Click to jump to signature section
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49710 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49725 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49726 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49728 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49733 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49734 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49735 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49737 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:49749 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49752 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49798 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49799 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49801 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49800 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49802 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49804 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49819 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49820 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49824 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49825 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49823 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49822 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49838 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49840 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49842 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49850 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49849 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49851 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49852 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49854 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49859 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.4:443 -> 192.168.2.18:49860 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49904 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49906 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49907 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:49908 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 142.250.185.132:443 -> 192.168.2.18:50016 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.86.4.65:443 -> 192.168.2.18:50071 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.86.4.65:443 -> 192.168.2.18:50073 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.33.187.25:443 -> 192.168.2.18:50076 version: TLS 1.2 |
Source: C:\Windows\System32\msiexec.exe | File opened: z: |
Source: C:\Windows\System32\msiexec.exe | File opened: x: |
Source: C:\Windows\System32\msiexec.exe | File opened: v: |
Source: C:\Windows\System32\msiexec.exe | File opened: t: |
Source: C:\Windows\System32\msiexec.exe | File opened: r: |
Source: C:\Windows\System32\msiexec.exe | File opened: p: |
Source: C:\Windows\System32\msiexec.exe | File opened: n: |
Source: C:\Windows\System32\msiexec.exe | File opened: l: |
Source: C:\Windows\System32\msiexec.exe | File opened: j: |
Source: C:\Windows\System32\msiexec.exe | File opened: h: |
Source: C:\Windows\System32\msiexec.exe | File opened: f: |
Source: C:\Windows\System32\msiexec.exe | File opened: b: |
Source: C:\Windows\System32\msiexec.exe | File opened: y: |
Source: C:\Windows\System32\msiexec.exe | File opened: w: |
Source: C:\Windows\System32\msiexec.exe | File opened: u: |
Source: C:\Windows\System32\msiexec.exe | File opened: s: |
Source: C:\Windows\System32\msiexec.exe | File opened: q: |
Source: C:\Windows\System32\msiexec.exe | File opened: o: |
Source: C:\Windows\System32\msiexec.exe | File opened: m: |
Source: C:\Windows\System32\msiexec.exe | File opened: k: |
Source: C:\Windows\System32\msiexec.exe | File opened: i: |
Source: C:\Windows\System32\msiexec.exe | File opened: g: |
Source: C:\Windows\System32\msiexec.exe | File opened: e: |
Source: C:\Windows\System32\msiexec.exe | File opened: c: |
Source: C:\Windows\System32\msiexec.exe | File opened: a: |
Source: chrome.exe | Memory has grown: Private usage: 11MB later: 35MB |
Source: Network traffic | Suricata IDS: 2829202 - Severity 1 - ETPRO MALWARE MSIL/Zbrain PUP/Stealer Installer UA : 192.168.2.18:50090 -> 143.204.98.82:80 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.185.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.185.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.19.122.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.77.188 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.77.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.77.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.131 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=ones&oit=1&cp=4&pgcl=2&gs_rn=42&psi=N78ND-Zk1Y-znKZ1&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=onest&oit=1&cp=5&pgcl=2&gs_rn=42&psi=N78ND-Zk1Y-znKZ1&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=onesta&oit=1&cp=6&pgcl=2&gs_rn=42&psi=N78ND-Zk1Y-znKZ1&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=onestar&oit=1&cp=7&pgcl=2&gs_rn=42&psi=N78ND-Zk1Y-znKZ1&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=onestart&oit=1&cp=8&pgcl=2&gs_rn=42&psi=N78ND-Zk1Y-znKZ1&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /search?q=onestart&oq=onestart&pf=cs&sourceid=chrome&ie=UTF-8 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Purpose: prefetchSec-Purpose: prefetchAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Browser-Channel: stableX-Browser-Year: 2025X-Browser-Validation: wTKGXmLo+sPWz1JKKbFzUyHly1Q=X-Browser-Copyright: Copyright 2025 Google LLC. All rights reserved.X-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=onestart.&oit=1&cp=9&pgcl=2&gs_rn=42&psi=N78ND-Zk1Y-znKZ1&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CPyDywE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: AEC=AVcja2fviLCaI8Xa-yJyp8rD2OyYY1LmERRciMAHHxZK7lqEXGhHWFJcHS4; NID=522=iIdDSwrT7CRhsXJhKyTIXiANhlr1fXnXUY5u1JUhcO54BYuvo-Lp2wKR8MUwTrFDwuzAJl8lcfEK1aozjM7tzW24_UkyLxoyZnZe1k7bxYj0bMnOK41LL1GQo1LtK1_n9fSxZtgE9NOGbrWtodSzEltQMwFG8jheWoX5hoeiMgEQ8aSBnIo4IJhePApUxDgcvKQG5-qkHVCj43I |
Source: global traffic | HTTP traffic detected: GET /search?q=onestart&oq=onestart&gs_lcrp=EgZjaHJvbWUyDAgAEEUYORixAxiABDIHCAEQABiABDIHCAIQABiABDIHCAMQABiABDIHCAQQABiABDIHCAUQABiABDIHCAYQABiABDIHCAcQABiABDIHCAgQABiABDIHCAkQABiABKgCALACAQ&sourceid=chrome&ie=UTF-8&sei=4SXYZ9mHKrn87_UPvLPW6Q8 HTTP/1.1Host: www.google.comConnection: keep-alivertt: 300downlink: 0.45sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-full-version: "134.0.6998.36"sec-ch-ua-arch: "x86"sec-ch-ua-platform: "Windows"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-model: ""sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-full-version-list: "Chromium";v="134.0.6998.36", "Not:A-Brand";v="24.0.0.0", "Google Chrome";v="134.0.6998.36"sec-ch-ua-form-factors: "Desktop"sec-ch-prefers-color-scheme: lightUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Sec-Purpose: prefetch;prerenderPurpose: prefetchAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7X-Browser-Channel: stableX-Browser-Year: 2025X-Browser-Validation: wTKGXmLo+sPWz1JKKbFzUyHly1Q=X-Browser-Copyright: Copyright 2025 Google LLC. All rights reserved.X-Client-Data: CPyDywE=Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.google.com/search?q=onestart&oq=onestart&gs_lcrp=EgZjaHJvbWUyDAgAEEUYORixAxiABDIHCAEQABiABDIHCAIQABiABDIHCAMQABiABDIHCAQQABiABDIHCAUQABiABDIHCAYQABiABDIHCAcQABiABDIHCAgQABiABDIHCAkQABiABKgCALACAQ&sourceid=chrome&ie=UTF-8Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: AEC=AVcja2fviLCaI8Xa-yJyp8rD2OyYY1LmERRciMAHHxZK7lqEXGhHWFJcHS4; NID=522=iIdDSwrT7CRhsXJhKyTIXiANhlr1fXnXUY5u1JUhcO54BYuvo-Lp2wKR8MUwTrFDwuzAJl8lcfEK1aozjM7tzW24_UkyLxoyZnZe1k7bxYj0bMnOK41LL1GQo1LtK1_n9fSxZtgE9NOGbrWtodSzEltQMwFG8jheWoX5hoeiMgEQ8aSBnIo4IJhePApUxDgcvKQG5-qkHVCj43I; SG_SS=*c0-aTxfyAAa7yTBNm8l9Rw5uxDJ7rGAEADQBEArZ1F6cbbniAwluRPFiobxWvnC326rKiteYnsBfPPxqgolF4CRzjNQn0Zc4KqKt6vVPPQAAADhtAAAADFcBB0EANUaictlBd7Ou753b79l7DX09JecQkf6tsIX3-1Ia0_QUuKA1_9vr4uftdvjSbqtZtAsV3rphNQCUezxovO5KYW2cgQtEH23ZFJ9cJhdEcK8avHW8iMUd2D1rfY7PZ_Q48mOBrtJe7cTalc69GoqVGgUrHKjrIm8pH-y9OGUpmRK7z21gJB6GULM2CAoRqynT_un7ajubHKhvdPqZIuWh26NEEO9LO14BrDfClMG7TJ-oryWlqUu5e3jRi8P1mdBc32jRz9vMrGkb46McbaYCMitetxWGKtmYm9p_tBBRp-NnLp2uVUqOJbXypN-zlLYgsLwR0HS_fX31nvZNZnv5Bg-tzNlfB8 |