URL:

https://www.az-launcher.nz/static/launcher/i/AZ-Launcher_Installer.exe

Full analysis: https://app.any.run/tasks/b2a17e94-3481-49d3-ab31-2bf02c8beaf5
Verdict: Malicious activity
Analysis date: September 14, 2020, 06:23:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

97AACCAFEC1149F773E89CCD4460E80F

SHA1:

4F28F7E30C3717D551EAE60602D79665BF1567B8

SHA256:

3A3446A99381C9A0D75802EB537EBFFC8CCAFA51974BE13906C62EC62F9B766D

SSDEEP:

3:N8DSLvKzAvsKLffMEZBXLNn:2OLit6XLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AZ-Launcher_Installer.exe (PID: 2576)
      • AZ-Launcher_Installer.exe (PID: 3272)
      • AZ-Launcher.exe (PID: 1164)
      • AZ-Launcher.exe (PID: 2224)
      • vc_redist.x86.exe (PID: 2652)
      • AZ-Launcher.exe (PID: 2360)
      • AZ-Launcher.exe (PID: 2352)
      • vc_redist.x86.exe (PID: 2440)
    • Changes settings of System certificates

      • AZ-Launcher_Installer.tmp (PID: 236)
    • Loads dropped or rewritten executable

      • vc_redist.x86.exe (PID: 2652)
      • AZ-Launcher.exe (PID: 1164)
      • AZ-Launcher.exe (PID: 2224)
      • AZ-Launcher.exe (PID: 2360)
      • AZ-Launcher.exe (PID: 2352)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2468)
      • AZ-Launcher_Installer.exe (PID: 2576)
      • iexplore.exe (PID: 2340)
      • AZ-Launcher_Installer.tmp (PID: 236)
      • AZ-Launcher_Installer.exe (PID: 3272)
      • AZ-Launcher_Setup.exe (PID: 1960)
      • AZ-Launcher_Setup.exe (PID: 2232)
      • AZ-Launcher_Setup.tmp (PID: 3056)
      • vc_redist.x86.exe (PID: 2652)
    • Reads Windows owner or organization settings

      • AZ-Launcher_Installer.tmp (PID: 236)
      • AZ-Launcher_Setup.tmp (PID: 3056)
    • Reads the Windows organization settings

      • AZ-Launcher_Installer.tmp (PID: 236)
      • AZ-Launcher_Setup.tmp (PID: 3056)
    • Adds / modifies Windows certificates

      • AZ-Launcher_Installer.tmp (PID: 236)
    • Creates files in the user directory

      • AZ-Launcher_Installer.tmp (PID: 236)
    • Reads Internet Cache Settings

      • AZ-Launcher_Installer.tmp (PID: 236)
    • Application launched itself

      • vc_redist.x86.exe (PID: 2440)
      • AZ-Launcher.exe (PID: 1164)
      • AZ-Launcher.exe (PID: 2360)
    • Creates files in the program directory

      • AZ-Launcher.exe (PID: 2352)
      • AZ-Launcher.exe (PID: 2224)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2468)
    • Changes internet zones settings

      • iexplore.exe (PID: 2468)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2468)
      • iexplore.exe (PID: 2340)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2468)
    • Application was dropped or rewritten from another process

      • AZ-Launcher_Installer.tmp (PID: 2080)
      • AZ-Launcher_Installer.tmp (PID: 236)
      • AZ-Launcher_Setup.exe (PID: 1960)
      • AZ-Launcher_Setup.tmp (PID: 2664)
      • AZ-Launcher_Setup.tmp (PID: 3056)
      • AZ-Launcher_Setup.exe (PID: 2232)
    • Creates files in the user directory

      • iexplore.exe (PID: 2340)
    • Dropped object may contain Bitcoin addresses

      • AZ-Launcher_Setup.tmp (PID: 3056)
    • Creates a software uninstall entry

      • AZ-Launcher_Setup.tmp (PID: 3056)
    • Creates files in the program directory

      • AZ-Launcher_Setup.tmp (PID: 3056)
    • Loads dropped or rewritten executable

      • AZ-Launcher_Installer.tmp (PID: 236)
    • Manual execution by user

      • AZ-Launcher.exe (PID: 2360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
16
Malicious processes
8
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe az-launcher_installer.exe az-launcher_installer.tmp no specs az-launcher_installer.exe az-launcher_installer.tmp az-launcher_setup.exe az-launcher_setup.tmp no specs az-launcher_setup.exe az-launcher_setup.tmp vc_redist.x86.exe no specs vc_redist.x86.exe az-launcher.exe az-launcher.exe az-launcher.exe az-launcher.exe

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\AppData\Local\Temp\is-5HMT2.tmp\AZ-Launcher_Installer.tmp" /SL5="$3019E,1044538,954880,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AZ-Launcher_Installer.exe" /SPAWNWND=$30168 /NOTIFYWND=$20194 C:\Users\admin\AppData\Local\Temp\is-5HMT2.tmp\AZ-Launcher_Installer.tmp
AZ-Launcher_Installer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5hmt2.tmp\az-launcher_installer.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1164"C:\Program Files\AZ-Launcher\AZ-Launcher.exe"C:\Program Files\AZ-Launcher\AZ-Launcher.exe
AZ-Launcher_Setup.tmp
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\az-launcher\az-launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\az-launcher\qt5widgets.dll
c:\program files\az-launcher\qt5gui.dll
c:\program files\az-launcher\qt5core.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
1960"C:\Users\admin\AppData\Local\Temp\is-1I7L2.tmp\AZ-Launcher_Setup.exe"C:\Users\admin\AppData\Local\Temp\is-1I7L2.tmp\AZ-Launcher_Setup.exe
AZ-Launcher_Installer.tmp
User:
admin
Company:
AZ
Integrity Level:
MEDIUM
Description:
AZ Launcher - Minecraft (32 bits) Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\is-1i7l2.tmp\az-launcher_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2080"C:\Users\admin\AppData\Local\Temp\is-U22J4.tmp\AZ-Launcher_Installer.tmp" /SL5="$20194,1044538,954880,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AZ-Launcher_Installer.exe" C:\Users\admin\AppData\Local\Temp\is-U22J4.tmp\AZ-Launcher_Installer.tmpAZ-Launcher_Installer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u22j4.tmp\az-launcher_installer.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2224"C:\Program Files\AZ-Launcher\AZ-Launcher.exe" --is-elevated --launcher-datadir "C:/Program Files/AZ-Launcher/runtime" --legacy-launcher-datadir "C:/Program Files/Pactify Launcher" --launcher-update-source "" --client-datadir C:/Users/admin/AppData/Roaming/.az-client --legacy-client-datadir C:/Users/admin/AppData/Roaming/.pactify --client-update-source ""C:\Program Files\AZ-Launcher\AZ-Launcher.exe
AZ-Launcher.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\az-launcher\az-launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\az-launcher\qt5widgets.dll
c:\program files\az-launcher\qt5gui.dll
c:\program files\az-launcher\qt5core.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2232"C:\Users\admin\AppData\Local\Temp\is-1I7L2.tmp\AZ-Launcher_Setup.exe" /SPAWNWND=$10232 /NOTIFYWND=$10222 C:\Users\admin\AppData\Local\Temp\is-1I7L2.tmp\AZ-Launcher_Setup.exe
AZ-Launcher_Setup.tmp
User:
admin
Company:
AZ
Integrity Level:
HIGH
Description:
AZ Launcher - Minecraft (32 bits) Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\is-1i7l2.tmp\az-launcher_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2340"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2468 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2352"C:\Program Files\AZ-Launcher\AZ-Launcher.exe" --is-elevated --launcher-datadir "C:/Program Files/AZ-Launcher/runtime" --legacy-launcher-datadir "C:/Program Files/Pactify Launcher" --launcher-update-source "" --client-datadir C:/Users/admin/AppData/Roaming/.az-client --legacy-client-datadir C:/Users/admin/AppData/Roaming/.pactify --client-update-source ""C:\Program Files\AZ-Launcher\AZ-Launcher.exe
AZ-Launcher.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\az-launcher\az-launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\az-launcher\qt5widgets.dll
c:\program files\az-launcher\qt5gui.dll
c:\program files\az-launcher\qt5core.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2360"C:\Program Files\AZ-Launcher\AZ-Launcher.exe" C:\Program Files\AZ-Launcher\AZ-Launcher.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\az-launcher\az-launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\az-launcher\qt5widgets.dll
c:\program files\az-launcher\qt5gui.dll
c:\program files\az-launcher\qt5core.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2440"C:\Program Files\AZ-Launcher\vc_redist.x86.exe" /install /quiet /norestartC:\Program Files\AZ-Launcher\vc_redist.x86.exeAZ-Launcher_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27012
Exit code:
1638
Version:
14.16.27012.6
Modules
Images
c:\program files\az-launcher\vc_redist.x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 703
Read events
1 591
Write events
106
Delete events
6

Modification events

(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
3016137972
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30837343
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2468) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
37
Suspicious files
3
Text files
36
Unknown types
26

Dropped files

PID
Process
Filename
Type
2340iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab7FD3.tmp
MD5:
SHA256:
2340iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar7FD4.tmp
MD5:
SHA256:
2340iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AZ-Launcher_Installer.exe.9e257b8.partial
MD5:
SHA256:
2468iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF12152E5AE15258E5.TMP
MD5:
SHA256:
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\AZ-Launcher_Installer.exe.9e257b8.partial:Zone.Identifier
MD5:
SHA256:
236AZ-Launcher_Installer.tmpC:\Users\admin\AppData\Local\Temp\CabA387.tmp
MD5:
SHA256:
236AZ-Launcher_Installer.tmpC:\Users\admin\AppData\Local\Temp\TarA388.tmp
MD5:
SHA256:
3056AZ-Launcher_Setup.tmpC:\Program Files\AZ-Launcher\is-CG66B.tmp
MD5:
SHA256:
3056AZ-Launcher_Setup.tmpC:\Program Files\AZ-Launcher\is-OF3PN.tmp
MD5:
SHA256:
3056AZ-Launcher_Setup.tmpC:\Program Files\AZ-Launcher\is-RSFAN.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2340
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2352
AZ-Launcher.exe
104.18.56.196:443
www.az-launcher.nz
Cloudflare Inc
US
unknown
2224
AZ-Launcher.exe
104.18.56.196:443
www.az-launcher.nz
Cloudflare Inc
US
unknown
236
AZ-Launcher_Installer.tmp
104.18.56.196:443
www.az-launcher.nz
Cloudflare Inc
US
unknown
2340
iexplore.exe
104.18.56.196:443
www.az-launcher.nz
Cloudflare Inc
US
unknown
2340
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
www.az-launcher.nz
  • 104.18.56.196
  • 172.67.173.208
  • 104.18.57.196
unknown
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
Process
Message
AZ-Launcher.exe
Application file: "C:/Program Files/AZ-Launcher/AZ-Launcher.exe"
AZ-Launcher.exe
Elevate process...
AZ-Launcher.exe
Launcher data dir: "C:/Program Files/AZ-Launcher/runtime"
AZ-Launcher.exe
Client data dir: "C:/Users/admin/AppData/Roaming/.az-client"
AZ-Launcher.exe
Process elevation requested!
AZ-Launcher.exe
Launcher directory: "C:/Program Files/AZ-Launcher/runtime"
AZ-Launcher.exe
Application file: "C:/Program Files/AZ-Launcher/AZ-Launcher.exe"
AZ-Launcher.exe
Client data dir: "C:/Users/admin/AppData/Roaming/.az-client"
AZ-Launcher.exe
Elevate process...
AZ-Launcher.exe
Launcher data dir: "C:/Program Files/AZ-Launcher/runtime"