File name:

Onelaunch Software.exe

Full analysis: https://app.any.run/tasks/69d9c1c3-93da-44d6-b659-ee9dba3abbb5
Verdict: Malicious activity
Analysis date: December 15, 2023, 22:28:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

306425979B5AA1D854CBA9BFCE09B2B1

SHA1:

4E8AF2004A77F531E655E2E5CB669C388D0655C9

SHA256:

6208ACC0F0333A79EFCB375E127926116CC771D6D6585098206B6F99C79609E0

SSDEEP:

98304:N+QqZ8fXEcLnUerTfc2yVdK3SM6qo8vj0eW8RMOaNNL4hkz4ceHfyXpyrDLgJwjM:VFHzeGo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.exe (PID: 2540)
      • Onelaunch Software.exe (PID: 1560)
      • OneLaunch Setup_.exe (PID: 2976)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.tmp (PID: 2868)
    • Uses Task Scheduler to run other applications

      • OneLaunch Setup_.tmp (PID: 2868)
    • Create files in the Startup directory

      • OneLaunch Setup_.tmp (PID: 2868)
    • Actions looks like stealing of personal data

      • chromium.exe (PID: 3812)
      • OneLaunch.exe (PID: 276)
      • OneLaunch Setup_.tmp (PID: 2868)
    • Changes the autorun value in the registry

      • OneLaunch.exe (PID: 276)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.tmp (PID: 2868)
      • OneLaunch.exe (PID: 276)
      • onelaunchtray.exe (PID: 3876)
    • Reads settings of System Certificates

      • Onelaunch Software.tmp (PID: 3264)
      • OneLaunch Setup_.tmp (PID: 2868)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch.exe (PID: 276)
    • Reads the Windows owner or organization settings

      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.tmp (PID: 2868)
    • Uses TASKKILL.EXE to kill process

      • OneLaunch Setup_.tmp (PID: 2868)
    • The process drops Mozilla's DLL files

      • OneLaunch Setup_.tmp (PID: 2868)
    • Process drops legitimate windows executable

      • OneLaunch Setup_.tmp (PID: 2868)
      • chrome.exe (PID: 1248)
  • INFO

    • Checks supported languages

      • Onelaunch Software.exe (PID: 1560)
      • wmpnscfg.exe (PID: 2632)
      • Onelaunch Software.exe (PID: 2540)
      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.exe (PID: 2976)
      • OneLaunch Setup_.tmp (PID: 2868)
      • OneLaunch.exe (PID: 276)
      • onelaunchtray.exe (PID: 3876)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2632)
      • chrome.exe (PID: 1248)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2632)
      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.tmp (PID: 2868)
      • OneLaunch.exe (PID: 276)
      • onelaunchtray.exe (PID: 3876)
    • Create files in a temporary directory

      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.exe (PID: 2540)
      • Onelaunch Software.exe (PID: 1560)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.tmp (PID: 2868)
      • OneLaunch Setup_.exe (PID: 2976)
    • Reads the machine GUID from the registry

      • Onelaunch Software.tmp (PID: 3264)
      • Onelaunch Software.tmp (PID: 2424)
      • OneLaunch Setup_.tmp (PID: 2868)
      • OneLaunch.exe (PID: 276)
      • onelaunchtray.exe (PID: 3876)
    • Creates files or folders in the user directory

      • OneLaunch.exe (PID: 276)
      • OneLaunch Setup_.tmp (PID: 2868)
      • onelaunchtray.exe (PID: 3876)
    • Creates files in the program directory

      • OneLaunch.exe (PID: 276)
      • onelaunchtray.exe (PID: 3876)
    • Reads Environment values

      • OneLaunch.exe (PID: 276)
    • Drops the executable file immediately after the start

      • chrome.exe (PID: 1248)
    • Application launched itself

      • chrome.exe (PID: 1248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 10:48:30+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.26.0.0
ProductVersionNumber: 5.26.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.26.0
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.26.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
84
Monitored processes
34
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start onelaunch software.exe no specs onelaunch software.tmp wmpnscfg.exe no specs onelaunch software.exe no specs onelaunch software.tmp onelaunch setup_.exe no specs onelaunch setup_.tmp taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs onelaunch.exe chromium.exe onelaunchtray.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
276"C:\Users\admin\AppData\Local\OneLaunch\5.26.0\onelaunch.exe" /l /startedFrom=installerC:\Users\admin\AppData\Local\OneLaunch\5.26.0\OneLaunch.exe
OneLaunch Setup_.tmp
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
5.26.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.26.0\onelaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
316"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x5f2f8b38,0x5f2f8b48,0x5f2f8b54C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
476"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1440 --field-trial-handle=1132,i,18009005260739746435,16934644236598685981,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1248"C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1356"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3624 --field-trial-handle=1132,i,18009005260739746435,16934644236598685981,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1560"C:\Users\admin\AppData\Local\Temp\Onelaunch Software.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE3MDI2NzkzNDEsImRpc3RpbmN0X2lkIjoiODZFQUVGOEItQzY0RS00NjkxLTlGMjMtMkY3NzM0Q0VFMDA3IiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjYuMC4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImIiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18xMF9lbmhhbmNlZF9zZWFyY2hfYXNzaXN0IjoidmFyaWF0aW9uIiwic2VydmVyX3NpZGVfc3BsaXRfMjhfMTFfbnRwX2Rpc3RyaWJ1dGlvbiI6ImNvbnRyb2wiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNwbGl0XzIyXzEyX21vcmVfZWR1Y2F0aW9uYWxfbWluaXByb21wdHMiOiJ2YXJpYXRpb24iLCJlbmNvZGVkX3NwbGl0cyI6IjAwMCJ9 /LAUNCHER /VERYSILENTC:\Users\admin\AppData\Local\Temp\Onelaunch Software.exeOnelaunch Software.tmp
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
0
Version:
5.26.0
Modules
Images
c:\users\admin\appdata\local\temp\onelaunch software.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1612"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1076 --field-trial-handle=1132,i,18009005260739746435,16934644236598685981,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1696"C:\Windows\System32\taskkill.exe" /f /im chromium.exeC:\Windows\System32\taskkill.exeOneLaunch Setup_.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2196"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3508 --field-trial-handle=1132,i,18009005260739746435,16934644236598685981,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2312"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2076 --field-trial-handle=1132,i,18009005260739746435,16934644236598685981,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
20 873
Read events
20 753
Write events
120
Delete events
0

Modification events

(PID) Process:(3264) Onelaunch Software.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3264) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3264) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3264) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3264) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2424) Onelaunch Software.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2424) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2424) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2424) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2424) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
247
Suspicious files
224
Text files
191
Unknown types
3

Dropped files

PID
Process
Filename
Type
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-3LNGF.tmp\is-NB56M.tmp
MD5:
SHA256:
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-3LNGF.tmp\OneLaunch Setup.exe
MD5:
SHA256:
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
2424Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe
MD5:
SHA256:
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-3LNGF.tmp\Win32Library.dllexecutable
MD5:7333593D8EE94D2E6BE1FD236E14A8A9
SHA256:E7A4CDE58670895CC16EBDD87CE6B677F07A550E469CB6D8484766C1230409BC
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-3LNGF.tmp\min-10-dark.pngimage
MD5:14CA04108E5AC6A1B8C7A2B689382E44
SHA256:9CB22401A923DFECAFC5F51DACEF5CBAE440B53B9932217C6BC4626F04920929
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-3LNGF.tmp\onelaunch.bmpimage
MD5:6A360D71735931F6DEED2F1FC0D1E0A0
SHA256:98F2C973DF13A6B642274E76F9DF0E5C04D213958BDDB0693A7C4F689C64DFCB
3264Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-3LNGF.tmp\min-pressed.bmpimage
MD5:CC62DDE39B9CAA24626A3A0EB93C70FA
SHA256:8D25A76A6552A927407CB0D7BA1E61E8644D76420C2690F8CB3DB90F75ECC1E7
2868OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-3SCSG.tmp\exit-10-dark.pngimage
MD5:B422C1A63AF9DD5B4B1E6D61FBEC6802
SHA256:0E774C6FF8143D4A0F4071AD69EBF85D1C55CB9A3950E26E2786A4329F2A3E6B
2868OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-3SCSG.tmp\exit-hover.bmpimage
MD5:F98B9E4D774BBA8181BEE7EEF1F1664C
SHA256:7161CFB43045E561A411795858CC586A18D90C8FE220EE2887316969A0CC05D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
261
DNS requests
79
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
276
OneLaunch.exe
GET
200
184.86.251.141:80
http://api.accuweather.com/locations/v1/cities/ipaddress?&apikey=7f64ed3093d8436e994f9dc7e382a06a
DE
binary
1.06 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3264
Onelaunch Software.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
3264
Onelaunch Software.tmp
52.33.136.252:443
api.keen.io
AMAZON-02
US
unknown
3264
Onelaunch Software.tmp
35.190.25.25:443
api.mixpanel.com
GOOGLE
US
whitelisted
3264
Onelaunch Software.tmp
104.26.13.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
3264
Onelaunch Software.tmp
34.210.161.55:443
api.keen.io
AMAZON-02
US
unknown
2424
Onelaunch Software.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
update.onelaunch.com
  • 104.26.12.224
  • 104.26.13.224
  • 172.67.68.170
unknown
api.keen.io
  • 52.33.136.252
  • 52.12.201.196
  • 34.210.161.55
whitelisted
api.mixpanel.com
  • 35.190.25.25
  • 107.178.240.159
  • 130.211.34.183
  • 35.186.241.51
whitelisted
release-cdn.onelaunch.com
  • 104.26.13.224
  • 172.67.68.170
  • 104.26.12.224
unknown
api.accuweather.com
  • 184.86.251.141
  • 184.86.251.159
unknown
youtube.com
  • 142.250.184.238
whitelisted
facebook.com
  • 157.240.251.35
whitelisted
www.youtube.com
  • 142.250.185.238
  • 172.217.16.142
  • 142.250.74.206
  • 142.250.186.142
  • 142.250.181.238
  • 216.58.212.174
  • 142.250.186.110
  • 142.250.186.78
  • 142.250.184.238
  • 142.250.184.206
  • 142.250.185.110
  • 142.250.185.174
  • 142.250.185.78
  • 142.250.186.46
  • 142.250.185.206
  • 142.250.185.142
whitelisted
www.facebook.com
  • 157.240.252.35
whitelisted
reddit.com
  • 151.101.129.140
  • 151.101.1.140
  • 151.101.65.140
  • 151.101.193.140
whitelisted

Threats

No threats detected
Process
Message
OneLaunch.exe
2023-12-15 22:30:57,730 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.26.0.0
OneLaunch.exe
2023-12-15 22:30:57,918 DEBUG [ 1] (Com.WebBar.Popups.PopupScheduler+PopupSchedule: 0) - scheduled popup slot app_wizard with ViewModel type AppWizardPopupViewModel to be shown at 12/15/2023 23:00:57 +00:00
OneLaunch.exe
2023-12-15 22:30:58,262 DEBUG [ 1] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
onelaunchtray.exe
log4net:ERROR XmlHierarchyConfigurator: No appender named [Analytics] could be found.
onelaunchtray.exe
log4net:ERROR Appender named [Analytics] not found.
onelaunchtray.exe
Rebase.OneLaunch.Tray.TrayApp: 2023-12-15 22:30:58,334 [1] INFO - starting up
OneLaunch.exe
2023-12-15 22:30:58,454 DEBUG [17] (Com.WebBar.Util.UserActivityDetector: 0) - raising ActivityDetected
OneLaunch.exe
2023-12-15 22:30:58,453 DEBUG [17] (Com.WebBar.Util.UserActivityDetector: 0) - idle for 0:00:00
OneLaunch.exe
2023-12-15 22:30:58,453 DEBUG [17] (Com.WebBar.Util.UserActivityDetector: 0) - first run or minimum interval expired
OneLaunch.exe
2023-12-15 22:31:01,463 DEBUG [ 5] (Com.WebBar.Util.UserActivityDetector: 0) - waiting for minimum interval to expire