页面伪装者 (保护隐私)
Unknown developer · 2 users at risk
Threat Summary
Key Security Threats
YARA rule match: -postinstall_obfuscation
/tmp/extract-719ba482d1eed8c1e7649e21fa3bcb60a00e5dbc53a29c0aea5a1bb3d56673e4-483069253/background.js
YARA rule match: -postinstall_persistence_mechanism
/tmp/extract-719ba482d1eed8c1e7649e21fa3bcb60a00e5dbc53a29c0aea5a1bb3d56673e4-483069253/background.js
YARA rule match: -postinstall_system_command
/tmp/extract-719ba482d1eed8c1e7649e21fa3bcb60a00e5dbc53a29c0aea5a1bb3d56673e4-483069253/background.js
YARA rule match: -postinstall_file_download
/tmp/extract-719ba482d1eed8c1e7649e21fa3bcb60a00e5dbc53a29c0aea5a1bb3d56673e4-483069253/background.js
YARA rule match: -postinstall_network_communication
/tmp/extract-719ba482d1eed8c1e7649e21fa3bcb60a00e5dbc53a29c0aea5a1bb3d56673e4-483069253/background.js
All Findings (33)
View all 33 security findings
YARA rule match: -postinstall_obfuscation
YARA rule match: -postinstall_persistence_mechanism
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_network_communication
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_crypto_operations
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_system_command
XIOC detected IP: ::af
XIOC detected Domain: clients2.google.com
XIOC detected Domain: toast.show
XIOC detected Domain: parts.map
XIOC detected URL: https://www.baidu.com/';
XIOC detected IP: ::bef
XIOC detected Domain: www.baidu.com
XIOC detected Domain: tab.id
XIOC detected Domain: iframe.id
XIOC detected Domain: date.now
XIOC detected Domain: fakeicon.id
XIOC detected Domain: sender.tab
XIOC detected Domain: e.target
XIOC detected Domain: apple.com
XIOC detected Domain: sender.tab.id
XIOC detected URL: https://URL.',
XIOC detected URL: https://URL.
XIOC detected URL: https://clients2.google.com/service/update2/crx
Potentially sensitive permission 'tabs' declared in manifest.
Network call of type 'fetch' detected.
Network call of type 'fetch' detected.
Recommended Action
This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.