File name:

OneLaunch - ManualsLibrary_f7acl.exe

Full analysis: https://app.any.run/tasks/e5246d08-28e0-4e9a-8b6c-5550966d20e4
Verdict: Malicious activity
Analysis date: May 28, 2024, 01:52:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2D083E880E7DC3554F2561BCF21CD23D

SHA1:

8AA9E9F69636A354722CF7E3FC391E9A510E19C9

SHA256:

6B3F1414D14CDA0B582420FFE7F1484356882FCC21E7FB1A19AB86008CA57B70

SSDEEP:

98304:x+QqZ8fXANzKEZKw1vknbamyM2bcihyptBtDODgRrjJyNHNJOWpvbUSnduGQXOCi:Z1BGx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OneLaunch - ManualsLibrary_f7acl.exe (PID: 3984)
      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OneLaunch - ManualsLibrary_f7acl.exe (PID: 3984)
      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
    • Reads the Windows owner or organization settings

      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
    • Reads settings of System Certificates

      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
    • Reads the Internet Settings

      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
  • INFO

    • Checks supported languages

      • OneLaunch - ManualsLibrary_f7acl.exe (PID: 3984)
      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
      • wmpnscfg.exe (PID: 4088)
    • Reads the computer name

      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
      • wmpnscfg.exe (PID: 4088)
    • Create files in a temporary directory

      • OneLaunch - ManualsLibrary_f7acl.exe (PID: 3984)
      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
    • Reads the software policy settings

      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
    • Reads the machine GUID from the registry

      • OneLaunch - ManualsLibrary_f7acl.tmp (PID: 4000)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 4088)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 09:48:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.31.3.0
ProductVersionNumber: 5.31.3.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.31.3
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.31.3
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start onelaunch - manualslibrary_f7acl.exe onelaunch - manualslibrary_f7acl.tmp wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3984"C:\Users\admin\Desktop\OneLaunch - ManualsLibrary_f7acl.exe" C:\Users\admin\Desktop\OneLaunch - ManualsLibrary_f7acl.exe
explorer.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Version:
5.31.3
Modules
Images
c:\users\admin\desktop\onelaunch - manualslibrary_f7acl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4000"C:\Users\admin\AppData\Local\Temp\is-RNNR6.tmp\OneLaunch - ManualsLibrary_f7acl.tmp" /SL5="$20138,2484213,893952,C:\Users\admin\Desktop\OneLaunch - ManualsLibrary_f7acl.exe" C:\Users\admin\AppData\Local\Temp\is-RNNR6.tmp\OneLaunch - ManualsLibrary_f7acl.tmp
OneLaunch - ManualsLibrary_f7acl.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rnnr6.tmp\onelaunch - manualslibrary_f7acl.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
4088"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
4 817
Read events
4 800
Write events
17
Delete events
0

Modification events

(PID) Process:(4000) OneLaunch - ManualsLibrary_f7acl.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A00F00009EE1BAC3A1B0DA01
(PID) Process:(4000) OneLaunch - ManualsLibrary_f7acl.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
379153F44125DD5A6A802305A9EBF190EDAD297AE283FA4A5CAD709A3B700982
(PID) Process:(4000) OneLaunch - ManualsLibrary_f7acl.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(4000) OneLaunch - ManualsLibrary_f7acl.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
2
Suspicious files
3
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\Tar445F.tmpcat
MD5:435A9AC180383F9FA094131B173A2F7B
SHA256:67DC37ED50B8E63272B49A254A6039EE225974F1D767BB83EB1FD80E759A7C34
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\Cab445E.tmpcompressed
MD5:29F65BA8E88C063813CC50A4EA544E93
SHA256:1ED81FA8DFB6999A9FEDC6E779138FFD99568992E22D300ACD181A6D2C8DE184
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:29F65BA8E88C063813CC50A4EA544E93
SHA256:1ED81FA8DFB6999A9FEDC6E779138FFD99568992E22D300ACD181A6D2C8DE184
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\is-AKMOJ.tmp\onelaunch.pngimage
MD5:D3110FB775EE7FD24426503D67840C25
SHA256:F8392390DC81756E79EC5F359DBDCAC3B4BD219B5188A429B814FC51AABB6E36
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\is-AKMOJ.tmp\onelaunch.bmpimage
MD5:6A360D71735931F6DEED2F1FC0D1E0A0
SHA256:98F2C973DF13A6B642274E76F9DF0E5C04D213958BDDB0693A7C4F689C64DFCB
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\is-AKMOJ.tmp\min-10-dark.pngimage
MD5:14CA04108E5AC6A1B8C7A2B689382E44
SHA256:9CB22401A923DFECAFC5F51DACEF5CBAE440B53B9932217C6BC4626F04920929
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\is-AKMOJ.tmp\Win32Library.dllexecutable
MD5:F801D3A6F441E1475342906BAE8B73E8
SHA256:DADB7C8637D9B9D6F0F36B110D324BBEB80E3CCFFD8E376235857A0162DE090C
3984OneLaunch - ManualsLibrary_f7acl.exeC:\Users\admin\AppData\Local\Temp\is-RNNR6.tmp\OneLaunch - ManualsLibrary_f7acl.tmpexecutable
MD5:C0E3F092B137EF1604C7E1B31A755E06
SHA256:1829C12B58954D0D71389ACD73DA79D13E2571ACD1EEAE3CF48273CEABA98D31
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\is-AKMOJ.tmp\min-hover.bmpimage
MD5:E08B0A658E4A166C5461C542BE2B0D2F
SHA256:6F696C0C59CEDD0456270BCC868B6B3D7CBCA43911390904014F532CD7B131D5
4000OneLaunch - ManualsLibrary_f7acl.tmpC:\Users\admin\AppData\Local\Temp\is-AKMOJ.tmp\min-pressed.bmpimage
MD5:CC62DDE39B9CAA24626A3A0EB93C70FA
SHA256:8D25A76A6552A927407CB0D7BA1E61E8644D76420C2690F8CB3DB90F75ECC1E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4000
OneLaunch - ManualsLibrary_f7acl.tmp
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?60da87739b649fea
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
4000
OneLaunch - ManualsLibrary_f7acl.tmp
18.173.205.38:443
attribution.onelaunch.com
US
unknown
4000
OneLaunch - ManualsLibrary_f7acl.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
4000
OneLaunch - ManualsLibrary_f7acl.tmp
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
4000
OneLaunch - ManualsLibrary_f7acl.tmp
52.88.125.197:443
api.keen.io
AMAZON-02
US
unknown
4000
OneLaunch - ManualsLibrary_f7acl.tmp
130.211.34.183:443
api.mixpanel.com
GOOGLE
US
whitelisted
4000
OneLaunch - ManualsLibrary_f7acl.tmp
104.26.13.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
attribution.onelaunch.com
  • 18.173.205.38
  • 18.173.205.66
  • 18.173.205.55
  • 18.173.205.127
whitelisted
update.onelaunch.com
  • 104.26.12.224
  • 172.67.68.170
  • 104.26.13.224
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
api.keen.io
  • 52.88.125.197
  • 54.71.15.80
  • 52.43.162.221
whitelisted
api.mixpanel.com
  • 130.211.34.183
  • 35.186.241.51
  • 35.190.25.25
  • 107.178.240.159
whitelisted
release-cdn.onelaunch.com
  • 104.26.13.224
  • 172.67.68.170
  • 104.26.12.224
unknown

Threats

No threats detected
No debug info