File name:

AceLauncher.exe

Full analysis: https://app.any.run/tasks/d35b83ee-2a9b-4ec9-b59b-c647ec494c6e
Verdict: Malicious activity
Analysis date: June 25, 2025, 17:40:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

77474A1580B32BAD078608E8F25DD14F

SHA1:

9D28C69BF8C612C7116CEF12BF39E12229199A97

SHA256:

321EA554A469F37F77F49255324AA7A13F080A0D16042D7B8BAFAD128D860951

SSDEEP:

98304:GLVIF8P3n1BLHxtD59KEKjSvkY4oKM3sCwVTk9E28IHboxIEBNwymlVH540oUmg4:vMuz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • AceLauncher.exe (PID: 3720)
      • AceLauncher.exe (PID: 7536)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.exe (PID: 2708)
      • AceLauncher.exe (PID: 2044)
      • AceLauncher.tmp (PID: 6652)
      • mini_installer.exe (PID: 4044)
      • setup.exe (PID: 3000)
      • AceLauncherInstaller.exe (PID: 3952)
      • AceLauncherInstaller.exe (PID: 5720)
    • Reads the date of Windows installation

      • AceLauncher.tmp (PID: 4412)
      • setup.exe (PID: 2180)
    • Reads the Windows owner or organization settings

      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.tmp (PID: 6652)
    • Reads security settings of Internet Explorer

      • AceLauncher.tmp (PID: 4412)
      • setup.exe (PID: 2180)
      • AceLauncher.exe (PID: 3720)
    • Process drops legitimate windows executable

      • AceLauncher.tmp (PID: 6652)
      • AceLauncherInstaller.exe (PID: 5720)
      • AceLauncherInstaller.exe (PID: 3952)
    • Creates a software uninstall entry

      • setup.exe (PID: 3000)
      • AceLauncherUpdater.exe (PID: 6980)
    • Searches for installed software

      • setup.exe (PID: 3000)
      • AceLauncherUpdater.exe (PID: 6980)
    • Application launched itself

      • setup.exe (PID: 2180)
      • setup.exe (PID: 3000)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 4236)
      • AceLauncher.exe (PID: 5780)
      • AceLauncher.exe (PID: 7536)
      • AceLauncher.exe (PID: 7556)
      • AceLauncher.exe (PID: 2272)
      • AceLauncher.exe (PID: 5460)
    • The process creates files with name similar to system file names

      • AceLauncherInstaller.exe (PID: 3952)
    • The process checks if it is being run in the virtual environment

      • AceLauncher.exe (PID: 7536)
    • Connects to unusual port

      • AceLauncher.exe (PID: 7780)
  • INFO

    • Checks supported languages

      • AceLauncher.exe (PID: 2708)
      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.exe (PID: 2044)
      • AceLauncher.tmp (PID: 6652)
      • AceLauncherInstaller.exe (PID: 1160)
      • AceLauncherInstaller.exe (PID: 5480)
      • AceLauncherInstaller.exe (PID: 4648)
      • mini_installer.exe (PID: 4044)
      • setup.exe (PID: 3000)
      • setup.exe (PID: 1180)
      • setup.exe (PID: 2180)
      • setup.exe (PID: 5236)
      • AceLauncherInstaller.exe (PID: 5720)
      • AceLauncherAutoUpdate.exe (PID: 7092)
      • AceLauncher.exe (PID: 3720)
      • Update.exe (PID: 2124)
      • AceLauncherInstaller.exe (PID: 3952)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 1160)
      • AceLauncher.exe (PID: 2880)
      • AceLauncher.exe (PID: 4236)
      • AceLauncher.exe (PID: 3740)
      • AceLauncher.exe (PID: 5468)
      • AceLauncher.exe (PID: 5780)
      • AceLauncher.exe (PID: 3584)
      • AceLauncher.exe (PID: 4444)
      • AceLauncher.exe (PID: 4100)
      • AceLauncher.exe (PID: 1300)
      • AceLauncher.exe (PID: 4888)
      • AceLauncher.exe (PID: 6404)
      • AceLauncher.exe (PID: 2228)
      • AceLauncher.exe (PID: 6424)
      • AceLauncher.exe (PID: 6652)
      • AceLauncher.exe (PID: 1944)
      • AceLauncher.exe (PID: 1392)
      • AceLauncher.exe (PID: 7536)
      • AceLauncher.exe (PID: 2704)
      • AceLauncher.exe (PID: 7208)
      • AceLauncher.exe (PID: 7216)
      • AceLauncher.exe (PID: 7592)
      • AceLauncher.exe (PID: 7556)
      • AceLauncher.exe (PID: 7136)
      • AceLauncher.exe (PID: 7836)
      • AceLauncher.exe (PID: 7780)
      • AceLauncher.exe (PID: 7972)
      • AceLauncher.exe (PID: 7864)
      • AceLauncher.exe (PID: 7872)
      • AceLauncher.exe (PID: 8180)
      • AceLauncher.exe (PID: 2272)
      • AceLauncher.exe (PID: 2032)
      • AceLauncher.exe (PID: 856)
      • AceLauncher.exe (PID: 5716)
      • AceLauncher.exe (PID: 7080)
      • AceLauncher.exe (PID: 1192)
      • AceLauncher.exe (PID: 536)
      • AceLauncher.exe (PID: 7152)
      • AceLauncher.exe (PID: 2804)
      • AceLauncher.exe (PID: 5496)
      • AceLauncher.exe (PID: 2220)
      • AceLauncher.exe (PID: 2272)
      • AceLauncher.exe (PID: 5460)
      • AceLauncher.exe (PID: 3620)
      • AceLauncher.exe (PID: 4680)
      • AceLauncher.exe (PID: 7488)
      • AceLauncher.exe (PID: 6684)
      • AceLauncher.exe (PID: 6200)
      • AceLauncher.exe (PID: 7752)
      • AceLauncher.exe (PID: 7964)
      • AceLauncher.exe (PID: 6808)
    • Create files in a temporary directory

      • AceLauncher.exe (PID: 2708)
      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.exe (PID: 2044)
      • AceLauncher.tmp (PID: 6652)
      • mini_installer.exe (PID: 4044)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 7536)
    • Reads Environment values

      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.exe (PID: 2708)
      • AceLauncher.exe (PID: 2044)
      • AceLauncher.tmp (PID: 6652)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 3720)
      • AceLauncher.exe (PID: 2220)
      • AceLauncher.exe (PID: 7752)
    • Process checks computer location settings

      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 1944)
      • AceLauncher.exe (PID: 7216)
      • AceLauncher.exe (PID: 2704)
      • AceLauncher.exe (PID: 6652)
      • AceLauncher.exe (PID: 7536)
      • AceLauncher.exe (PID: 7864)
      • AceLauncher.exe (PID: 7872)
      • AceLauncher.exe (PID: 1192)
      • AceLauncher.exe (PID: 536)
    • Reads the computer name

      • AceLauncher.tmp (PID: 4412)
      • AceLauncher.tmp (PID: 6652)
      • AceLauncherInstaller.exe (PID: 1160)
      • AceLauncherInstaller.exe (PID: 5480)
      • AceLauncherInstaller.exe (PID: 4648)
      • mini_installer.exe (PID: 4044)
      • setup.exe (PID: 3000)
      • setup.exe (PID: 2180)
      • AceLauncherInstaller.exe (PID: 5720)
      • AceLauncher.exe (PID: 3720)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 4236)
      • AceLauncher.exe (PID: 5780)
      • AceLauncher.exe (PID: 3740)
      • AceLauncher.exe (PID: 5468)
      • AceLauncher.exe (PID: 7536)
      • AceLauncherInstaller.exe (PID: 3952)
      • AceLauncher.exe (PID: 7752)
      • AceLauncher.exe (PID: 7780)
      • AceLauncher.exe (PID: 7152)
      • AceLauncher.exe (PID: 2220)
      • AceLauncher.exe (PID: 5460)
      • AceLauncher.exe (PID: 6684)
      • AceLauncher.exe (PID: 2272)
      • AceLauncher.exe (PID: 7556)
    • Reads the software policy settings

      • AceLauncher.tmp (PID: 6652)
      • AceLauncher.exe (PID: 3720)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 2220)
      • slui.exe (PID: 7076)
    • Detects InnoSetup installer (YARA)

      • AceLauncher.exe (PID: 2044)
      • AceLauncher.tmp (PID: 6652)
    • Compiled with Borland Delphi (YARA)

      • AceLauncher.tmp (PID: 6652)
      • AceLauncher.exe (PID: 2044)
    • Reads the machine GUID from the registry

      • AceLauncherInstaller.exe (PID: 1160)
      • AceLauncherInstaller.exe (PID: 5480)
      • AceLauncherInstaller.exe (PID: 4648)
      • AceLauncherInstaller.exe (PID: 5720)
      • AceLauncherInstaller.exe (PID: 3952)
      • AceLauncher.exe (PID: 3720)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 7536)
      • AceLauncher.exe (PID: 2220)
      • AceLauncher.exe (PID: 7752)
      • AceLauncher.exe (PID: 6684)
    • Checks proxy server information

      • AceLauncher.tmp (PID: 6652)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 3720)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 2220)
      • slui.exe (PID: 7076)
      • AceLauncher.exe (PID: 7536)
    • Creates files or folders in the user directory

      • AceLauncherInstaller.exe (PID: 4648)
      • setup.exe (PID: 3000)
      • setup.exe (PID: 2180)
      • AceLauncherInstaller.exe (PID: 3952)
      • AceLauncherInstaller.exe (PID: 5720)
      • AceLauncherAutoUpdate.exe (PID: 7092)
      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 3720)
      • AceLauncher.exe (PID: 5600)
      • AceLauncher.exe (PID: 5468)
      • AceLauncher.exe (PID: 5780)
      • AceLauncher.exe (PID: 7536)
      • AceLauncher.exe (PID: 7780)
      • AceLauncher.exe (PID: 6684)
    • The sample compiled with english language support

      • mini_installer.exe (PID: 4044)
      • setup.exe (PID: 3000)
    • Creates files in the program directory

      • AceLauncher.exe (PID: 3720)
      • AceLauncherUpdater.exe (PID: 6980)
    • Launching a file from a Registry key

      • AceLauncher.exe (PID: 3720)
      • AceLauncher.exe (PID: 7536)
    • Disables trace logs

      • AceLauncherUpdater.exe (PID: 6980)
      • AceLauncher.exe (PID: 3720)
      • AceLauncher.exe (PID: 2220)
    • Reads CPU info

      • AceLauncher.exe (PID: 7536)
    • Manual execution by a user

      • AceLauncher.exe (PID: 2220)
      • AceLauncher.exe (PID: 2272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:13 06:55:45+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 704512
InitializedDataSize: 142336
UninitializedDataSize: -
EntryPoint: 0xacfe0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Sunstream Labs
FileDescription: AceLauncherInstaller Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: AceLauncherInstaller
ProductVersion: 1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
211
Monitored processes
71
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start acelauncher.exe acelauncher.tmp acelauncher.exe acelauncher.tmp acelauncherinstaller.exe no specs acelauncherinstaller.exe no specs acelauncherinstaller.exe no specs mini_installer.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs acelauncherinstaller.exe acelauncherinstaller.exe acelauncherautoupdate.exe no specs update.exe no specs acelauncher.exe acelauncherupdater.exe acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs slui.exe acelauncher.exe no specs acelauncher.exe acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs acelauncher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=renderer --extension-process --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --metrics-shmem-handle=5848,i,10657736969629383231,2871869642991511112,2097152 --field-trial-handle=2064,i,2342406802289870874,7901245135311375738,262144 --variations-seed-version --mojo-platform-channel-handle=5904 /prefetch:2C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
856"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --metrics-shmem-handle=5444,i,17319135130072811596,17268170430152928584,524288 --field-trial-handle=2064,i,2342406802289870874,7901245135311375738,262144 --variations-seed-version --mojo-platform-channel-handle=5656 /prefetch:8C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1160"C:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\SetupHelper\AceLauncherInstaller.exe" Acelauncher promptC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\SetupHelper\AceLauncherInstaller.exeAceLauncher.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
1
Version:
1.0.19
Modules
Images
c:\users\admin\appdata\local\temp\is-ujjph.tmp\setuphelper\acelauncherinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1160C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\AceLauncher\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\AceLauncher\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=AceLauncher --annotation=ver=134.0.6998.210 --initial-client-data=0x148,0x14c,0x150,0x124,0x154,0x7ffc3feb4f38,0x7ffc3feb4f44,0x7ffc3feb4f50C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
MEDIUM
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1180C:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\CR_BACBC.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\AceLauncher\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=AceLauncher --annotation=ver=134.0.6998.210 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff690544690,0x7ff69054469c,0x7ff6905446a8C:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\CR_BACBC.tmp\setup.exesetup.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
MEDIUM
Description:
AceLauncher Installer
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\temp\is-ujjph.tmp\cr_bacbc.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1192"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=renderer --extension-process --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --metrics-shmem-handle=5636,i,11626073056136529579,11537038542518060795,2097152 --field-trial-handle=2064,i,2342406802289870874,7901245135311375738,262144 --variations-seed-version --mojo-platform-channel-handle=5704 /prefetch:2C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1300"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --metrics-shmem-handle=3516,i,11783442562884835609,18196444547232534034,524288 --field-trial-handle=1996,i,1794314729632750944,1680998159410998498,262144 --variations-seed-version --mojo-platform-channel-handle=3204 /prefetch:8C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1392"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --metrics-shmem-handle=6164,i,4760500525066431262,6546657841582274908,524288 --field-trial-handle=1996,i,1794314729632750944,1680998159410998498,262144 --variations-seed-version --mojo-platform-channel-handle=5012 /prefetch:8C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1944"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --metrics-shmem-handle=5108,i,4559000925093605577,3377185157337349162,2097152 --field-trial-handle=1996,i,1794314729632750944,1680998159410998498,262144 --variations-seed-version --mojo-platform-channel-handle=5140 /prefetch:1C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
4294967295
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2032"C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --metrics-shmem-handle=5496,i,13380582023580312009,843811836402816436,524288 --field-trial-handle=2064,i,2342406802289870874,7901245135311375738,262144 --variations-seed-version --mojo-platform-channel-handle=5504 /prefetch:8C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exeAceLauncher.exe
User:
admin
Company:
Sunstream Labs
Integrity Level:
LOW
Description:
AceLauncher
Exit code:
0
Version:
134.0.6998.210
Modules
Images
c:\users\admin\appdata\local\acelauncher\application\acelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\acelauncher\application\134.0.6998.210\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
18 928
Read events
18 474
Write events
446
Delete events
8

Modification events

(PID) Process:(6652) AceLauncher.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
FC190000D8674E4AF8E5DB01
(PID) Process:(6652) AceLauncher.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
9B26998EB8D69929F2F7B309355379B4B3F65389ADB0018F4DAE3CAC3466FBA0
(PID) Process:(6652) AceLauncher.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1160) AceLauncherInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AceLauncherUpdater\BrowserSettings
Operation:writeName:WakeUp
Value:
true
(PID) Process:(1160) AceLauncherInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DockSettings
Operation:delete valueName:ClosedByUser
Value:
(PID) Process:(1160) AceLauncherInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AceLauncherUpdater\BrowserSettings
Operation:writeName:RunInBackgroundEnabled
Value:
true
(PID) Process:(1160) AceLauncherInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\AceLauncher\ImportBrowserData
Operation:writeName:ShouldImport
Value:
true
(PID) Process:(4412) AceLauncher.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
3C1100006945134AF8E5DB01
(PID) Process:(4412) AceLauncher.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
30A0AF5001A40AA511A5AC5C606CDF424A0F32A38B183E524098E747AF342053
(PID) Process:(4412) AceLauncher.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
Executable files
54
Suspicious files
164
Text files
147
Unknown types
95

Dropped files

PID
Process
Filename
Type
6652AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\is-MRHTL.tmp
MD5:
SHA256:
6652AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\mini_installer.exe
MD5:
SHA256:
6652AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\SetupHelper\AceLauncherInstaller.pdbbinary
MD5:512D2EF791FDE7B173C709B75B3D4CA2
SHA256:60B9F074F8D22767FDA4ACB209E9DCA587EF97B4247C6460BA3227D35D3ED11F
6652AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\SetupHelper\AceLauncherShared.dllexecutable
MD5:7578A880D568622BE9EAEB2E60FD7391
SHA256:528779808F954F45C01107699D7BE887BC2AEF7038AA507C5AC5EBDE769A537F
2708AceLauncher.exeC:\Users\admin\AppData\Local\Temp\is-95RVA.tmp\AceLauncher.tmpexecutable
MD5:1C57B8ACDFFEDFF1EE9F086E4680D61B
SHA256:2F5953ACEEE956398B783C837FAE2247ACA710202F5412866A3473B56EC1A145
6652AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\SetupHelper\AceLauncherInstaller.exe.configxml
MD5:2A2DF45A07478A1C77D5834C21F3D7FD
SHA256:051099983B896673909E01A1F631B6652ABB88DA95C9F06F3EFEF4BE033091FA
4412AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-U7G2L.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6652AceLauncher.tmpC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
4648AceLauncherInstaller.exeC:\Users\admin\AppData\Local\AceLauncher\User Data\Default\Faviconssqlite
MD5:46CA0435A20303F7DDC5D5BFA1910FC6
SHA256:6092D439881703436AA52E99C1862C03F1345E3AE65B6E7CD40DE7BF63913DFF
4044mini_installer.exeC:\Users\admin\AppData\Local\Temp\is-UJJPH.tmp\CR_BACBC.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
75
DNS requests
69
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7000
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7000
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2552
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7780
AceLauncher.exe
GET
200
142.250.186.46:80
http://clients2.google.com/time/1/current?cup2key=8:Pgow_zZvYr6-B_srrB4fZ2FndlXqjHQuMW9ez1Vze8c&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
5468
AceLauncher.exe
GET
200
142.250.186.46:80
http://clients2.google.com/time/1/current?cup2key=8:p7eZr5wpgijPEp_el1qij_CeefFQDhhjJY4l3HFuNwg&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
3720
AceLauncher.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
whitelisted
3720
AceLauncher.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7268
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/iznregam3uclnr3zhalqfsnk7a_2025.1.17.0/cffplpkejcbdpfnfabnjikeicbedmifn_2025.01.17.00_all_ac2sumq77lyrpdnlfw5kbuorw2wq.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2432
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6652
AceLauncher.tmp
52.203.92.28:443
analytics.acelauncher.com
AMAZON-AES
US
unknown
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2552
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
analytics.acelauncher.com
  • 52.203.92.28
unknown
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.0
  • 40.126.31.130
  • 20.190.159.0
  • 20.190.159.2
  • 20.190.159.131
  • 40.126.31.3
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
download.acelauncher.com
  • 18.66.112.67
  • 18.66.112.22
  • 18.66.112.92
  • 18.66.112.72
unknown
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

No threats detected
No debug info