| URL: | https://transmigridexp.net/?cid=gYv8SHzIQZOJcwt9&id=78061900 |
| Full analysis: | https://app.any.run/tasks/c991526c-95e7-475d-b3d7-b753c5d1443b |
| Verdict: | Malicious activity |
| Analysis date: | April 20, 2025, 03:56:12 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | D018B36FD1101115C58CFBB7194F9707 |
| SHA1: | 8F78D2A4AC0A026E6F229E6978A814CAEBE8FE4D |
| SHA256: | C2334CB72DB5440C45FCA3BF74D6B2271BEF8714623A05BB3FA526261DBA6E52 |
| SSDEEP: | 3:N8fiWIMV6V/KY/FN/XYcVVn:26461/lVVn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 536 | "C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=gpu-process --start-stack-profiler --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=1980 /prefetch:2 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe | — | onestart.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: LOW Description: OneStart Version: 134.0.6998.108 Modules
| |||||||||||||||
| 632 | C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe --crash-handler --database=C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\Crashpad --url=https://onestart.ai/ --annotation=prod=OneStartUpdater --annotation=ver=134.0.6998.101 --initial-client-data=0x218,0x21c,0x220,0x1f4,0x224,0x7ff60f6b257c,0x7ff60f6b2588,0x7ff60f6b2598 | C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe | — | updater.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: MEDIUM Description: OneStart Updater Exit code: 0 Version: 134.0.6998.101 Modules
| |||||||||||||||
| 668 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\OneStart.ai\OneStart\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\OneStart.ai\OneStart\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=OneStart --annotation=ver=134.0.6998.108 --initial-client-data=0x128,0x12c,0x130,0xac,0x134,0x7ffc89773f38,0x7ffc89773f44,0x7ffc89773f50 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe | — | onestart.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: MEDIUM Description: OneStart Exit code: 0 Version: 134.0.6998.108 Modules
| |||||||||||||||
| 904 | "C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1184_122078569\onestart_installer_134.0.6998.108.exe" "C:\Users\admin\OneStart.ai" "15" "2" "1" "1" | C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1184_122078569\onestart_installer_134.0.6998.108.exe | updater.exe | ||||||||||||
User: admin Company: OneStart.ai Integrity Level: MEDIUM Description: OneStart Installer Exit code: 0 Version: 134.0.6998.108 Modules
| |||||||||||||||
| 1184 | "C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe" --server --service=update -Embedding | C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe | svchost.exe | ||||||||||||
User: admin Company: OneStart.ai Integrity Level: MEDIUM Description: OneStart Updater Exit code: 0 Version: 134.0.6998.101 Modules
| |||||||||||||||
| 1912 | "C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=2456 /prefetch:8 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe | — | onestart.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: LOW Description: OneStart Version: 134.0.6998.108 Modules
| |||||||||||||||
| 2136 | "C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=4944 /prefetch:8 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe | — | onestart.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: LOW Description: OneStart Exit code: 0 Version: 134.0.6998.108 Modules
| |||||||||||||||
| 2136 | "C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=6076 /prefetch:8 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe | — | onestart.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: LOW Description: OneStart Exit code: 0 Version: 134.0.6998.108 Modules
| |||||||||||||||
| 2140 | "C:\Users\admin\AppData\Local\Temp\OneStart.ai2852_966855268\bin\updater.exe" --install --install-dir="C:\Users\admin\OneStart.ai" --install-pref=15-2-1-1 --app-id={8060F172-F5A8-4798-B813-D0DA39CCFF06} --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2 | C:\Users\admin\AppData\Local\Temp\OneStart.ai2852_966855268\bin\updater.exe | UpdaterSetup.exe | ||||||||||||
User: admin Company: OneStart.ai Integrity Level: MEDIUM Description: OneStart Updater Exit code: 0 Version: 134.0.6998.101 Modules
| |||||||||||||||
| 2236 | "C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=6624 /prefetch:8 | C:\Users\admin\OneStart.ai\OneStart\onestart.exe | — | onestart.exe | |||||||||||
User: admin Company: OneStart.ai Integrity Level: LOW Description: OneStart Exit code: 0 Version: 134.0.6998.108 Modules
| |||||||||||||||
| (PID) Process: | (7408) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (7408) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (7408) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (7408) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (7408) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (8064) chrome.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached |
| Operation: | write | Name: | {2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF |
Value: 01000000000000005879B02EA8B1DB01 | |||
| (PID) Process: | (6032) OneStart.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6032) OneStart.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (6032) OneStart.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (6032) OneStart.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF10beed.TMP | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF10beed.TMP | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF10befc.TMP | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF10befc.TMP | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF10befc.TMP | — | |
MD5:— | SHA256:— | |||
| 7408 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7408 | chrome.exe | GET | 200 | 108.138.36.71:80 | http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQg3SSkKA74hABkhmlBtJTz8w3hlAQU%2BWC71OPVNPa49QaAJadz20ZpqJ4CEEJLalPOx2YUHCpjsaUcQQQ%3D | unknown | — | — | whitelisted |
7408 | chrome.exe | GET | 200 | 108.138.36.71:80 | http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSoEwb5tith0jIBy9frSyNGB1lsAAQUNr1J%2FzEs669qQP6ZwBbtuvxI3V8CECg0yH5ERdG2%2F1YKJNfz4Kw%3D | unknown | — | — | whitelisted |
1676 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1676 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2140 | updater.exe | GET | 200 | 18.245.38.41:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D | unknown | — | — | whitelisted |
904 | onestart_installer_134.0.6998.108.exe | POST | 200 | 18.245.31.47:80 | http://event.onestartapi.com/ | unknown | — | — | unknown |
2140 | updater.exe | GET | 200 | 18.245.65.219:80 | http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEAWCnjQyuEUUPHtP0qoDCE8%3D | unknown | — | — | whitelisted |
7708 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/iytumhagvyo3keak5z5zmak3iu_9718/hfnkpimlhhgieaddgfemjhofmfblmnib_9718_all_ad5rf75vihxf6gw6fevkopsrjaza.crx3 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4212 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7644 | chrome.exe | 18.66.122.12:443 | transmigridexp.net | AMAZON-02 | US | unknown |
7408 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
7644 | chrome.exe | 142.250.153.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
transmigridexp.net |
| unknown |
accounts.google.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4868 | onestart.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
4868 | onestart.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |