KREMLIN Browser Extension C2 Polling Disguised as CSS Fetch

Detects outbound HTTP GET requests to a specific C2 domain 'luizestrelhashapr.online' masquerading as CSS file fetches. The request pattern uses a specific path '/google_api/' followed by predefined alphanumeric filenames, consistent with the KREMLIN malware browser extension's C2 polling mechanism.