URL:

https://transmigridexp.net/?cid=gYv8SHzIQZOJcwt9&id=78061900

Full analysis: https://app.any.run/tasks/c991526c-95e7-475d-b3d7-b753c5d1443b
Verdict: Malicious activity
Analysis date: April 20, 2025, 03:56:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MD5:

D018B36FD1101115C58CFBB7194F9707

SHA1:

8F78D2A4AC0A026E6F229E6978A814CAEBE8FE4D

SHA256:

C2334CB72DB5440C45FCA3BF74D6B2271BEF8714623A05BB3FA526261DBA6E52

SSDEEP:

3:N8fiWIMV6V/KY/FN/XYcVVn:26461/lVVn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • OneStart.exe (PID: 6032)
      • UpdaterSetup.exe (PID: 2852)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 6724)
      • updater.exe (PID: 5780)
      • updater.exe (PID: 1184)
      • updater.exe (PID: 7152)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • updater.exe (PID: 632)
      • setup.exe (PID: 6744)
      • setup.exe (PID: 7000)
      • setup.exe (PID: 6620)
      • setup.exe (PID: 4212)
      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 7988)
      • onestart.exe (PID: 8028)
      • onestart.exe (PID: 668)
      • onestart.exe (PID: 536)
      • onestart.exe (PID: 4868)
      • onestart.exe (PID: 1912)
      • onestart.exe (PID: 4736)
      • onestart.exe (PID: 5188)
      • onestart.exe (PID: 5172)
      • onestart.exe (PID: 5952)
      • onestart.exe (PID: 2136)
      • onestart.exe (PID: 6712)
      • onestart.exe (PID: 2136)
      • onestart.exe (PID: 6972)
      • onestart.exe (PID: 7352)
      • onestart.exe (PID: 3620)
      • onestart.exe (PID: 4016)
      • onestart.exe (PID: 2852)
      • onestart.exe (PID: 3124)
      • onestart.exe (PID: 5384)
      • onestart.exe (PID: 5360)
      • onestart.exe (PID: 5508)
      • onestart.exe (PID: 2236)
      • onestart.exe (PID: 6080)
      • onestart.exe (PID: 6744)
      • onestart.exe (PID: 6256)
      • onestart.exe (PID: 5124)
      • onestart.exe (PID: 2772)
      • onestart.exe (PID: 5408)
      • onestart.exe (PID: 5304)
      • onestart.exe (PID: 6660)
      • onestart.exe (PID: 7996)
    • Changes the autorun value in the registry

      • updater.exe (PID: 2140)
      • onestart.exe (PID: 6632)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • OneStart.exe (PID: 6032)
      • updater.exe (PID: 2140)
    • Executable content was dropped or overwritten

      • OneStart.exe (PID: 6032)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 6724)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • setup.exe (PID: 6744)
      • onestart.exe (PID: 3124)
    • Application launched itself

      • updater.exe (PID: 2140)
      • updater.exe (PID: 6724)
      • updater.exe (PID: 1184)
      • setup.exe (PID: 6744)
      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 8028)
      • setup.exe (PID: 6620)
    • Creates a software uninstall entry

      • setup.exe (PID: 6744)
    • Searches for installed software

      • setup.exe (PID: 6744)
    • The process checks if it is being run in the virtual environment

      • onestart.exe (PID: 6632)
  • INFO

    • Checks supported languages

      • OneStart.exe (PID: 6032)
      • UpdaterSetup.exe (PID: 2852)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 6724)
      • updater.exe (PID: 5780)
      • updater.exe (PID: 7152)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • updater.exe (PID: 632)
      • updater.exe (PID: 1184)
      • setup.exe (PID: 7000)
      • notification_helper.exe (PID: 8132)
      • setup.exe (PID: 6620)
      • setup.exe (PID: 6744)
      • setup.exe (PID: 4212)
      • onestart.exe (PID: 7988)
      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 8028)
      • onestart.exe (PID: 668)
      • onestart.exe (PID: 536)
      • onestart.exe (PID: 4868)
      • onestart.exe (PID: 4736)
      • onestart.exe (PID: 5188)
      • onestart.exe (PID: 5172)
      • onestart.exe (PID: 1912)
      • onestart.exe (PID: 5952)
      • onestart.exe (PID: 2136)
      • onestart.exe (PID: 6712)
      • onestart.exe (PID: 2136)
      • onestart.exe (PID: 6972)
      • onestart.exe (PID: 5384)
      • onestart.exe (PID: 4016)
      • onestart.exe (PID: 7352)
      • onestart.exe (PID: 3620)
      • onestart.exe (PID: 2852)
      • onestart.exe (PID: 3124)
      • onestart.exe (PID: 5360)
      • onestart.exe (PID: 5508)
      • onestart.exe (PID: 2236)
      • onestart.exe (PID: 6744)
      • onestart.exe (PID: 6080)
      • onestart.exe (PID: 6256)
      • onestart.exe (PID: 5124)
      • onestart.exe (PID: 2772)
      • onestart.exe (PID: 6660)
      • onestart.exe (PID: 5304)
      • onestart.exe (PID: 7996)
      • onestart.exe (PID: 5408)
    • Application launched itself

      • chrome.exe (PID: 7408)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 7408)
      • chrome.exe (PID: 7152)
    • Reads the computer name

      • OneStart.exe (PID: 6032)
      • UpdaterSetup.exe (PID: 2852)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 6724)
      • updater.exe (PID: 1184)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • setup.exe (PID: 6744)
      • notification_helper.exe (PID: 8132)
      • setup.exe (PID: 6620)
      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 8028)
      • onestart.exe (PID: 536)
      • onestart.exe (PID: 4868)
      • onestart.exe (PID: 5952)
      • onestart.exe (PID: 2772)
    • Disables trace logs

      • OneStart.exe (PID: 6032)
    • Reads the machine GUID from the registry

      • OneStart.exe (PID: 6032)
      • updater.exe (PID: 2140)
      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 2772)
    • Reads the software policy settings

      • OneStart.exe (PID: 6032)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 1184)
      • slui.exe (PID: 8188)
      • slui.exe (PID: 5136)
    • Checks proxy server information

      • OneStart.exe (PID: 6032)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 1184)
      • onestart.exe (PID: 6632)
      • slui.exe (PID: 5136)
    • The sample compiled with english language support

      • OneStart.exe (PID: 6032)
      • UpdaterSetup.exe (PID: 2852)
      • updater.exe (PID: 2140)
      • updater.exe (PID: 6724)
      • setup.exe (PID: 6744)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • chrome.exe (PID: 7152)
      • onestart.exe (PID: 3124)
    • Create files in a temporary directory

      • UpdaterSetup.exe (PID: 2852)
      • updater.exe (PID: 1184)
      • updater.exe (PID: 2140)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • onestart.exe (PID: 6632)
    • Creates files or folders in the user directory

      • updater.exe (PID: 2140)
      • onestart_installer_134.0.6998.108.exe (PID: 904)
      • setup.exe (PID: 6744)
      • notification_helper.exe (PID: 8132)
      • setup.exe (PID: 6620)
      • onestart.exe (PID: 8028)
      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 4868)
      • onestart.exe (PID: 2772)
    • Process checks computer location settings

      • onestart.exe (PID: 6632)
      • onestart.exe (PID: 5188)
      • onestart.exe (PID: 5172)
      • onestart.exe (PID: 6972)
      • onestart.exe (PID: 2852)
    • Reads CPU info

      • onestart.exe (PID: 6632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
212
Monitored processes
71
Malicious processes
11
Suspicious processes
36

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs sppextcomobj.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs onestart.exe updatersetup.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs onestart_installer_134.0.6998.108.exe setup.exe setup.exe no specs slui.exe notification_helper.exe no specs chrome.exe no specs setup.exe no specs setup.exe no specs onestart.exe onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs chrome.exe no specs chrome.exe onestart.exe no specs chrome.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe chrome.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs chrome.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs chrome.exe no specs onestart.exe no specs chrome.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=gpu-process --start-stack-profiler --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=1980 /prefetch:2C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Version:
134.0.6998.108
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.108\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
632C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe --crash-handler --database=C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\Crashpad --url=https://onestart.ai/ --annotation=prod=OneStartUpdater --annotation=ver=134.0.6998.101 --initial-client-data=0x218,0x21c,0x220,0x1f4,0x224,0x7ff60f6b257c,0x7ff60f6b2588,0x7ff60f6b2598C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exeupdater.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.101
Modules
Images
c:\users\admin\onestart.ai\onestartupdater\134.0.6998.101\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
668C:\Users\admin\OneStart.ai\OneStart\onestart.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\OneStart.ai\OneStart\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\OneStart.ai\OneStart\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=OneStart --annotation=ver=134.0.6998.108 --initial-client-data=0x128,0x12c,0x130,0xac,0x134,0x7ffc89773f38,0x7ffc89773f44,0x7ffc89773f50C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart
Exit code:
0
Version:
134.0.6998.108
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.108\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
904"C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1184_122078569\onestart_installer_134.0.6998.108.exe" "C:\Users\admin\OneStart.ai" "15" "2" "1" "1"C:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping1184_122078569\onestart_installer_134.0.6998.108.exe
updater.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Installer
Exit code:
0
Version:
134.0.6998.108
Modules
Images
c:\users\admin\appdata\local\temp\chrome_unpacker_beginunzipping1184_122078569\onestart_installer_134.0.6998.108.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
1184"C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe" --server --service=update -EmbeddingC:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.101\updater.exe
svchost.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.101
Modules
Images
c:\users\admin\onestart.ai\onestartupdater\134.0.6998.101\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
1912"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=2456 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Version:
134.0.6998.108
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.108\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2136"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=4944 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.108
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.108\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2136"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=6076 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.108
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.108\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2140"C:\Users\admin\AppData\Local\Temp\OneStart.ai2852_966855268\bin\updater.exe" --install --install-dir="C:\Users\admin\OneStart.ai" --install-pref=15-2-1-1 --app-id={8060F172-F5A8-4798-B813-D0DA39CCFF06} --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2C:\Users\admin\AppData\Local\Temp\OneStart.ai2852_966855268\bin\updater.exe
UpdaterSetup.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.101
Modules
Images
c:\users\admin\appdata\local\temp\onestart.ai2852_966855268\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
2236"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,18300355853291706885,1649250275730236118,262144 --variations-seed-version --mojo-platform-channel-handle=6624 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.108
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.108\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
Total events
20 835
Read events
20 541
Write events
261
Delete events
33

Modification events

(PID) Process:(7408) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(7408) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(7408) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(7408) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(7408) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(8064) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
01000000000000005879B02EA8B1DB01
(PID) Process:(6032) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6032) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6032) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6032) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
32
Suspicious files
590
Text files
93
Unknown types
3

Dropped files

PID
Process
Filename
Type
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF10beed.TMP
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF10beed.TMP
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF10befc.TMP
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF10befc.TMP
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF10befc.TMP
MD5:
SHA256:
7408chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
52
TCP/UDP connections
85
DNS requests
79
Threats
31

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7408
chrome.exe
GET
200
108.138.36.71:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQg3SSkKA74hABkhmlBtJTz8w3hlAQU%2BWC71OPVNPa49QaAJadz20ZpqJ4CEEJLalPOx2YUHCpjsaUcQQQ%3D
unknown
whitelisted
7408
chrome.exe
GET
200
108.138.36.71:80
http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSoEwb5tith0jIBy9frSyNGB1lsAAQUNr1J%2FzEs669qQP6ZwBbtuvxI3V8CECg0yH5ERdG2%2F1YKJNfz4Kw%3D
unknown
whitelisted
1676
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1676
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2140
updater.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
whitelisted
904
onestart_installer_134.0.6998.108.exe
POST
200
18.245.31.47:80
http://event.onestartapi.com/
unknown
unknown
2140
updater.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEAWCnjQyuEUUPHtP0qoDCE8%3D
unknown
whitelisted
7708
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/iytumhagvyo3keak5z5zmak3iu_9718/hfnkpimlhhgieaddgfemjhofmfblmnib_9718_all_ad5rf75vihxf6gw6fevkopsrjaza.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4212
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
7644
chrome.exe
18.66.122.12:443
transmigridexp.net
AMAZON-02
US
unknown
7408
chrome.exe
239.255.255.250:1900
whitelisted
7644
chrome.exe
142.250.153.84:443
accounts.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
google.com
  • 216.58.206.78
whitelisted
transmigridexp.net
  • 18.66.122.12
  • 18.66.122.47
  • 18.66.122.118
  • 18.66.122.4
unknown
accounts.google.com
  • 142.250.153.84
whitelisted
sb-ssl.google.com
  • 142.250.186.110
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.71
  • 20.190.159.0
  • 40.126.31.131
  • 20.190.159.71
  • 20.190.159.130
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
www.google.com
  • 142.250.186.36
whitelisted

Threats

PID
Process
Class
Message
4868
onestart.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
4868
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info