|
5 | 5 | "analysis": "2", |
6 | 6 | "distribution": "3", |
7 | 7 | "date": "2026-04-19", |
8 | | - "timestamp": "1776578465", |
| 8 | + "timestamp": "1776583381", |
9 | 9 | "published": false, |
10 | 10 | "uuid": "41ef2090-fab5-547e-9eb6-2aa8f195c66f", |
11 | 11 | "Orgc": { |
|
27 | 27 | } |
28 | 28 | ], |
29 | 29 | "Attribute": [ |
| 30 | + { |
| 31 | + "uuid": "70c24c8a-98cf-5284-ad5b-fa87d91fd5a7", |
| 32 | + "type": "text", |
| 33 | + "category": "Other", |
| 34 | + "to_ids": false, |
| 35 | + "value": "nglingapjinhecnfejdcpihlpneeadjp", |
| 36 | + "comment": "OpenClaw Browser Relay | Category: malware | Type: malicious | Browser-control relay extension with local WebSocket/CDP automation - third-party depreciated package for openclaw. Added for enterprise blocklist - not as confirmed malware", |
| 37 | + "distribution": "5", |
| 38 | + "Tag": [ |
| 39 | + { |
| 40 | + "name": "extsentry:category=\"malware\"" |
| 41 | + }, |
| 42 | + { |
| 43 | + "name": "extsentry:type=\"malicious\"" |
| 44 | + } |
| 45 | + ] |
| 46 | + }, |
| 47 | + { |
| 48 | + "uuid": "b1b797e3-c239-5fab-acb2-81729019cbff", |
| 49 | + "type": "sha256", |
| 50 | + "category": "Payload delivery", |
| 51 | + "to_ids": true, |
| 52 | + "value": "133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f", |
| 53 | + "comment": "CRX file hash for OpenClaw Browser Relay (nglingapjinhecnfejdcpihlpneeadjp)", |
| 54 | + "distribution": "5", |
| 55 | + "Tag": [ |
| 56 | + { |
| 57 | + "name": "extsentry:category=\"malware\"" |
| 58 | + }, |
| 59 | + { |
| 60 | + "name": "extsentry:type=\"malicious\"" |
| 61 | + } |
| 62 | + ] |
| 63 | + }, |
30 | 64 | { |
31 | 65 | "uuid": "29bf0cc7-d0c4-590a-aa90-17e47e6ff02d", |
32 | 66 | "type": "text", |
|
32108 | 32142 | } |
32109 | 32143 | ], |
32110 | 32144 | "Object": [ |
| 32145 | + { |
| 32146 | + "uuid": "daf46dee-21fe-5199-b2d4-cf680a33455f", |
| 32147 | + "name": "annotation", |
| 32148 | + "meta-category": "misc", |
| 32149 | + "description": "Suspicious/Malicious browser extension: OpenClaw Browser Relay", |
| 32150 | + "template_uuid": "e434b304-a905-53fb-b7df-1d552e338795", |
| 32151 | + "template_version": "1", |
| 32152 | + "Attribute": [ |
| 32153 | + { |
| 32154 | + "object_relation": "text", |
| 32155 | + "type": "text", |
| 32156 | + "value": "nglingapjinhecnfejdcpihlpneeadjp", |
| 32157 | + "comment": "Browser Extension ID", |
| 32158 | + "to_ids": false |
| 32159 | + }, |
| 32160 | + { |
| 32161 | + "object_relation": "text", |
| 32162 | + "type": "text", |
| 32163 | + "value": "OpenClaw Browser Relay", |
| 32164 | + "comment": "Extension Name", |
| 32165 | + "to_ids": false |
| 32166 | + }, |
| 32167 | + { |
| 32168 | + "object_relation": "text", |
| 32169 | + "type": "text", |
| 32170 | + "value": "malware", |
| 32171 | + "comment": "Threat Category", |
| 32172 | + "to_ids": false |
| 32173 | + }, |
| 32174 | + { |
| 32175 | + "object_relation": "text", |
| 32176 | + "type": "text", |
| 32177 | + "value": "malicious", |
| 32178 | + "comment": "Threat Type", |
| 32179 | + "to_ids": false |
| 32180 | + }, |
| 32181 | + { |
| 32182 | + "object_relation": "text", |
| 32183 | + "type": "sha256", |
| 32184 | + "value": "133df5ad1bd5f3c5444fc6bf15040b34372dd309d7481be708ae6445c3a20c6f", |
| 32185 | + "comment": "CRX File SHA-256", |
| 32186 | + "to_ids": true |
| 32187 | + }, |
| 32188 | + { |
| 32189 | + "object_relation": "text", |
| 32190 | + "type": "link", |
| 32191 | + "value": "https://chromewebstore.google.com/detail/openclaw-browser-relay/nglingapjinhecnfejdcpihlpneeadjp", |
| 32192 | + "comment": "Reference URL", |
| 32193 | + "to_ids": false |
| 32194 | + } |
| 32195 | + ] |
| 32196 | + }, |
32111 | 32197 | { |
32112 | 32198 | "uuid": "f089e386-fca0-5989-9c52-16c036681cbb", |
32113 | 32199 | "name": "annotation", |
|
0 commit comments