Unknown developer · 5 users at risk
Threat Summary
Key Security Threats
YARA rule match: -postinstall_file_download
/tmp/extract-78e3ab85e95bed4b070b1034969e057b3f4ba659af82b1de5892d231bbf04a73-3608508712/manifest.json
YARA rule match: -postinstall_file_manipulation
/tmp/extract-78e3ab85e95bed4b070b1034969e057b3f4ba659af82b1de5892d231bbf04a73-3608508712/popup.js
YARA rule match: -postinstall_network_communication
/tmp/extract-78e3ab85e95bed4b070b1034969e057b3f4ba659af82b1de5892d231bbf04a73-3608508712/popup.js
YARA rule match: -postinstall_file_download
/tmp/extract-78e3ab85e95bed4b070b1034969e057b3f4ba659af82b1de5892d231bbf04a73-3608508712/popup.js
YARA rule match: -postinstall_environment_access
/tmp/extract-78e3ab85e95bed4b070b1034969e057b3f4ba659af82b1de5892d231bbf04a73-3608508712/popup.js
All Findings (32)
View all 32 security findings
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_file_manipulation
YARA rule match: -postinstall_network_communication
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_environment_access
YARA rule match: -postinstall_network_communication
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_persistence_mechanism
XIOC detected Domain: cookie.secure
XIOC detected Domain: signingca1.addons.mozilla.org
XIOC detected Domain: input.click
XIOC detected Email: [email protected]
XIOC detected URL: http://addons.mozilla.org/ca/crl.pem0N
XIOC detected URL: http://curl.haxx.se/rfc/cookie_spec.html
XIOC detected URL: https://example.com/cookie-exporter
XIOC detected MD5 Hash: b4bef08b82c037d9cdf14c299bca44c4
XIOC detected Domain: date.now
XIOC detected Domain: browser.downloads.download
Network call of type 'fetch' detected.
XIOC detected Domain: cookie.name
XIOC detected Domain: tab.dataset.tab
XIOC detected Domain: a.download
XIOC detected Domain: a.click
XIOC detected Domain: mozilla.com
XIOC detected Domain: content-signature.mozilla.org
XIOC detected Domain: yourdomain.com
XIOC detected Domain: td693b67f049725b9e12a4614e18b0c31.b4bef08b82c037d9cdf14c299bca44c4.addons.mozilla.org
XIOC detected Domain: q.cx
XIOC detected Domain: curl.haxx.se
XIOC detected Domain: alarm.name
Network call of type 'fetch' detected.
Potentially sensitive permission '<all_urls>' declared in manifest.
Recommended Action
This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.