Windows Analysis Report
https://okefeokok.live/

Overview

General Information

Sample URL: https://okefeokok.live/
Analysis ID: 1523620
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected ZipBomb
HTML body with high number of embedded images detected
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)

Classification

Source: https://sfdawe.buzz/#/home HTTP Parser: Total embedded image size: 22538
Source: https://906fdd.seeaa.top/mq19xv HTTP Parser: Total embedded image size: 47140
Source: https://cctv.49zs.vip/#/home HTTP Parser: Total embedded image size: 22538
Source: https://sfdawe.buzz/static/js/common.js HTTP Parser: var __defprop=object.defineproperty,__defnormalprop=(e,t,o)=>t in e?__defprop(e,t,{enumerable:!0,configurable:!0,writable:!0,value:o}):e[t]=o,__publicfield=(e,t,o)=>(__defnormalprop(e,"symbol"!=typeof t?t+"":t,o),o);function makemap(e,t){const o=object.create(null),n=e.split(",");for(let r=0;r<n.length;r++)o[n[r]]=!0;return t?e=>!!o[e.tolowercase()]:e=>!!o[e]}function normalizestyle(e){if(isarray$2(e)){const t={};for(let o=0;o<e.length;o++){const n=e[o],r=isstring$1(n)?parsestringstyle(n):normalizestyle(n);if(r)for(const e in r)t[e]=r[e]}return t}return isstring$1(e)||isobject$2(e)?e:void 0}!function(){const e=document.createelement("link").rellist;if(!(e&&e.supports&&e.supports("modulepreload"))){for(const e of document.queryselectorall('link[rel="modulepreload"]'))t(e);new mutationobserver((e=>{for(const o of e)if("childlist"===o.type)for(const e of o.addednodes)"link"===e.tagname&&"modulepreload"===e.rel&&t(e)})).observe(document,{childlist:!0,subtree:!0})}function t(e){if(e.ep)return;e.ep=!0;const t=funct...
Source: https://906fdd.seeaa.top/mq19xv HTTP Parser: No favicon
Source: https://906fdd.seeaa.top/mq19xv HTTP Parser: No favicon
Source: https://www.qq.com/ HTTP Parser: No favicon
Source: https://www.qq.com/ HTTP Parser: No favicon
Source: https://www.qq.com/ HTTP Parser: No favicon
Source: https://www.qq.com/ HTTP Parser: No favicon
Source: chromecache_960.2.dr String found in binary or memory: http://beian.miit.gov.cn/
Source: chromecache_392.2.dr String found in binary or memory: http://developer.yahoo.com/yui/license.html
Source: chromecache_1177.2.dr, chromecache_392.2.dr String found in binary or memory: http://feross.org
Source: chromecache_960.2.dr String found in binary or memory: http://ga.sz.gov.cn
Source: chromecache_960.2.dr String found in binary or memory: http://inews.gtimg.com/newsapp_bt/0/15822141894/0
Source: chromecache_960.2.dr String found in binary or memory: http://inews.gtimg.com/newsapp_bt/0/15822141895/0
Source: chromecache_960.2.dr String found in binary or memory: http://inews.gtimg.com/newsapp_bt/0/15822141896/0
Source: chromecache_960.2.dr String found in binary or memory: http://jedwatson.github.io/classnames
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/1692586939507318556/243
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/1709089079042065775/243
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/1715226009591150348/243
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/1722457501519154857/0
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/1722567344205153231/0
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/WjWdV6ozMhLPHXhiaw6icASg_1673112041791173000/76
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/_1719538566123895398/76
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/_1723774626903263646/76
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/_1724405372540082665/76
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/_1727691122055119525/76
Source: chromecache_494.2.dr String found in binary or memory: http://p.qpic.cn/user_pic/0/_1727693931640360550/76
Source: chromecache_960.2.dr String found in binary or memory: http://szwljb.sz.gov.cn/
Source: chromecache_1171.2.dr, chromecache_972.2.dr String found in binary or memory: http://time.qq.com/?pgv_ref=ad
Source: chromecache_960.2.dr String found in binary or memory: http://underscorejs.org/LICENSE
Source: chromecache_1171.2.dr, chromecache_972.2.dr String found in binary or memory: http://users.qq.com
Source: chromecache_960.2.dr String found in binary or memory: http://www.beian.gov.cn/portal/registerSystemInfo?recordcode=44030002000001
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: http://www.openssl.org/support/faq.html
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: http://www.openssl.org/support/faq.htmldual
Source: chromecache_756.2.dr String found in binary or memory: https://906fdd.seeaa.top/api/download/apk/?apkUrl=http://hgq2req4f569.tyy789.top/KMR835.apk&param=xn
Source: chromecache_960.2.dr String found in binary or memory: https://ads.privacy.qq.com/ads/adoptout.html?media_source=113001
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: https://android.googlesource.com/toolchain/clang
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: https://android.googlesource.com/toolchain/llvm
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: https://android.googlesource.com/toolchain/llvm-project
Source: chromecache_756.2.dr String found in binary or memory: https://c1elbgk.slyvvscpae.com/data/info
Source: chromecache_960.2.dr String found in binary or memory: https://careers.tencent.com/
Source: chromecache_1091.2.dr, chromecache_392.2.dr String found in binary or memory: https://clipboardjs.com/
Source: chromecache_756.2.dr String found in binary or memory: https://d2cyx94bat91jh.cloudfront.net
Source: chromecache_756.2.dr String found in binary or memory: https://d2lvrxij0tja0q.cloudfront.net/website-images/0lg5fnkedxteq9v6_icon.png?X-Amz-Algorithm=AWS4-
Source: chromecache_1085.2.dr, chromecache_323.2.dr String found in binary or memory: https://devtools.vuejs.org/guide/installation.html.
Source: chromecache_960.2.dr String found in binary or memory: https://feross.org
Source: chromecache_1177.2.dr, chromecache_392.2.dr String found in binary or memory: https://feross.org/opensource
Source: chromecache_960.2.dr String found in binary or memory: https://gdca.miit.gov.cn/
Source: chromecache_1177.2.dr String found in binary or memory: https://github.com/emn178/js-md5
Source: chromecache_364.2.dr String found in binary or memory: https://github.com/zloirock/core-js
Source: chromecache_364.2.dr String found in binary or memory: https://github.com/zloirock/core-js/blob/v3.37.1/LICENSE
Source: chromecache_960.2.dr String found in binary or memory: https://gongyi.qq.com/
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/news_bt/O5SGzcBSKaRHqXCvWbwGJhZUdLESA-Kwk6fzeVvMzM_gQAA/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/news_ls/OXSYIo3dwaIFzrne9Ph_yZkHyMxoJocmGjNhg0eaW67G8AA_200200/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/news_ls/OaTQXzSTeGVsgMD7U5Ye-6cVblW3l89VnLlcVZFEWD9vAAA/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/news_ls/Ofug9iT5S30k5BHmzYYXVHHwU_0WPisAmdK7l-X--ccI0AA_200200/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/news_ls/OkomnhSVtg3-UYHR5zp7U9wS08iQ3pLtvgAm2FQcXr9zAAA_200200/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/news_ls/OxeWHKJiBulUzh4DLwbXHNwOUzplPolVaauAf-8IYxxmoAA_200200/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0426124454168_4788/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0511155854519_5325/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0515145728138_9808/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0522113150470_328/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0522140749102_9238/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0522140829891_9683/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0522145509890_5775/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0523085844336_5864/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0530120609137_1607/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0530120609344_1814/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0530120609625_2095/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0609172256937_279/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0609172307189_445/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/060917231414_7270/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0609172322959_6129/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0609172712129_3321/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0613150938895_706/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0703113132826_1260/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/070311313312_1446/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/070311313370_1504/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0722104411591_6917/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/091822593172_5129/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0924171733768_8784/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/0924172023710_7265/0
Source: chromecache_960.2.dr String found in binary or memory: https://inews.gtimg.com/newsapp_bt/0/102416082070_174/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O0_8A-Ka3CIjX_N3KyVPpV3PbuJHw1rgyp7yfqRCBNfXsAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O3S7T1HgNPv--yj6OlT4Rn-NLxeOkAqmOjLNlsuclwjo0AA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O5m9s101uUohdVU_rxnojqmi4rar0mn5KYd6OqsXWmIxoAA_200200/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O7UWHU9_t6SWfhjZkvplk_hqG9iGMayKzF4R9dLJE9MgYAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O9Ezi4Jkam_VdHh1KLUARaWJRtOP2KmN3hj9qUgeDCuPwAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O9xwK7DGhWGMejMAs-sfCiUxFySKYMYVwKRtAmQvc2mS0AA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OJLS7gqn4xgG6LFmBlxhTtxHq8RQiGItvewbRXhTSNp2QAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OOsl6SQ6siP9xEMmCBHhB3XkoibZ5r-4ffCg-d6eS89GwAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/ORrPtr_-qMr16ZLeejXaRT9KuLsVaMmhbhYVdt0_jTJJsAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OUq40QpGFr8uWDL7kkb0eOfLDfZ5H9BTzAvD3BX4w10UwAA_200200/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OXQD5DwuFHf0rwXUEul67vo0aWSupxZPBgUd3obSrdjWsAA_200200/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OZ7bzhCV2W2sLeYqfTlF4McZFTSpXY3nIvP6BqZxy7wgoAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/O_UJufD0rRSRwm66Rbsm6Q1yfmFJ4uWQDP6XKdAzNyYXkAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OfGK3Ebsc5ImawpcatwvIfhJiye1rt3lbUwAr0C4e4gOEAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OgBaVpFsr33DWw-bPDelUD8rAnYh721rb8uweAT41X-dsAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OgspyamkdCsPj1Mbq7VQYUeaVNohlB8cO7aqTnoyKRcjkAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OhVyMYTlf6cW-L8lD_9NiFC_AOlLgdxVHoR2ZqnD3YkAYAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OlYes1SvqBPd1GLM4Ku8b1ULjoFkBnolMjvAFyDYQAxZcAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/Om75ZblG4XmkxvMaBf5n9t8DZn7DcdXyJ-Qn8J2ldqyQgAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OnQ6ubSjZrxn8rbLzVm8fq7S0xiTEPTnUCsgjcjKv6ve0AA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OqaWiD5akmiREjcl4hEfL2x1YktoG4gWbDHm-sZ5YFnCQAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OqgmLnE2rkcnh0-VeotacwkXqKmSRLkVfDnZj3uOVQpfIAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OtD-AqLtRKO5TEJXQv9nTXXWU1ofzvJL-Z9slg3ohS_tEAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/Ots14m0VpIwWZNeLc8fP-FHCoF7ogusdoK4Baq8x7iEhMAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OvR_VAGRbFFHG7cdzSiYaoeEbf4yP2T55YsT7BODAGDhsAA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/Ow2-Ytj6lzB7_TZUs8YMlqAsHp_f4x5h9stuZ1uWOTrr4AA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OwuBr_dCc9LPoewdGXrGT3Y3ljp5nJ17DYF-IHDob2zV0AA_294195/0
Source: chromecache_494.2.dr String found in binary or memory: https://inews.gtimg.com/om_ls/OxZJ-X2SFoFrC4BZ7c3zShBr6nIu2pGxkhR7GdiFrRDUcAA_294195/0
Source: chromecache_960.2.dr String found in binary or memory: https://kf.qq.com/
Source: chromecache_392.2.dr String found in binary or memory: https://kjur.github.io/jsrsasign/license/
Source: chromecache_960.2.dr String found in binary or memory: https://lodash.com/
Source: chromecache_960.2.dr String found in binary or memory: https://lodash.com/license
Source: chromecache_960.2.dr String found in binary or memory: https://mail.qq.com/
Source: chromecache_960.2.dr String found in binary or memory: https://mat1.gtimg.com/qqcdn/tupload/1708573978453.png
Source: chromecache_756.2.dr String found in binary or memory: https://mu6d0lt.fayinmei.com/ability/3mq19xv
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/mobile/
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q01AL600
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q01D4G00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q01D6Q00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q02Z0P00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q03GPA00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q03JM400
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q03Z9C00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q04IX500
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q04MVD00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q065PL00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q0877A00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q087JU00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q08E7800
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q08Z8I00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q0AAPU00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q0AAXO00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q0AB3M00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20240930Q0AFO100
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q0096P00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q022Z800
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q02XH100
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q032KJ00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q0375400
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q043OA00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q04PJL00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q05DU500
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q05UBO00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q05VVQ00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q078WZ00
Source: chromecache_494.2.dr String found in binary or memory: https://new.qq.com/rain/a/20241001Q07CHZ00
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/bjhlwfyflfwgzz.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/cbst.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/contract.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/copyright.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/culture.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/dzwfggcns.htm
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/icp2.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/internet_licence.htm
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/scio.htm
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/static/xwdz.shtml
Source: chromecache_960.2.dr String found in binary or memory: https://new.qq.com/sv1/app/agreement_android.html
Source: chromecache_960.2.dr String found in binary or memory: https://news.qq.com/
Source: chromecache_960.2.dr String found in binary or memory: https://news.qq.com/mobile
Source: chromecache_972.2.dr String found in binary or memory: https://news.qq.com/mobile/index.htm
Source: chromecache_960.2.dr String found in binary or memory: https://open.qq.com/
Source: chromecache_960.2.dr String found in binary or memory: https://openjsf.org/
Source: chromecache_323.2.dr String found in binary or memory: https://pinia.vuejs.org
Source: chromecache_323.2.dr String found in binary or memory: https://pinia.vuejs.org/logo.svg
Source: chromecache_960.2.dr String found in binary or memory: https://privacy.qq.com/document/priview/4bd0bd84be654afe8c1a545ea9b64ec8
Source: chromecache_960.2.dr String found in binary or memory: https://privacy.qq.com/mb/policy/tencent-privacypolicy
Source: chromecache_960.2.dr String found in binary or memory: https://qq.com
Source: chromecache_1171.2.dr, chromecache_972.2.dr String found in binary or memory: https://ra.gtimg.com/web/default_fodders/
Source: chromecache_1171.2.dr, chromecache_972.2.dr String found in binary or memory: https://ra.gtimg.com/web/default_fodders/1400x90_www.png
Source: chromecache_1171.2.dr, chromecache_972.2.dr String found in binary or memory: https://ra.gtimg.com/web/default_fodders/920x75_www.png
Source: chromecache_1171.2.dr, chromecache_972.2.dr String found in binary or memory: https://ra.gtimg.com/web/default_fodders/920x90_www.png
Source: chromecache_960.2.dr String found in binary or memory: https://sports.qq.com/
Source: chromecache_960.2.dr String found in binary or memory: https://sports3.gtimg.com/nationalFlag/26.png/0
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: https://support.google.com/chromecastbuiltin/answer/3006709
Source: KMR835.apk.crdownload.0.dr String found in binary or memory: https://support.google.com/chromecastbuiltin/answer/3006709&H
Source: chromecache_960.2.dr String found in binary or memory: https://support.qq.com/products/2198
Source: chromecache_494.2.dr String found in binary or memory: https://thirdwx.qlogo.cn/mmopen/vi_32/gHqcrBnVxibdUKIuypddYiaHYdiaAP5Vllbyib0ruquicwRjjfYHtEZ0HDGxs0
Source: chromecache_960.2.dr String found in binary or memory: https://v.qq.com/
Source: chromecache_960.2.dr String found in binary or memory: https://view.inews.qq.com/
Source: chromecache_364.2.dr String found in binary or memory: https://www.jsdelivr.com/using-sri-with-dynamic-files
Source: chromecache_960.2.dr String found in binary or memory: https://www.tencent.com/en-us/index.html
Source: chromecache_960.2.dr String found in binary or memory: https://www.tencent.com/zh-cn/
Source: chromecache_960.2.dr String found in binary or memory: https://www.tencent.com/zh-cn/partnership.html
Source: chromecache_323.2.dr String found in binary or memory: https://x1.$
Source: chromecache_323.2.dr String found in binary or memory: https://x2.$
Source: chromecache_323.2.dr String found in binary or memory: https://x3.$
Source: chromecache_323.2.dr String found in binary or memory: https://x4.$
Source: chromecache_323.2.dr String found in binary or memory: https://x5.$
Source: classification engine Classification label: mal48.evad.win@27/1340@0/46
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\Downloads\c09a2750-9c02-469c-b9b5-3d96bac2e44f.tmp Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5224:120:WilError_03
Source: C:\Windows\System32\OpenWith.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2084,i,12269707295863670503,4330667601123277937,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://okefeokok.live/"
Source: unknown Process created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7008 --field-trial-handle=2084,i,12269707295863670503,4330667601123277937,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2084,i,12269707295863670503,4330667601123277937,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7008 --field-trial-handle=2084,i,12269707295863670503,4330667601123277937,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinui.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: pdh.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: actxprxy.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.appdefaults.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.immersive.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: dui70.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: duser.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: uianimation.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.ui.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: inputhost.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: thumbcache.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: tiledatarepository.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: staterepository.core.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.staterepository.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: windows.staterepositorycore.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: mrmcorer.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: directmanipulation.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: C:\Users\user\Downloads\c09a2750-9c02-469c-b9b5-3d96bac2e44f.tmp, type: DROPPED
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs