| File name: | Onelaunch Software.exe |
| Full analysis: | https://app.any.run/tasks/919b6a64-183d-4cdb-a910-0cfebae2e230 |
| Verdict: | Malicious activity |
| Analysis date: | December 29, 2023, 14:08:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 306425979B5AA1D854CBA9BFCE09B2B1 |
| SHA1: | 4E8AF2004A77F531E655E2E5CB669C388D0655C9 |
| SHA256: | 6208ACC0F0333A79EFCB375E127926116CC771D6D6585098206B6F99C79609E0 |
| SSDEEP: | 98304:N+QqZ8fXEcLnUerTfc2yVdK3SM6qo8vj0eW8RMOaNNL4hkz4ceHfyXpyrDLgJwjM:VFHzeGo |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:11:15 10:48:30+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 151552 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.26.0.0 |
| ProductVersionNumber: | 5.26.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | OneLaunch |
| FileDescription: | OneLaunch Setup |
| FileVersion: | 5.26.0 |
| LegalCopyright: | Copyright OneLaunch. All rights reserved. |
| OriginalFileName: | |
| ProductName: | OneLaunch |
| ProductVersion: | 5.26.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Users\admin\AppData\Local\Temp\is-FRHRI.tmp\OneLaunch Setup_.tmp" /SL5="$201B6,104703795,893952,C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE3MDM4NTg5MTAsImRpc3RpbmN0X2lkIjoiN0Q2RDg3RTQtMkIwQy00OTYxLTk2QjctODRCQkYwQzQ1RTRBIiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjYuMC4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImEiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNlcnZlcl9zaWRlX3NwbGl0XzI4XzExX250cF9kaXN0cmlidXRpb24iOiJjb250cm9sIiwic2VydmVyX3NpZGVfc3BsaXRfMjNfMTBfZW5oYW5jZWRfc2VhcmNoX2Fzc2lzdCI6InZhcmlhdGlvbiIsInNwbGl0XzIyXzEyX21vcmVfZWR1Y2F0aW9uYWxfbWluaXByb21wdHMiOiJ2YXJpYXRpb24iLCJlbmNvZGVkX3NwbGl0cyI6IjAwMCJ9 | C:\Users\admin\AppData\Local\Temp\is-FRHRI.tmp\OneLaunch Setup_.tmp | OneLaunch Setup_.exe | ||||||||||||
User: admin Company: OneLaunch Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 492 | "C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE3MDM4NTg5MTAsImRpc3RpbmN0X2lkIjoiN0Q2RDg3RTQtMkIwQy00OTYxLTk2QjctODRCQkYwQzQ1RTRBIiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjYuMC4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImEiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNlcnZlcl9zaWRlX3NwbGl0XzI4XzExX250cF9kaXN0cmlidXRpb24iOiJjb250cm9sIiwic2VydmVyX3NpZGVfc3BsaXRfMjNfMTBfZW5oYW5jZWRfc2VhcmNoX2Fzc2lzdCI6InZhcmlhdGlvbiIsInNwbGl0XzIyXzEyX21vcmVfZWR1Y2F0aW9uYWxfbWluaXByb21wdHMiOiJ2YXJpYXRpb24iLCJlbmNvZGVkX3NwbGl0cyI6IjAwMCJ9 | C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe | — | Onelaunch Software.tmp | |||||||||||
User: admin Company: OneLaunch Integrity Level: MEDIUM Description: OneLaunch Setup Exit code: 0 Version: 5.26.0 Modules
| |||||||||||||||
| 572 | "C:\Windows\System32\taskkill.exe" /f /im onelaunch.exe | C:\Windows\System32\taskkill.exe | — | OneLaunch Setup_.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 984 | "schtasks" /delete /tn ChromiumLaunchTask /f | C:\Windows\System32\schtasks.exe | — | OneLaunch Setup_.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1232 | "schtasks" /Delete /TN "ChromiumLaunchTask" /F | C:\Windows\System32\schtasks.exe | — | OneLaunch Setup_.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1736 | "C:\Windows\System32\taskkill.exe" /f /im onelaunchtray.exe | C:\Windows\System32\taskkill.exe | — | OneLaunch Setup_.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1848 | "C:\Windows\System32\taskkill.exe" /f /im chromium.exe | C:\Windows\System32\taskkill.exe | — | OneLaunch Setup_.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1860 | "C:\Users\admin\AppData\Local\OneLaunch\5.26.0\chromium\chromium.exe" --start-maximized --tab-trigger=Launch | C:\Users\admin\AppData\Local\OneLaunch\5.26.0\chromium\chromium.exe | OneLaunch Setup_.tmp | ||||||||||||
User: admin Company: OneLaunch Integrity Level: MEDIUM Description: OneLaunch Exit code: 3221225785 Version: 118.0.0.0 Modules
| |||||||||||||||
| 2044 | "C:\Users\admin\AppData\Local\Temp\is-0E37Q.tmp\Onelaunch Software.tmp" /SL5="$401A8,2484193,893952,C:\Users\admin\AppData\Local\Temp\Onelaunch Software.exe" | C:\Users\admin\AppData\Local\Temp\is-0E37Q.tmp\Onelaunch Software.tmp | Onelaunch Software.exe | ||||||||||||
User: admin Company: OneLaunch Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2124 | "C:\Users\admin\AppData\Local\Temp\Onelaunch Software.exe" | C:\Users\admin\AppData\Local\Temp\Onelaunch Software.exe | — | explorer.exe | |||||||||||
User: admin Company: OneLaunch Integrity Level: MEDIUM Description: OneLaunch Setup Exit code: 0 Version: 5.26.0 Modules
| |||||||||||||||
| (PID) Process: | (2044) Onelaunch Software.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2044) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2044) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2044) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2044) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2408) Onelaunch Software.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2408) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2408) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2408) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2408) Onelaunch Software.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\is-K327H.tmp\is-HGVVT.tmp | — | |
MD5:— | SHA256:— | |||
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\is-K327H.tmp\OneLaunch Setup.exe | — | |
MD5:— | SHA256:— | |||
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe | — | |
MD5:— | SHA256:— | |||
| 2408 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe | — | |
MD5:— | SHA256:— | |||
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\is-K327H.tmp\onelaunch.png | image | |
MD5:D3110FB775EE7FD24426503D67840C25 | SHA256:F8392390DC81756E79EC5F359DBDCAC3B4BD219B5188A429B814FC51AABB6E36 | |||
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\is-K327H.tmp\min-10-dark.png | image | |
MD5:14CA04108E5AC6A1B8C7A2B689382E44 | SHA256:9CB22401A923DFECAFC5F51DACEF5CBAE440B53B9932217C6BC4626F04920929 | |||
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\is-K327H.tmp\min-hover.bmp | image | |
MD5:E08B0A658E4A166C5461C542BE2B0D2F | SHA256:6F696C0C59CEDD0456270BCC868B6B3D7CBCA43911390904014F532CD7B131D5 | |||
| 2124 | Onelaunch Software.exe | C:\Users\admin\AppData\Local\Temp\is-0E37Q.tmp\Onelaunch Software.tmp | executable | |
MD5:043C6CCAFF1B885DE5617DAB68BE7AAD | SHA256:9E3300BE102567F9245ECAD4124EAD8AEA88F975F8D8354C34AFF8F4F34F30E1 | |||
| 2256 | Onelaunch Software.exe | C:\Users\admin\AppData\Local\Temp\is-I1B4V.tmp\Onelaunch Software.tmp | executable | |
MD5:043C6CCAFF1B885DE5617DAB68BE7AAD | SHA256:9E3300BE102567F9245ECAD4124EAD8AEA88F975F8D8354C34AFF8F4F34F30E1 | |||
| 2044 | Onelaunch Software.tmp | C:\Users\admin\AppData\Local\Temp\is-K327H.tmp\min-rest.bmp | image | |
MD5:C32BFC11F1A32BAB6A1ED327C8A89E0E | SHA256:24BEE6D5DA65DC8A65EB639E3C189F257BC4B231940BD078BBEA23BA985EABB5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2452 | OneLaunch.exe | GET | 301 | 172.67.14.199:80 | http://nc.onenews.com/api/precomputed/?category=NC1&source_type=Domains&headlines_type=head_NA&threshold=0.6&last_n_hours=24&sort=date&number=100 | unknown | — | — | unknown |
2452 | OneLaunch.exe | GET | 200 | 23.36.163.6:80 | http://api.accuweather.com/locations/v1/cities/ipaddress?&apikey=7f64ed3093d8436e994f9dc7e382a06a | unknown | binary | 1.06 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2044 | Onelaunch Software.tmp | 172.67.68.170:443 | update.onelaunch.com | CLOUDFLARENET | US | unknown |
2044 | Onelaunch Software.tmp | 44.225.134.164:443 | api.keen.io | AMAZON-02 | US | unknown |
2044 | Onelaunch Software.tmp | 130.211.34.183:443 | api.mixpanel.com | GOOGLE | US | whitelisted |
2044 | Onelaunch Software.tmp | 104.26.12.224:443 | update.onelaunch.com | CLOUDFLARENET | US | unknown |
2044 | Onelaunch Software.tmp | 52.35.210.93:443 | api.keen.io | AMAZON-02 | US | unknown |
2408 | Onelaunch Software.tmp | 172.67.68.170:443 | update.onelaunch.com | CLOUDFLARENET | US | unknown |
268 | OneLaunch Setup_.tmp | 52.35.210.93:443 | api.keen.io | AMAZON-02 | US | unknown |
268 | OneLaunch Setup_.tmp | 130.211.34.183:443 | api.mixpanel.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
update.onelaunch.com |
| unknown |
api.keen.io |
| whitelisted |
api.mixpanel.com |
| whitelisted |
release-cdn.onelaunch.com |
| unknown |
api.accuweather.com |
| unknown |
youtube.com |
| whitelisted |
facebook.com |
| whitelisted |
www.youtube.com |
| whitelisted |
www.facebook.com |
| whitelisted |
reddit.com |
| whitelisted |
Process | Message |
|---|---|
OneLaunch.exe | 2023-12-29 14:11:10,637 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.26.0.0
|
OneLaunch.exe | 2023-12-29 14:11:10,981 DEBUG [ 1] (Com.WebBar.Popups.PopupScheduler+PopupSchedule: 0) - scheduled popup slot app_wizard with ViewModel type AppWizardPopupViewModel to be shown at 12/29/2023 14:41:10 +00:00
|
onelaunchtray.exe | log4net:ERROR XmlHierarchyConfigurator: No appender named [Analytics] could be found.
|
onelaunchtray.exe | log4net:ERROR Appender named [Analytics] not found.
|
onelaunchtray.exe | Rebase.OneLaunch.Tray.TrayApp: 2023-12-29 14:11:11,715 [1] INFO - starting up
|
OneLaunch.exe | 2023-12-29 14:11:11,747 DEBUG [ 1] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
|
OneLaunch.exe | 2023-12-29 14:11:12,276 DEBUG [ 6] (Com.WebBar.Util.UserActivityDetector: 0) - first run or minimum interval expired
|
OneLaunch.exe | 2023-12-29 14:11:12,276 DEBUG [ 6] (Com.WebBar.Util.UserActivityDetector: 0) - idle for 0:00:21.579
|
OneLaunch.exe | 2023-12-29 14:11:15,293 DEBUG [ 6] (Com.WebBar.Util.UserActivityDetector: 0) - idle for 0:00:00.047
|
OneLaunch.exe | 2023-12-29 14:11:15,293 DEBUG [ 6] (Com.WebBar.Util.UserActivityDetector: 0) - raising ActivityDetected
|