downloaded
Chrome Cache Entry: 76
gzip compressed data, from Unix, original size modulo 2^32 11440
downloaded
Chrome Cache Entry: 77
gzip compressed data, from Unix, original size modulo 2^32 3635
downloaded
Chrome Cache Entry: 78
gzip compressed data, from Unix, original size modulo 2^32 95671
dropped
Chrome Cache Entry: 79
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 80
gzip compressed data, from Unix, original size modulo 2^32 5229
dropped
Chrome Cache Entry: 81
gzip compressed data, from Unix, original size modulo 2^32 1753
downloaded
Chrome Cache Entry: 82
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (10194), with no line terminators
downloaded
Chrome Cache Entry: 84
gzip compressed data, from Unix, original size modulo 2^32 4718
downloaded
Chrome Cache Entry: 85
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 86
HTML document, ASCII text, with very long lines (906), with no line terminators
downloaded
Chrome Cache Entry: 87
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 88
gzip compressed data, from Unix, original size modulo 2^32 1051722
dropped
Chrome Cache Entry: 89
gzip compressed data, from Unix, original size modulo 2^32 484367
downloaded
Chrome Cache Entry: 90
gzip compressed data, from Unix, original size modulo 2^32 3635
dropped
Chrome Cache Entry: 91
gzip compressed data, from Unix, original size modulo 2^32 109906
downloaded
Chrome Cache Entry: 92
gzip compressed data, from Unix, original size modulo 2^32 2173
downloaded
Chrome Cache Entry: 93
PNG image data, 240 x 83, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 94
gzip compressed data, from Unix, original size modulo 2^32 111187
dropped
Chrome Cache Entry: 95
gzip compressed data, from Unix, original size modulo 2^32 208214
downloaded
Chrome Cache Entry: 96
gzip compressed data, from Unix, original size modulo 2^32 1753
dropped
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 195653
dropped
Chrome Cache Entry: 98
HTML document, ASCII text, with very long lines (906), with no line terminators
dropped
Chrome Cache Entry: 99
gzip compressed data, from Unix, original size modulo 2^32 11440
dropped
There are 40 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2024,i,4110611763947970368,17166306496067060294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://aa5aa5aa5aa5aa44.app/"

URLs

Name
IP
Malicious
http://aa5aa5aa5aa5aa44.app/
malicious
http://aa5aa5aa5aa5aa44.app/assets/index-fd1be804.css
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/SwiperBanner-cd8dc074.css
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/ColVideoItem-2396d821.css
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/home
malicious
http://aa5aa5aa5aa5aa44.app/assets/Home-52354fe8.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/AdvertisementList.vue_vue_type_script_setup_true_name_AdvertisementList_lang-6c6de8d9.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/openIM.wasm
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/favicon.ico
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/index-71f5a5dd.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/worker-d3bc0bde.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/wasm_exec.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/Home-f4762739.css
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/qr_code-8c1a238d.jpg
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/logo-b4e095e7.png
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/ColVideoItem-07d4d17c.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/assets/SwiperBanner-530f3655.js
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/
134.122.200.173
malicious
http://aa5aa5aa5aa5aa44.app/console-ban.min.js
134.122.200.173
malicious
https://aawapi-v3.trh999.com/msg_demo/client_config/get
163.181.131.212
https://aawapi-v3.trh999.com/msg_demo/v/pc/video/getAllCategoryVideos
163.181.131.212
https://c.cnzz.com/c.js?web_id=1281366638&t=z
122.225.212.209
http://collect-v6.51.la/v6/collect?dt=4
148.153.240.75
https://quanjing.cnzz.com
unknown
https://webapi.amap.com
unknown
https://v1.cnzz.com/z.js?id=1281366638&async=1
122.225.212.209
http://sdk.51.la/js-sdk-pro.min.js
148.153.240.75
https://aawapi-v3.trh999.com/msg_demo/v/pc/video/category
163.181.131.212
https://z6.cnzz.com/stat.htm?id=1281366638&r=&lg=en-us&ntime=none&cnzz_eid=1701857660-1727417946-&showp=1280x1024&p=http%3A%2F%2Faa5aa5aa5aa5aa44.app%2F&t=%E7%88%B1%E7%88%B1%E7%BD%91&umuuid=19232220dae2bd-07a6196558f62e-26031e51-140000-19232220daf416&h=1
223.109.148.140
http://gaode.com
unknown
http://m.amap.com
unknown
https://www.cnzz.com/stat/website.php?web_id=
unknown
https://webapi.amap.com/maps?callback=___onAPILoaded&v=2.0&key=0f3e523aa49b944f6ae53c488cbae6c3&plugin=
47.246.174.224
https://restapi.amap.com/v3/log/init?platform=JS&s=rsv3&logversion=2.0&product=JsInit&key=0f3e523aa49b944f6ae53c488cbae6c3&t=1727417949472&sdkversion=2.0&appname=http%253A%252F%252Faa5aa5aa5aa5aa44.app%252Fhome&csid=7EF5F9F4-A4F9-4234-B965-6AEE75896E1C&resolution=1280*1024&mob=0&vt=1&dpr=1&scale=1&detect=false&callback=jsonp_463776_1727417949473_
59.82.132.217
https://aawapi-v3.trh999.com/msg_demo/v/pc/video/adList
163.181.131.212
https://aawapi-v3.trh999.com/msg_demo/v/search/hotLists
163.181.131.212
There are 25 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
os30.wagbridge.ingress.amap.com
47.246.174.224
bg.microsoft.map.fastly.net
199.232.210.172
hcdnwsa120.v5.cdnhwczoy106.cn
148.153.240.75
all.cnzz.com.danuoyi.tbcache.com
122.225.212.209
www.google.com
142.250.184.196
aawapi-v3.trh999.com.w.cdngslb.com
163.181.131.212
aa5aa5aa5aa5aa44.app
134.122.200.173
restapi.amap.com.gds.alibabadns.com
59.82.132.217
g952bba.cdn.dakaiwangzhi.com
212.50.235.119
z.gds.cnzz.com
223.109.148.140
_3669._https.cos-v3.024kh.com
unknown
v1.cnzz.com
unknown
cos-v3.024kh.com
unknown
z6.cnzz.com
unknown
webapi.amap.com
unknown
c.cnzz.com
unknown
collect-v6.51.la
unknown
restapi.amap.com
unknown
sdk.51.la
unknown
aawapi-v3.trh999.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.184.196
www.google.com
United States
90.84.161.25
unknown
France
163.181.131.212
aawapi-v3.trh999.com.w.cdngslb.com
United States
163.181.131.215
unknown
United States
47.246.165.44
unknown
United States
203.119.169.174
unknown
China
148.153.240.75
hcdnwsa120.v5.cdnhwczoy106.cn
United States
122.225.212.209
all.cnzz.com.danuoyi.tbcache.com
China
192.168.2.7
unknown
unknown
59.82.132.217
restapi.amap.com.gds.alibabadns.com
China
212.50.235.119
g952bba.cdn.dakaiwangzhi.com
Netherlands
223.109.148.140
z.gds.cnzz.com
China
239.255.255.250
unknown
Reserved
47.246.174.224
os30.wagbridge.ingress.amap.com
United States
134.122.200.173
aa5aa5aa5aa5aa44.app
United States
There are 5 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
http://aa5aa5aa5aa5aa44.app/home
http://aa5aa5aa5aa5aa44.app/home