IOC Report
https://www.realme.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 05:27:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 05:27:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 05:27:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 05:27:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 05:27:07 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 212
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 213
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 214
RIFF (little-endian) data, Web/P image, VP8 encoding, 3840x1300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 215
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 216
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 217
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 218
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 219
RIFF (little-endian) data, Web/P image, VP8 encoding, 1080x1080, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 220
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 221
Unicode text, UTF-8 text, with very long lines (65441), with CRLF line terminators
downloaded
Chrome Cache Entry: 222
RIFF (little-endian) data, Web/P image, VP8 encoding, 920x920, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 223
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 224
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 225
ASCII text, with very long lines (20679)
dropped
Chrome Cache Entry: 226
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 227
RIFF (little-endian) data, Web/P image, VP8 encoding, 1404x960, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 228
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 229
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 230
RIFF (little-endian) data, Web/P image, VP8 encoding, 1180x1328, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 231
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 232
PNG image data, 422 x 640, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 233
ASCII text, with very long lines (65449)
downloaded
Chrome Cache Entry: 234
RIFF (little-endian) data, Web/P image, VP8 encoding, 1404x960, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 235
RIFF (little-endian) data, Web/P image, VP8 encoding, 920x920, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 236
RIFF (little-endian) data, Web/P image, VP8 encoding, 1184x640, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 237
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 238
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 239
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 240
RIFF (little-endian) data, Web/P image, VP8 encoding, 920x920, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 241
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 242
RIFF (little-endian) data, Web/P image, VP8 encoding, 1180x1328, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 243
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 244
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 245
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 246
ASCII text, with very long lines (4345)
dropped
Chrome Cache Entry: 247
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 248
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 249
PNG image data, 422 x 640, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 250
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 251
TrueType Font data, digitally signed, 19 tables, 1st "DSIG", 26 names, Macintosh, Digitized data copyright \251 2010-2011, Google Corporation.Open SansRegularAscender - Open Sans
downloaded
Chrome Cache Entry: 252
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 253
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 254
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 255
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 256
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 257
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (65284)
downloaded
Chrome Cache Entry: 259
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 260
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 261
Unicode text, UTF-8 text, with very long lines (65409), with no line terminators
downloaded
Chrome Cache Entry: 262
RIFF (little-endian) data, Web/P image, VP8 encoding, 702x480, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 263
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 264
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 265
Unicode text, UTF-8 text, with very long lines (65409), with no line terminators
dropped
Chrome Cache Entry: 266
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 267
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 268
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 269
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 270
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 271
ASCII text, with very long lines (2343)
dropped
Chrome Cache Entry: 272
RIFF (little-endian) data, Web/P image, VP8 encoding, 1440x1440, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 273
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 274
Unicode text, UTF-8 text, with very long lines (65441), with CRLF line terminators
dropped
Chrome Cache Entry: 275
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 277
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 278
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 279
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 280
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 281
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 282
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 283
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 284
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 285
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 286
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 287
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 288
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 289
RIFF (little-endian) data, Web/P image, VP8 encoding, 1184x640, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 290
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 291
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 292
ASCII text, with very long lines (4345)
downloaded
Chrome Cache Entry: 293
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 294
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 295
RIFF (little-endian) data, Web/P image, VP8 encoding, 1080x1080, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 296
RIFF (little-endian) data, Web/P image, VP8 encoding, 1184x640, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 297
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 298
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 299
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 300
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 301
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 302
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 303
ASCII text, with very long lines (65284)
dropped
Chrome Cache Entry: 304
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 305
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 306
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 307
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 308
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 309
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 311
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 312
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 313
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 314
ASCII text, with very long lines (20679)
downloaded
Chrome Cache Entry: 315
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 316
RIFF (little-endian) data, Web/P image, VP8 encoding, 1184x640, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 317
RIFF (little-endian) data, Web/P image, VP8 encoding, 3840x1300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (65449)
dropped
Chrome Cache Entry: 319
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (46742)
dropped
Chrome Cache Entry: 321
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 322
Unicode text, UTF-8 text, with very long lines (65505), with no line terminators
downloaded
Chrome Cache Entry: 323
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 324
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 325
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 326
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 327
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 328
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 329
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 330
TrueType Font data, digitally signed, 19 tables, 1st "DSIG", 30 names, Macintosh, Digitized data copyright \251 2011, Google Corporation.Open Sans SemiboldRegularAscender - Open
downloaded
Chrome Cache Entry: 331
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 332
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 333
Unicode text, UTF-8 text, with very long lines (65505), with no line terminators
dropped
Chrome Cache Entry: 334
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 335
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 336
RIFF (little-endian) data, Web/P image, VP8 encoding, 920x920, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 337
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 338
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 339
RIFF (little-endian) data, Web/P image, VP8 encoding, 702x480, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 340
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 341
ASCII text, with very long lines (46742)
downloaded
Chrome Cache Entry: 342
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 343
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 344
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 345
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 346
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 347
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 348
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 349
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 350
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 351
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 352
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 353
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 354
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 355
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 356
ASCII text, with very long lines (16215)
downloaded
Chrome Cache Entry: 357
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 358
RIFF (little-endian) data, Web/P image, VP8 encoding, 3840x1300, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 359
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 360
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 361
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 362
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 363
RIFF (little-endian) data, Web/P image, VP8 encoding, 1440x1440, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
There are 148 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=1972,i,3179036088240847159,15598012822748502770,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.realme.com"

URLs

Name
IP
Malicious
https://www.realme.com
https://www.clarity.ms/tag/kgh4f17dqf
13.107.246.67
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://stats.g.doubleclick.net/g/collect
unknown
https://test2-api.myoas.net/
unknown
https://api.realme.com/global/one/key/gray/get?source=2
52.47.130.115
https://test.myoas.net/
unknown
https://pre-buy.realme.com/
unknown
https://pre-3w.realme.com/
unknown
https://test2-buy.myoas.net/
unknown
https://googleads.g.doubleclick.net
unknown
https://tagassistant.google.com/
unknown
https://api.realme.com/cn/auth/login
52.47.130.115
https://ampcid.google.com/v1/publisher:getClientId
unknown
https://api.realme.com/
unknown
https://buy.realme.com/
unknown
https://cct.google/taggy/agent.js
unknown
https://swiperjs.com
unknown
https://www.realme.com/global/
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htmlLicensed
unknown
https://test2.myoas.net/
unknown
https://www.google.com/ads/ga-audiences
unknown
https://www.google.%/ads/ga-audiences
unknown
https://td.doubleclick.net
unknown
https://api.realme.com/global/official/website/flash
52.47.130.115
http://www.apache.org/licenses/LICENSE-2.0Digitized
unknown
https://connect.facebook.net/en_US/fbevents.js
unknown
https://www.realme.com/
unknown
https://www.merchant-center-analytics.goog
unknown
https://github.com/krux/postscribe/blob/master/LICENSE.
unknown
https://stats.g.doubleclick.net/j/collect
unknown
https://www.clarity.ms/s/0.7.47/clarity.js
13.107.246.67
https://google.com
unknown
https://pre-api.realme.com/
unknown
https://api.realme.com/global/official/website/online-offer
52.47.130.115
https://github.com/microsoft/clarity
unknown
https://test1-api.myoas.net/
unknown
https://adservice.google.com/pagead/regclk?
unknown
https://test-buy.myoas.net/
unknown
There are 30 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.132
s-part-0039.t-0009.t-msedge.net
13.107.246.67
par-public-realmecom-pubgw-38256589.eu-west-3.elb.amazonaws.com
52.47.130.115
api.realme.com
unknown
r2.realme.net
unknown
www.clarity.ms
unknown
t.clarity.ms
unknown
www.realme.com
unknown
static.realme.net
unknown
image01.realme.net
unknown
c.clarity.ms
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.67
s-part-0039.t-0009.t-msedge.net
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
192.168.2.16
unknown
unknown
52.47.130.115
par-public-realmecom-pubgw-38256589.eu-west-3.elb.amazonaws.com
United States
142.250.185.132
www.google.com
United States
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://www.realme.com/global/
https://www.realme.com/global/
https://www.realme.com/global/
https://www.realme.com/global/
https://www.realme.com/global/