File name:

ATLauncher-setup-1.3.0.0.exe

Full analysis: https://app.any.run/tasks/4c2e6cf6-570d-45b2-ab41-d0d9f68c1037
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 17, 2025, 12:12:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
inno
installer
delphi
adware
innosetup
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

9D56B8206CBC9F298DFE5991161EF21D

SHA1:

C4F531D4499676685C162C014E6024A441BED82C

SHA256:

4AC8068C83E84B9C9C09DCAD37120ED4041E72480C4E9A36543445DCB78432D2

SSDEEP:

98304:Z6GavilarPpxm7kWxWuMYp/tgpnpbpMnrYkSEZxcT1XG15aikVIFh8ECMiN/VW+1:1j6Nb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ATLauncher-setup-1.3.0.0.exe (PID: 6240)
      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • 7za.exe (PID: 5868)
      • javaw.exe (PID: 1096)
    • Reads the Windows owner or organization settings

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
    • Drops 7-zip archiver for unpacking

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 5868)
    • The process drops C-runtime libraries

      • 7za.exe (PID: 5868)
    • Uses REG/REGEDIT.EXE to modify registry

      • javaw.exe (PID: 1096)
    • Application launched itself

      • javaw.exe (PID: 1096)
    • Reads security settings of Internet Explorer

      • javaw.exe (PID: 1096)
    • The process checks if it is being run in the virtual environment

      • javaw.exe (PID: 1096)
  • INFO

    • Checks supported languages

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • ATLauncher-setup-1.3.0.0.exe (PID: 6240)
      • 7za.exe (PID: 5868)
      • javaw.exe (PID: 664)
      • ATLauncher.exe (PID: 5576)
      • javaw.exe (PID: 1096)
      • javaw.exe (PID: 5960)
      • java.exe (PID: 2644)
    • Reads the computer name

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • 7za.exe (PID: 5868)
      • javaw.exe (PID: 1096)
    • Create files in a temporary directory

      • ATLauncher-setup-1.3.0.0.exe (PID: 6240)
      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • javaw.exe (PID: 1096)
      • javaw.exe (PID: 664)
      • java.exe (PID: 2644)
      • javaw.exe (PID: 5960)
    • Detects InnoSetup installer (YARA)

      • ATLauncher-setup-1.3.0.0.exe (PID: 6240)
      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
    • Compiled with Borland Delphi (YARA)

      • ATLauncher-setup-1.3.0.0.exe (PID: 6240)
      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
    • Checks proxy server information

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • slui.exe (PID: 6476)
    • Reads the machine GUID from the registry

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • javaw.exe (PID: 1096)
    • The sample compiled with english language support

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • 7za.exe (PID: 5868)
    • Reads the software policy settings

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • slui.exe (PID: 6476)
    • Creates a software uninstall entry

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
    • Creates files or folders in the user directory

      • ATLauncher-setup-1.3.0.0.tmp (PID: 1312)
      • javaw.exe (PID: 1096)
      • 7za.exe (PID: 5868)
    • Reads CPU info

      • javaw.exe (PID: 664)
      • javaw.exe (PID: 1096)
      • javaw.exe (PID: 5960)
    • Process checks computer location settings

      • javaw.exe (PID: 1096)
    • Creates files in the program directory

      • java.exe (PID: 2644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:01:08 15:36:35+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 684032
InitializedDataSize: 529408
UninitializedDataSize: -
EntryPoint: 0xa7f98
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.0.0
ProductVersionNumber: 1.3.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ATLauncher
FileDescription: ATLauncher Setup
FileVersion: 1.3.0.0
LegalCopyright:
OriginalFileName:
ProductName: ATLauncher
ProductVersion: 1.3.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
16
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start atlauncher-setup-1.3.0.0.exe atlauncher-setup-1.3.0.0.tmp slui.exe 7za.exe conhost.exe no specs atlauncher.exe no specs javaw.exe no specs javaw.exe reg.exe no specs conhost.exe no specs java.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs javaw.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496C:\WINDOWS\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
664"C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -versionC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exeATLauncher.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.9.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\vcruntime140.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
720\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1052\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1088\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1096"C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -Djna.nosys=true -Djava.net.preferIPv4Stack=true -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true -classpath "C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe;lib\oshi-core-6.6.6.jar;lib\jna-platform-5.16.0.jar;lib\jna-5.16.0.jar;lib\gson-2.11.0.jar;lib\guava-33.4.0-jre.jar;lib\xz-1.10.jar;lib\base64-2.3.9.jar;lib\jopt-simple-5.0.4.jar;lib\zt-zip-1.17.jar;lib\sentry-8.0.0.jar;lib\gettext-lib-88ae68d897.jar;lib\murmur-1.0.0.jar;lib\jlhttp-3.2.jar;lib\joda-time-2.13.0.jar;lib\commonmark-0.21.0.jar;lib\dbus-java-3.3.2.jar;lib\nekodetector-Version-1.1-pre.jar;lib\imageio-webp-3.12.0.jar;lib\commons-compress-1.27.1.jar;lib\okhttp-tls-4.12.0.jar;lib\apollo-rx3-support-2.5.14.jar;lib\apollo-runtime-2.5.14.jar;lib\apollo-http-cache-2.5.14.jar;lib\okhttp-4.12.0.jar;lib\flatlaf-extras-3.5.4.jar;lib\flatlaf-3.5.4.jar;lib\log4j-core-2.24.3.jar;lib\log4j-api-2.24.3.jar;lib\rxswing-a5749ad421.jar;lib\rxjava-3.1.10.jar;lib\error_prone_annotations-2.36.0.jar;lib\failureaccess-1.0.2.jar;lib\listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar;lib\apollo-normalized-cache-jvm-2.5.14.jar;lib\cache-2.0.2.jar;lib\jsr305-3.0.2.jar;lib\checker-qual-3.43.0.jar;lib\j2objc-annotations-3.0.0.jar;lib\slf4j-api-2.0.16.jar;lib\antlr4-runtime-4.7.3.jar;lib\jnr-unixsocket-0.38.17.jar;lib\jnr-enxio-0.32.13.jar;lib\jnr-posix-3.1.15.jar;lib\jnr-ffi-2.2.11.jar;lib\asm-commons-9.2.jar;lib\asm-util-9.2.jar;lib\asm-analysis-9.2.jar;lib\asm-tree-9.5.jar;lib\asm-9.5.jar;lib\imageio-metadata-3.12.0.jar;lib\imageio-core-3.12.0.jar;lib\common-image-3.12.0.jar;lib\common-io-3.12.0.jar;lib\common-lang-3.12.0.jar;lib\commons-codec-1.17.1.jar;lib\commons-io-2.16.1.jar;lib\commons-lang3-3.16.0.jar;lib\apollo-http-cache-api-2.5.14.jar;lib\apollo-normalized-cache-api-jvm-2.5.14.jar;lib\apollo-api-jvm-2.5.14.jar;lib\okio-jvm-3.6.0.jar;lib\kotlin-stdlib-jdk8-1.9.10.jar;lib\jsvg-1.4.0.jar;lib\reactive-streams-1.0.4.jar;lib\jnr-constants-0.10.3.jar;lib\kotlin-stdlib-jdk7-1.9.10.jar;lib\uuid-jvm-0.2.0.jar;lib\kotlin-stdlib-1.9.10.jar;lib\jffi-1.3.9.jar;lib\jffi-1.3.9-native.jar;lib\jnr-a64asm-1.0.0.jar;lib\jnr-x86asm-1.0.2.jar;lib\kotlin-stdlib-common-1.9.10.jar;lib\annotations-13.0.jar" com.atlauncher.AppC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe
ATLauncher.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Version:
17.0.9.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1132reg query HKEY_LOCAL_MACHINE\Software\JavaSoft\ /f Home /t REG_SZ /s /reg:64C:\Windows\System32\reg.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1312"C:\Users\admin\AppData\Local\Temp\is-D5THD.tmp\ATLauncher-setup-1.3.0.0.tmp" /SL5="$A0296,1538498,1214464,C:\Users\admin\Desktop\ATLauncher-setup-1.3.0.0.exe" C:\Users\admin\AppData\Local\Temp\is-D5THD.tmp\ATLauncher-setup-1.3.0.0.tmp
ATLauncher-setup-1.3.0.0.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-d5thd.tmp\atlauncher-setup-1.3.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeicacls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2644"C:\Program Files\Java\jre1.8.0_271\bin\java.exe" -versionC:\Program Files\Java\jre1.8.0_271\bin\java.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
9 848
Read events
9 822
Write events
26
Delete events
0

Modification events

(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.4.0
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Roaming\ATLauncher
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\ATLauncher\
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
ATLauncher
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
desktopicon
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:Inno Setup: Language
Value:
english
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:DisplayName
Value:
ATLauncher Setup
(PID) Process:(1312) ATLauncher-setup-1.3.0.0.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F5FDA11-45A5-4CC3-8E51-5E11E2481697}_is1
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe
Executable files
107
Suspicious files
16
Text files
220
Unknown types
0

Dropped files

PID
Process
Filename
Type
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-MN00S.tmp\is-Q02A3.tmp
MD5:
SHA256:
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-MN00S.tmp\jre.zip
MD5:
SHA256:
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-MN00S.tmp\is-T4SIV.tmp
MD5:
SHA256:
6240ATLauncher-setup-1.3.0.0.exeC:\Users\admin\AppData\Local\Temp\is-D5THD.tmp\ATLauncher-setup-1.3.0.0.tmpexecutable
MD5:730EEB756F5A1120924D8CFE0696C2BC
SHA256:90AC2104FA150B68518E94E072CCC9F6FA67575ECEB9EA7BAD8A41F0EFA8A8D4
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-MN00S.tmp\ATLauncher.exeexecutable
MD5:3444D7FF38B0F7EDE8CECEA9C40E7734
SHA256:4ACC3760AA395EE027F7ACB0F2747317F6DA6B28923AF42D5E78FB6EF6F3F06A
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Roaming\ATLauncher\unins000.exeexecutable
MD5:F3C500E605567034D194EA0FC2A7A6F0
SHA256:A5ECD778D72A6725D21147278AB537B9E2ABDB7CC4A6DA93E0AEE0F7D52E4991
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ATLauncher\ATLauncher.lnkbinary
MD5:C93C15B6EB3C60AA1A7FE1556C080BDD
SHA256:B8B69EAA964CFE915F15DA899D6E23A9223D8E8E139693CF52763D95926CE54B
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-MN00S.tmp\7za.exeexecutable
MD5:43141E85E7C36E31B52B22AB94D5E574
SHA256:EA308C76A2F927B160A143D94072B0DCE232E04B751F0C6432A94E05164E716D
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-MN00S.tmp\is-K1SBH.tmpexecutable
MD5:43141E85E7C36E31B52B22AB94D5E574
SHA256:EA308C76A2F927B160A143D94072B0DCE232E04B751F0C6432A94E05164E716D
1312ATLauncher-setup-1.3.0.0.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ATLauncher\Uninstall ATLauncher.lnkbinary
MD5:062E8FA1489C4BFD46E0DA9F1B83322D
SHA256:FF8AC842FAB50161D0A6F0177CA5BD8A133CDB55A13F56335A81DCEC8E8B1155
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
34
DNS requests
11
Threats
4

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1312
ATLauncher-setup-1.3.0.0.tmp
172.67.11.201:443
download.nodecdn.net
CLOUDFLARENET
US
unknown
1312
ATLauncher-setup-1.3.0.0.tmp
140.82.121.3:443
github.com
GITHUB
US
whitelisted
1312
ATLauncher-setup-1.3.0.0.tmp
185.199.109.133:443
objects.githubusercontent.com
FASTLY
US
whitelisted
5176
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1096
javaw.exe
172.67.11.201:443
download.nodecdn.net
CLOUDFLARENET
US
unknown
1096
javaw.exe
35.186.247.156:443
sentry.io
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.78
whitelisted
download.nodecdn.net
  • 172.67.11.201
  • 104.22.68.118
  • 104.22.69.118
unknown
github.com
  • 140.82.121.3
whitelisted
objects.githubusercontent.com
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.108.133
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
sentry.io
  • 35.186.247.156
whitelisted
api.atlauncher.com
  • 104.21.96.1
  • 104.21.48.1
  • 104.21.32.1
  • 104.21.16.1
  • 104.21.64.1
  • 104.21.112.1
  • 104.21.80.1
whitelisted
paste.atlauncher.com
  • 104.21.16.1
  • 104.21.112.1
  • 104.21.64.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.80.1
  • 104.21.96.1
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
No debug info