Shortfy – Smart URL Shortener
Unknown developer
Threat Summary
Key Security Threats
YARA rule match: -SQLInjection
/tmp/extract-2cf8a1ba87b344e5c3bb9be4df8b93d2cdb22d1622e97a8a011da2b28693b632-1601176072/popup.js
YARA rule match: -postinstall_file_manipulation
/tmp/extract-2cf8a1ba87b344e5c3bb9be4df8b93d2cdb22d1622e97a8a011da2b28693b632-1601176072/popup.js
YARA rule match: -AlertStatementsShouldNotBeUsed
/tmp/extract-2cf8a1ba87b344e5c3bb9be4df8b93d2cdb22d1622e97a8a011da2b28693b632-1601176072/popup.js
YARA rule match: -postinstall_file_download
/tmp/extract-2cf8a1ba87b344e5c3bb9be4df8b93d2cdb22d1622e97a8a011da2b28693b632-1601176072/popup.js
YARA rule match: -postinstall_environment_access
/tmp/extract-2cf8a1ba87b344e5c3bb9be4df8b93d2cdb22d1622e97a8a011da2b28693b632-1601176072/popup.js
All Findings (33)
View all 33 security findings
YARA rule match: -SQLInjection
YARA rule match: -postinstall_file_manipulation
YARA rule match: -AlertStatementsShouldNotBeUsed
YARA rule match: -postinstall_file_download
YARA rule match: -postinstall_environment_access
YARA rule match: -postinstall_system_command
YARA rule match: -postinstall_crypto_operations
Network call of type 'fetch' detected.
Network call of type 'fetch' detected.
Network call of type 'fetch' detected.
Network call of type 'fetch' detected.
XIOC detected IP: ::
XIOC detected URL: https://shortfy.xyz';
XIOC detected URL: https://skkhandokar22.pythonanywhere.com/api';
XIOC detected URL: https://api.qrserver.com/v1/create-qr-code/?size=140x140&data=$
XIOC detected URL: https://shortfy.xyz/analytics/$
XIOC detected URL: https://www.google.com/s2/favicons?sz=64&domain=$
XIOC detected Domain: items.map
XIOC detected Domain: item.id
XIOC detected URL: https://clients2.google.com/service/update2/crx
XIOC detected URL: https://skkhandokar22.pythonanywhere.com/*
XIOC detected URL: https://api.qrserver.com/*
XIOC detected URL: https://shortfy.xyz/*
XIOC detected URL: https://shortfy.xyz
XIOC detected Domain: clients2.google.com
XIOC detected Domain: skkhandokar22.pythonanywhere.com
XIOC detected Domain: api.qrserver.com
XIOC detected Domain: shortfy.xyz
XIOC detected Domain: www.google.com
XIOC detected Domain: btn.id
XIOC detected Domain: qrbox.id
Network call of type 'fetch' detected.
Potentially sensitive permission 'tabs' declared in manifest.
Recommended Action
This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.