| File name: | Rune Launcher.bat |
| Full analysis: | https://app.any.run/tasks/d509ff50-f439-4562-8837-85df08c2fb7c |
| Verdict: | Malicious activity |
| Analysis date: | November 25, 2023, 14:28:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines, with CRLF line terminators |
| MD5: | 7BC400C287E863D093E099A2A3D86D0A |
| SHA1: | 0C53D559FA4F3E58241F67986FE7C0D342671E20 |
| SHA256: | 420FB1238DD57CC2166770C49D1577EEDC64ACE3C130E5B10871B2E9B71F4C04 |
| SSDEEP: | 49152:uTP+Ip2MMykXMHOh7Ufks1muCwKWPM7J6QlHiVH7BRDS83Tm+fn907TA1HimUEQf:r |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 952 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2140 --field-trial-handle=1168,i,17753474378743290218,5983233420292587378,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1008 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1128 | "C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop" /prefetch:7 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Crashpad" --url=appcenter://generic?aid=a7417433-29d9-4bc0-8826-af367733939d&iid=ad142ee9-ecfe-4580-ec0f-259fb963ccd2&uid=ad142ee9-ecfe-4580-ec0f-259fb963ccd2 --annotation=IsOfficialBuild=1 --annotation=_companyName=Skype --annotation=_productName=skype-preview --annotation=_version=8.100.0.203 "--annotation=exe=C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --annotation=plat=Win32 --annotation=prod=Electron --annotation=ver=19.1.8 --initial-client-data=0x334,0x338,0x33c,0x330,0x340,0x82a3398,0x82a33a8,0x82a33b4 | C:\Program Files\Microsoft\Skype for Desktop\Skype.exe | Skype.exe | ||||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: MEDIUM Description: Skype Exit code: 0 Version: 8.100.0.203 Modules
| |||||||||||||||
| 1272 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x67978b38,0x67978b48,0x67978b54 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1460 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.1.1812790153\1052439460" -parentBuildID 20230710165010 -prefsHandle 1396 -prefMapHandle 1392 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {adcba207-2ba5-443e-b72b-cc1b59088ca0} 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 1408 ec1b5e0 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1668 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.3.624768554\1319439611" -childID 2 -isForBrowser -prefsHandle 2972 -prefMapHandle 2968 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 896 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a2c214ba-41cc-4e20-95aa-5fa5b1e69c1f} 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 2984 1d4fd3f0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1856 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1008.0.1725873247\1033536324" -parentBuildID 20230710165010 -prefsHandle 1104 -prefMapHandle 1096 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5fe2bee1-87c1-41ad-9f93-454249938f36} 1008 "\\.\pipe\gecko-crash-server-pipe.1008" 1204 cfa96c0 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 1860 | "C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop" --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --no-sandbox --no-zygote --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --ms-disable-indexeddb-transaction-timeout --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=1836 --field-trial-handle=1304,i,8951297569509710518,17400998026471833091,131072 --enable-features=WinUseBrowserSpellChecker,WinUseHybridSpellChecker,WinrtGeolocationImplementation --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand --skype-process-type=Main --skype-window-id=__MAIN_ROOT_VIEW_ID__ /prefetch:1 | C:\Program Files\Microsoft\Skype for Desktop\Skype.exe | — | Skype.exe | |||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: MEDIUM Description: Skype Exit code: 0 Version: 8.100.0.203 Modules
| |||||||||||||||
| 2092 | "C:\Program Files\Google\Chrome\Application\chrome.exe" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2428 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1064 --field-trial-handle=1168,i,17753474378743290218,5983233420292587378,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (3024) Rune Launcher.bat.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2460) Skype.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3528) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{46D2ACCE-72AA-4808-9623-D2FD93B627DF}\{AE060E1A-48A3-40B7-9966-3F566FFC349B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3528) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{46D2ACCE-72AA-4808-9623-D2FD93B627DF} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3528) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{67414F24-C9C7-4CFB-B8F1-0565A3776E94} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3268) ONENOTE.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (3268) ONENOTE.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: On | |||
| (PID) Process: | (3268) ONENOTE.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: On | |||
| (PID) Process: | (3268) ONENOTE.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: On | |||
| (PID) Process: | (3268) ONENOTE.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: On | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old~RF1d14a4.TMP | text | |
MD5:E1DDEA1CF3B526AB5670B1BD5DB17961 | SHA256:CC37017D6A77C63A9786DC9E7555696B1C862745F1A35D24672D981D7E44F42F | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\4E43N1D4CUUM8LCLI5B4.temp | binary | |
MD5:47F942424BF006D023A0B4505A3711AB | SHA256:97CF99F6C785082A0041A08526239159508878AE85837993B4EE4C9AABF5C235 | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b916037c1e115fe0.customDestinations-ms | binary | |
MD5:47F942424BF006D023A0B4505A3711AB | SHA256:97CF99F6C785082A0041A08526239159508878AE85837993B4EE4C9AABF5C235 | |||
| 2584 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\Cache_Data\f_000001 | binary | |
MD5:4604E676A0A7D18770853919E24EC465 | SHA256:A075B01D9B015C616511A9E87DA77DA3D9881621DB32F584E4606DDABF1C1100 | |||
| 2980 | cmd.exe | C:\Users\admin\AppData\Local\Temp\Rune Launcher.bat.exe | executable | |
MD5:92F44E405DB16AC55D97E3BFE3B132FA | SHA256:6C05E11399B7E3C8ED31BAE72014CF249C144A8F4A2C54A758EB2E6FAD47AEC7 | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b916037c1e115fe0.customDestinations-ms~RF1d1521.TMP | binary | |
MD5:E4A1661C2C886EBB688DEC494532431C | SHA256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5 | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Dictionaries\en-US-10-1.bdic | binary | |
MD5:4604E676A0A7D18770853919E24EC465 | SHA256:A075B01D9B015C616511A9E87DA77DA3D9881621DB32F584E4606DDABF1C1100 | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old | text | |
MD5:B4DCEF7068BF63E8D712B7528F1E9932 | SHA256:87D49743322980F35B8BAFDA3A6CDE33CCF9F03C4610782DA596CFCEB7CD873B | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Crashpad\settings.dat | binary | |
MD5:5D187988D1591D3FD80F3EEA284F3A4D | SHA256:ADACD52C6DAEA932EE305C540588D43B2FEE1A1307D7E98B84778A10D104646B | |||
| 2460 | Skype.exe | C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json | binary | |
MD5:0BCF67703377596741628EC37DF8D67A | SHA256:B23B8EE723EC0CF5651A2182F63AEEB51C3CB2FA3488A8DDC0274C2BA2BF1912 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1008 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | DE | binary | 503 b | unknown |
1008 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://ocsp.pki.goog/gts1c3 | US | binary | 472 b | unknown |
1008 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | DE | binary | 503 b | unknown |
1008 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | DE | binary | 503 b | unknown |
1008 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | unknown |
1008 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | DE | binary | 503 b | unknown |
1008 | firefox.exe | POST | 200 | 52.222.229.217:80 | http://ocsp.r2m02.amazontrust.com/ | US | binary | 471 b | unknown |
1008 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | DE | binary | 503 b | unknown |
1008 | firefox.exe | POST | 200 | 184.24.77.56:80 | http://r3.o.lencr.org/ | DE | binary | 503 b | unknown |
1008 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2460 | Skype.exe | 52.113.194.133:443 | get.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2460 | Skype.exe | 13.107.42.16:443 | a.config.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2460 | Skype.exe | 104.208.16.90:443 | pipe.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2584 | Skype.exe | 142.250.185.78:443 | redirector.gvt1.com | GOOGLE | US | whitelisted |
2460 | Skype.exe | 23.213.164.171:443 | download.skype.com | AKAMAI-AS | DE | unknown |
2584 | Skype.exe | 95.168.222.204:443 | r1---sn-n02xgoxufvg3-2gb6.gvt1.com | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
get.skype.com |
| whitelisted |
a.config.skype.com |
| whitelisted |
pipe.skype.com |
| whitelisted |
redirector.gvt1.com |
| whitelisted |
download.skype.com |
| whitelisted |
r1---sn-n02xgoxufvg3-2gb6.gvt1.com |
| whitelisted |
gateway.bingviz.microsoftapp.net |
| unknown |
login.live.com |
| whitelisted |
acctcdn.msauth.net |
| whitelisted |
logincdn.msauth.net |
| whitelisted |
Process | Message |
|---|---|
Skype.exe | [1125/143021.563:ERROR:filesystem_win.cc(130)] GetFileAttributes C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Crashpad\attachments\3a0ee62b-79ac-4cc3-bbd5-f65252e7a91f: The system cannot find the file specified. (0x2)
|