@HuntYethHounds@tsnikle@luke92881@SquiblydooBlog@InvokeReversing@struppigel Well, on one host, the dns resolution for 1 domain goes back further than 1 year, and i checked the chrome preferences file, same findings. The new tab url and other items have been hijacked with the same format of url. Looks like this is not very new :D
@HuntYethHounds@tsnikle@luke92881@SquiblydooBlog@InvokeReversing@struppigel This is really interesting stuff. The adware components do seem somewhat similar(but that could just be adware in general :D ) I am searching DNS in my env for those and see similar subdomains like goog. and home. so theres definitely a connection. Looking into it more.
@tsnikle@luke92881@SquiblydooBlog@HuntYethHounds@InvokeReversing@struppigel can you expand on 'visit from Google' ? in sandbox, out of sandbox, which browser, just googling 'pix-seek' etc. tried a few things but came up with winrar everytime so just curious if you can share more detail to reproduce.
@SquiblydooBlog@luke92881@HuntYethHounds@InvokeReversing@struppigel I just checked the pix-seek page and the download now works but i tried from multiple sources and it always seems to download....winrar version 7.10 installer??? My first thought is some kind of anti-sandbox type filtering but not sure :D