File name:

OneLaunch - Templates Search_hton0.exe

Full analysis: https://app.any.run/tasks/c90258dd-abcc-4376-8f50-e415ac2e9f35
Verdict: Malicious activity
Analysis date: September 30, 2024, 23:09:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A12D8B92788F446809C5599A4A67D001

SHA1:

866313B2C1DD5C7AFF3FD11E9744A5FCFBA6F52C

SHA256:

0000EA3156A7A0A9F0C9567136F123DB37AEFD36E1D0C301AAF1C2BEA7E35D71

SSDEEP:

49152:Kqe3f6RzVZC17KlBYjN1DcVnC8EljqVX5rIJwI2J5PiH7nBGt2:jSiRzVE17CBYj6C8AjgJLTiH7BU2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OneLaunch - Templates Search_hton0.exe (PID: 2268)
      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
      • OneLaunch - Templates Search_hton0.exe (PID: 3444)
      • OneLaunch - Templates Search_hton0.tmp (PID: 2080)
      • OneLaunch Setup_hton0.exe (PID: 5612)
      • OneLaunch Setup_hton0.tmp (PID: 6984)
      • onelaunch_8dce1a51fa10ecc.tmp (PID: 6772)
      • onelaunch_8dce1a51fa10ecc.exe (PID: 3076)
    • Reads the Windows owner or organization settings

      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
    • There is functionality for taking screenshot (YARA)

      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
    • Uses TASKKILL.EXE to kill process

      • OneLaunch Setup_hton0.tmp (PID: 6984)
    • Application launched itself

      • chromium.exe (PID: 6436)
    • Process drops legitimate windows executable

      • onelaunch_8dce1a51fa10ecc.tmp (PID: 6772)
      • OneLaunch Setup_hton0.tmp (PID: 6984)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 4472)
      • schtasks.exe (PID: 4048)
      • schtasks.exe (PID: 2240)
    • Executes application which crashes

      • OneLaunch Setup_hton0.tmp (PID: 6984)
  • INFO

    • Checks supported languages

      • OneLaunch - Templates Search_hton0.exe (PID: 2268)
      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
    • Create files in a temporary directory

      • OneLaunch - Templates Search_hton0.exe (PID: 2268)
      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
    • Reads the computer name

      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
    • Reads the machine GUID from the registry

      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
    • Reads the software policy settings

      • OneLaunch - Templates Search_hton0.tmp (PID: 2640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 09:48:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.13.5.0
ProductVersionNumber: 5.13.5.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.13.5
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.13.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
184
Monitored processes
49
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start onelaunch - templates search_hton0.exe THREAT onelaunch - templates search_hton0.tmp onelaunch - templates search_hton0.exe onelaunch - templates search_hton0.tmp onelaunch setup_hton0.exe onelaunch setup_hton0.tmp taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs onelaunch.exe chromium.exe chromium.exe chromium.exe no specs chromium.exe chromium.exe no specs chromium.exe chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs werfault.exe chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs werfault.exe chromium.exe no specs chromium.exe no specs onelaunch_8dce1a51fa10ecc.exe onelaunch_8dce1a51fa10ecc.tmp chromium.exe no specs chromium.exe no specs chromium.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
400\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1840"C:\Users\admin\AppData\Local\OneLaunch\5.13.5\chromium\chromium.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5204 --field-trial-handle=2072,i,16924012828844342933,15697185064866414602,131072 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.13.5\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Exit code:
0
Version:
109.0.2
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.13.5\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2080"C:\Users\admin\AppData\Local\Temp\is-TG9F7.tmp\OneLaunch - Templates Search_hton0.tmp" /SL5="$1E0222,1909830,893952,C:\Users\admin\AppData\Local\Temp\OneLaunch - Templates Search_hton0.exe" /PDATA=eyJtZXNzYWdlIjoiTm8gUmVjb3JkIEZvdW5kIiwiaW5zdGFsbF90aW1lIjoxNzI3NzM3Nzc2LCJkaXN0aW5jdF9pZCI6IjkwNTk3NEMwLTY2QjMtNDBDOC04QkQzLURBNzU0MUI1M0JEQiIsImRlZmF1bHRfYnJvd3NlciI6Ik1TRWRnZUhUTSIsImluaXRpbmFsX3ZlcnNpb24iOiI1LjEzLjUuMCIsInNwbGl0IjoiYSIsIm9sX3BsdXNfdjIiOmZhbHNlLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0XzIyXzEyX21vcmVfZWR1Y2F0aW9uYWxfbWluaXByb21wdHMiOiJ2YXJpYXRpb24iLCJzcGxpdF8yM18wMl9icm93c2VyX2xhYmVsIjoiY29udHJvbCIsInNwbGl0XzIzXzAzX3Nob3Bub21peF9hbWF6b24iOiJ2YXJpYXRpb24iLCJlbmNvZGVkX3NwbGl0cyI6IjAwMCIsInNwbGl0MiI6ImEifQ== /LAUNCHER /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-TG9F7.tmp\OneLaunch - Templates Search_hton0.tmp
OneLaunch - Templates Search_hton0.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-tg9f7.tmp\onelaunch - templates search_hton0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2088\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2240"schtasks" /delete /tn OneLaunchLaunchTask /fC:\Windows\System32\schtasks.exeOneLaunch Setup_hton0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2264"C:\Users\admin\AppData\Local\OneLaunch\5.13.5\chromium\chromium.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5216 --field-trial-handle=2072,i,16924012828844342933,15697185064866414602,131072 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.13.5\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
109.0.2
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.13.5\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2268"C:\Users\admin\AppData\Local\Temp\OneLaunch - Templates Search_hton0.exe" C:\Users\admin\AppData\Local\Temp\OneLaunch - Templates Search_hton0.exe
explorer.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
0
Version:
5.13.5
Modules
Images
c:\users\admin\appdata\local\temp\onelaunch - templates search_hton0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2460"C:\Users\admin\AppData\Local\OneLaunch\5.13.5\chromium\chromium.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5260 --field-trial-handle=2072,i,16924012828844342933,15697185064866414602,131072 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.13.5\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Exit code:
0
Version:
109.0.2
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.13.5\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2640"C:\Users\admin\AppData\Local\Temp\is-PV6SP.tmp\OneLaunch - Templates Search_hton0.tmp" /SL5="$1302E8,1909830,893952,C:\Users\admin\AppData\Local\Temp\OneLaunch - Templates Search_hton0.exe" C:\Users\admin\AppData\Local\Temp\is-PV6SP.tmp\OneLaunch - Templates Search_hton0.tmp
OneLaunch - Templates Search_hton0.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pv6sp.tmp\onelaunch - templates search_hton0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3032\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
19 169
Read events
19 035
Write events
132
Delete events
2

Modification events

(PID) Process:(2080) OneLaunch - Templates Search_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
200800000BFF76E68D13DB01
(PID) Process:(2080) OneLaunch - Templates Search_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
6D2107DE4AAC21DF33C32BE56ACE7351D2A685A9EF0D1D2B68989E707A095085
(PID) Process:(2080) OneLaunch - Templates Search_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:version
Value:
5.13.5.0
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:assembly
Value:
C:\Users\admin\AppData\Local\OneLaunch\5.13.5\onelaunch.exe
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:install_info
Value:
{"message":"No Record Found","install_time":1727737776,"distinct_id":"905974C0-66B3-40C8-8BD3-DA7541B53BDB","default_browser":"MSEdgeHTM","initinal_version":"5.13.5.0","split":"a","ol_plus_v2":false,"no_split":false,"split_22_12_more_educational_miniprompts":"variation","split_23_02_browser_label":"control","split_23_03_shopnomix_amazon":"variation","encoded_splits":"000","split2":"a"}
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:settings
Value:
{"amazon_url":"https://wbd_ol.ampxdirect.com/amazon?sub1=default&sub2=amazon","search_name":"Yahoo!","extensions":["hffgmnbojgnbalmhedkdikfhaflnfcno;https://chrmxtnsnhdnnlnch.onelaunch.com/ex?hf"],"search_url":"https://search.yahoo.com/yhs/search?hspart=reb&hsimp=yhs-ext_onelaunch&p={searchTerms}&type=0_1000_100_1000_100_691231","preload_extensions":["gcklppdiegejnfnpepkaagjmdneobkgi;https://static.slickdealscdn.com/attachment/extension/onelaunch/sd-3.6.8.crx"],"suggest_url":"https://us.search.yahoo.com/sugg/gossip/gossip-us-partner?output=fxjson&appid=reb&command={searchTerms}","type_tag":"0_1000_100_1000_100_240930","rich_suggest_url":"https://us.search.yahoo.com/sugg/gossip/gossip-us-fastbreak?command={searchTerms}&output=fxjson&appid=reb-rich","url_app_overrides":["ebay_popular;https://ebay.com","ebay;https://ebay.com"],"new_tab_url":"https://onenews.com/v8/?s=https%3A%2F%2Fsearch.yahoo.com%2Fyhs%2Fsearch%3Fhspart%3Dreb%26hsimp%3Dyhs-ext_onelaunch%26p%3D%7BsearchTerms%7D%26type%3D0_1000_100_1000_100_240930","ob_new_tab_url":"https://onenews.com/v8/?s=https%3A%2F%2Fsearch.yahoo.com%2Fyhs%2Fsearch%3Fhspart%3Dreb%26hsimp%3Dyhs-ext_onelaunch%26p%3D%7BsearchTerms%7D%26type%3D0_1000_100_1000_100_240930","accuweather_api":"7f64ed3093d8436e994f9dc7e382a06a","thanks_url":""}
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:reinstall_count
Value:
0
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:attribution_keys
Value:
{"keyList":["hton0"]}
(PID) Process:(6984) OneLaunch Setup_hton0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:update_count
Value:
0
Executable files
269
Suspicious files
348
Text files
327
Unknown types
3

Dropped files

PID
Process
Filename
Type
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\is-C7UTP.tmp
MD5:
SHA256:
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\OneLaunch Setup.exe
MD5:
SHA256:
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
2080OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_hton0.exe
MD5:
SHA256:
2080OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-FMCS9.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\split_tests.jsontext
MD5:5EDDF3C741303DD0D3D7271DDD110967
SHA256:74A8B39E6EA7D98C01AC19CCEE5AF021A4A74D4CDC4987087E4310E70418C0AA
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\Win32Library.dllexecutable
MD5:3CF0B929BCE4F215C85C0B9A4865E3E2
SHA256:9EE90580260F612F276B8343E4816CE6DCBB1908FD735FF795C7C4DFC031362C
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\min-hover.bmpimage
MD5:C94A77553F2C392D5F1FE2F08E30EFB2
SHA256:8DAA69B6252F6F773CEB6D7090664B933537478731473E1B54CAF67791C2D336
2640OneLaunch - Templates Search_hton0.tmpC:\Users\admin\AppData\Local\Temp\is-PL9CP.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
91
DNS requests
57
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1328
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3112
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3112
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2868
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4528
chromium.exe
GET
200
216.58.206.46:80
http://clients2.google.com/time/1/current?cup2key=6:WaAUtsAbenBXS8CjntTD3H3455amNpZerUzZwVNYscc&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
4528
chromium.exe
GET
200
216.58.206.46:80
http://clients2.google.com/time/1/current?cup2key=6:auS1OQxPAfsFhXea_visbuvGpjpoaJMeU72gfiQn--E&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
3184
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
876
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2640
OneLaunch - Templates Search_hton0.tmp
18.173.205.127:443
attribution.onelaunch.com
US
whitelisted
2640
OneLaunch - Templates Search_hton0.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
suspicious
2640
OneLaunch - Templates Search_hton0.tmp
44.240.16.236:443
api.keen.io
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.110
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 184.30.21.171
  • 95.101.149.131
whitelisted
attribution.onelaunch.com
  • 18.173.205.127
  • 18.173.205.66
  • 18.173.205.38
  • 18.173.205.55
whitelisted
update.onelaunch.com
  • 104.26.12.224
  • 104.26.13.224
  • 172.67.68.170
unknown
api.keen.io
  • 44.240.16.236
  • 52.89.2.240
  • 54.187.66.251
whitelisted
release-cdn.onelaunch.com
  • 172.67.68.170
  • 104.26.13.224
  • 104.26.12.224
unknown
login.live.com
  • 20.190.159.4
  • 20.190.159.75
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.23
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted

Threats

No threats detected
Process
Message
chromium.exe
[0930/231047.548:ERROR:crash_report_database_win.cc(614)] CreateDirectory C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad: The system cannot find the path specified. (0x3)
OneLaunch.exe
2024-09-30 23:10:49,299 DEBUG [ 1] (Com.WebBar.Analytics.AnalyticsService: 0) - sending "daily_activity": {"runningDock_minutes":0,"focusedDock_minutes":0,"runningChromium_minutes":0,"focusedChromium_minutes":0,"runningInBackground_minutes":0}
OneLaunch.exe
2024-09-30 23:10:49,314 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.13.5.0