download:

/download

Full analysis: https://app.any.run/tasks/7b390e27-4e1c-461a-9b8d-ab7ef454a5ec
Verdict: Malicious activity
Analysis date: November 26, 2024, 18:55:58
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

CE5C07B80B5B217C41E8401F2F8A506B

SHA1:

226FDE4A6E8778019EFC7416EDDB7A0AB02968C0

SHA256:

49A04B61179E3B16FB0F1F126C7ABE1218A863E1C300942759696BC8D7E07B2A

SSDEEP:

98304:6+QqZ8fX9S4PKlCsmhSwvuCiaHvdJqGRHRDMMCpaRJT4CaX6957tOmffXoXmsso9:6thFSEGN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • download.exe (PID: 6544)
      • download.tmp (PID: 6572)
      • OneLaunch Setup_.exe (PID: 3524)
      • download.exe (PID: 4500)
      • download.tmp (PID: 4516)
      • OneLaunch Setup_.tmp (PID: 4244)
    • Reads the Windows owner or organization settings

      • download.tmp (PID: 6572)
    • There is functionality for taking screenshot (YARA)

      • download.tmp (PID: 6572)
      • download.tmp (PID: 4516)
      • OneLaunch Setup_.tmp (PID: 4244)
    • Uses TASKKILL.EXE to kill process

      • OneLaunch Setup_.tmp (PID: 4244)
    • Process drops legitimate windows executable

      • OneLaunch Setup_.tmp (PID: 4244)
    • The process drops Mozilla's DLL files

      • OneLaunch Setup_.tmp (PID: 4244)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 2408)
      • schtasks.exe (PID: 7068)
      • schtasks.exe (PID: 7008)
      • schtasks.exe (PID: 4504)
      • schtasks.exe (PID: 2008)
      • schtasks.exe (PID: 2164)
    • Application launched itself

      • chromium.exe (PID: 4996)
      • chromium.exe (PID: 7740)
      • chromium.exe (PID: 880)
    • Uses ICACLS.EXE to modify access control lists

      • OneLaunch Setup_.tmp (PID: 4244)
    • Executes application which crashes

      • OneLaunch Setup_.tmp (PID: 4244)
    • Starts CMD.EXE for commands execution

      • OneLaunch Setup_.tmp (PID: 4244)
    • Executing commands from a ".bat" file

      • OneLaunch Setup_.tmp (PID: 4244)
  • INFO

    • Create files in a temporary directory

      • download.exe (PID: 6544)
      • download.tmp (PID: 6572)
    • Checks supported languages

      • download.tmp (PID: 6572)
      • download.exe (PID: 6544)
    • Reads the computer name

      • download.tmp (PID: 6572)
    • Checks proxy server information

      • download.tmp (PID: 6572)
    • Manual execution by a user

      • OneLaunch.exe (PID: 7604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 09:48:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.33.0.0
ProductVersionNumber: 5.33.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.33.0
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.33.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
226
Monitored processes
90
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start download.exe download.tmp download.exe download.tmp onelaunch setup_.exe onelaunch setup_.tmp taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs onelaunch.exe chromium.exe chromium.exe chromium.exe onelaunchtray.exe chromium.exe no specs chromium.exe chromium.exe no specs cmd.exe no specs conhost.exe no specs chromium.exe chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs werfault.exe chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs werfault.exe no specs onelaunch.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs chromium.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-sandbox --no-pre-read-main-dll --no-subproc-heap-profiling --metrics-shmem-handle=4748,i,16001727419086088054,12953864394903871455,524288 --field-trial-handle=4772,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=4768 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
127.0.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.33.0\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
836"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --no-pre-read-main-dll --no-subproc-heap-profiling --no-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=35 --metrics-shmem-handle=6392,i,9858151346270917481,477928889697939075,2097152 --field-trial-handle=6432,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=6684 /prefetch:1C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
127.0.0.0
880C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\OneLaunch\User Data" /prefetch:4 --monitor-self --monitor-self-argument=--type=crashpad-handler "--monitor-self-argument=--user-data-dir=C:\Users\admin\AppData\Local\OneLaunch\User Data" --monitor-self-argument=/prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad" --annotation=plat=Win32 --annotation=prod=OneLaunch --annotation=ver=127.0.0.0 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x6fbcbc84,0x6fbcbc90,0x6fbcbc9cC:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
1
Version:
127.0.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.33.0\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1076"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=network --no-sandbox --no-pre-read-main-dll --no-subproc-heap-profiling --metrics-shmem-handle=2288,i,17536250792490519849,7599636250439810933,524288 --field-trial-handle=2184,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=2200 /prefetch:3C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Version:
127.0.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.33.0\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1140"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=renderer --instant-process --enable-dinosaur-easter-egg-alt-images --no-pre-read-main-dll --no-subproc-heap-profiling --no-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --metrics-shmem-handle=4204,i,2697222215569208983,5924188224642529846,2097152 --field-trial-handle=4252,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=4244 /prefetch:1C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
127.0.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.33.0\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1192"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=gpu-process --no-sandbox --no-pre-read-main-dll --no-subproc-heap-profiling --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAMAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --metrics-shmem-handle=1964,i,2437703296294418640,11656837781245796743,262144 --field-trial-handle=2164,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=2156 /prefetch:2C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Version:
127.0.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.33.0\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1216"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --no-pre-read-main-dll --no-subproc-heap-profiling --no-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=49 --metrics-shmem-handle=8132,i,1780290586132115627,13469733798455646288,2097152 --field-trial-handle=8084,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=8140 /prefetch:1C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
127.0.0.0
1412\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1488"C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exe" --type=renderer --extension-process --enable-dinosaur-easter-egg-alt-images --no-pre-read-main-dll --no-subproc-heap-profiling --no-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=51 --metrics-shmem-handle=1332,i,4871398411056310779,13001729145036233616,2097152 --field-trial-handle=6488,i,9781472784358332003,736425346028175899,262144 --variations-seed-version --mojo-platform-channel-handle=6652 /prefetch:2C:\Users\admin\AppData\Local\OneLaunch\5.33.0\chromium\chromium.exechromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
127.0.0.0
1556"C:\WINDOWS\system32\cmd.exe" /C ""C:\Users\admin\AppData\Local\Temp\delete_is-M2TV1.tmp.bat""C:\Windows\System32\cmd.exeOneLaunch Setup_.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
Total events
16 116
Read events
15 948
Write events
166
Delete events
2

Modification events

(PID) Process:(4516) download.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
A4110000B9C259EB3440DB01
(PID) Process:(4516) download.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
911722BB0C56B4E9199171FCD8EBC92CC51B33E4BB295B439A70A7726680D987
(PID) Process:(4516) download.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:version
Value:
5.33.0.0
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:assembly
Value:
C:\Users\admin\AppData\Local\OneLaunch\5.33.0\onelaunch.exe
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:install_info
Value:
{"install_time":1732647366,"distinct_id":"BF1B550D-4414-4AAE-98D0-AA045B297A3C","default_browser":"MSEdgeHTM","initinal_version":"5.33.0.0","packaged_browser":"chromium","split":"a","no_split":false,"split2":"b","server_side_split_28_11_ntp_distribution":"control","encoded_splits":"000"}
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:settings
Value:
{"search_url":"https://search.yahoo.com/yhs/search?hspart=reb&hsimp=yhs-ext_onelaunch&p={searchTerms}&type=0_1000_100_1000_100_691231","suggest_url":"https://us.search.yahoo.com/sugg/gossip/gossip-us-partner?output=fxjson&appid=reb&command={searchTerms}","amazon_url":"https://wbd_ol.ampxdirect.com/amazon?sub1=default&sub2=amazon","rich_suggest_url":"https://us.search.yahoo.com/sugg/gossip/gossip-us-fastbreak?command={searchTerms}&output=fxjson&appid=reb-rich","extensions":["hffgmnbojgnbalmhedkdikfhaflnfcno;https://chrmxtnsnhdnnlnch.onelaunch.com/ex?hf"],"new_tab_url":"https://onenews.com/v8/?s=https%3A%2F%2Fsearch.yahoo.com%2Fyhs%2Fsearch%3Fhspart%3Dreb%26hsimp%3Dyhs-ext_onelaunch%26p%3D%7BsearchTerms%7D%26type%3D0_1000_100_1000_100_241126","preload_extensions":["gcklppdiegejnfnpepkaagjmdneobkgi;https://static.slickdealscdn.com/attachment/extension/onelaunch/sd-3.6.8.crx"],"ob_new_tab_url":"https://onenews.com/v8/?s=https%3A%2F%2Fsearch.yahoo.com%2Fyhs%2Fsearch%3Fhspart%3Dreb%26hsimp%3Dyhs-ext_onelaunch%26p%3D%7BsearchTerms%7D%26type%3D0_1000_100_1000_100_241126","accuweather_api":"7f64ed3093d8436e994f9dc7e382a06a","thanks_url":"","url_app_overrides":["ebay_popular;https://ebay.com","ebay;https://ebay.com"],"search_name":"Yahoo!","type_tag":"0_1000_100_1000_100_241126","iframe_ntp_url":"https://onenews.com/v8/","is_ntp_iframe":"false"}
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:reinstall_count
Value:
0
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:attribution_keys
Value:
{"keyList":["nokey"]}
(PID) Process:(4244) OneLaunch Setup_.tmpKey:HKEY_CURRENT_USER\SOFTWARE\OneLaunch
Operation:writeName:update_count
Value:
0
Executable files
250
Suspicious files
389
Text files
333
Unknown types
37

Dropped files

PID
Process
Filename
Type
6572download.tmpC:\Users\admin\AppData\Local\Temp\is-TNMN6.tmp\is-MDE48.tmp
MD5:
SHA256:
6572download.tmpC:\Users\admin\AppData\Local\Temp\is-TNMN6.tmp\OneLaunch Setup.exe
MD5:
SHA256:
6572download.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
4516download.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe
MD5:
SHA256:
6544download.exeC:\Users\admin\AppData\Local\Temp\is-C73S6.tmp\download.tmpexecutable
MD5:4F1E4827E080754AC98753A05E5846B9
SHA256:D379EC5E2897187A7FA92A82F4FB246CCA419CC9EB351A1ED52DAAE24A84DA10
6572download.tmpC:\Users\admin\AppData\Local\Temp\is-TNMN6.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
3524OneLaunch Setup_.exeC:\Users\admin\AppData\Local\Temp\is-4BNN0.tmp\OneLaunch Setup_.tmpexecutable
MD5:7447873BC274F133E90D98F7B3198405
SHA256:A27543154E9573521F7CCA5B41F821DC23869E1FC98490742887162B00254717
6572download.tmpC:\Users\admin\AppData\Local\Temp\is-TNMN6.tmp\min-hover.bmpimage
MD5:C94A77553F2C392D5F1FE2F08E30EFB2
SHA256:8DAA69B6252F6F773CEB6D7090664B933537478731473E1B54CAF67791C2D336
6572download.tmpC:\Users\admin\AppData\Local\Temp\is-TNMN6.tmp\Win32Library.dllexecutable
MD5:30BC0348A293E90F4B5DF0F3977A46C2
SHA256:2548BFAE581617570CEBC5C30059CCCBA5299806639B73E77738608A9AA16B5B
6572download.tmpC:\Users\admin\AppData\Local\Temp\is-TNMN6.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
472
DNS requests
492
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5208
svchost.exe
GET
200
2.19.198.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5208
svchost.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6636
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6492
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6492
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6276
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/japrfto3glzuybauq4wkmtrqte_2024.11.18.0/niikhdgajlphfehepabhhblakbdgeefj_2024.11.18.00_all_acj3wrlm6xavgplit7omufnappaa.crx3
unknown
whitelisted
6940
WerFault.exe
GET
200
2.19.198.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6940
WerFault.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5208
svchost.exe
2.19.198.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5208
svchost.exe
23.218.209.163:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.177:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6572
download.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
suspicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.19.198.194
  • 23.32.238.34
whitelisted
google.com
  • 142.250.185.142
whitelisted
www.microsoft.com
  • 23.218.209.163
  • 88.221.169.152
whitelisted
www.bing.com
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.133
  • 2.23.209.189
  • 2.23.209.185
  • 2.23.209.182
  • 2.23.209.130
  • 2.23.209.193
  • 2.23.209.179
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
update.onelaunch.com
  • 104.26.12.224
  • 104.26.13.224
  • 172.67.68.170
unknown
api.keen.io
  • 52.33.34.207
  • 52.26.224.221
  • 34.223.147.252
whitelisted
login.live.com
  • 40.126.31.69
  • 40.126.31.73
  • 20.190.159.71
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.4
  • 20.190.159.68
  • 40.126.31.67
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Image Sharing Service (imgur.com)
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Process
Message
chromium.exe
[1126/185722.474:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad: The system cannot find the path specified. (0x3)
chromium.exe
[1126/185722.474:ERROR:registration_protocol_win.cc(136)] TransactNamedPipe: The pipe has been ended. (0x6D)
chromium.exe
[1126/185722.474:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad: The system cannot find the path specified. (0x3)
OneLaunch.exe
2024-11-26 18:57:23,677 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.33.0.0
OneLaunch.exe
2024-11-26 18:57:24,099 DEBUG [ 1] (Com.WebBar.Popups.PopupScheduler+PopupSchedule: 0) - scheduled popup slot app_wizard with ViewModel type AppWizardPopupViewModel to be shown at 11/26/2024 19:27:24 +00:00
onelaunchtray.exe
log4net:ERROR Appender named [Analytics] not found.
onelaunchtray.exe
log4net:ERROR XmlHierarchyConfigurator: No appender named [Analytics] could be found.
onelaunchtray.exe
Rebase.OneLaunch.Tray.TrayApp: 2024-11-26 18:57:24,614 [1] INFO - starting up
OneLaunch.exe
2024-11-26 18:57:25,568 DEBUG [ 1] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
OneLaunch.exe
2024-11-26 18:57:26,373 DEBUG [22] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location