File name:

C:\Users\admin\Downloads\OneLaunch - Manuals Search_jnyvi.exe

Full analysis: https://app.any.run/tasks/d357020c-7bd5-41a1-abe7-d8719b3f426e
Verdict: Malicious activity
Analysis date: November 06, 2023, 14:23:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C595820011300866A3841A83765DE6D1

SHA1:

DFB207B0342BDF840FCDD890790DECD561C89686

SHA256:

7B2476A531DE636A8214EA2E7DDEB13F5301BE0663625EDE968CAC6CA9995C43

SSDEEP:

98304:V+QqZ8fXL19QufiETT8crkuOOgMpuUxQeFmKL6IupYa+K3Wd147PRVSIABs+sIpk:7HwYcG6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
      • OneLaunch - Manuals Search_jnyvi.exe (PID: 3440)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
    • Reads the Windows owner or organization settings

      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
  • INFO

    • Checks supported languages

      • OneLaunch - Manuals Search_jnyvi.exe (PID: 3440)
      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
      • wmpnscfg.exe (PID: 3484)
    • Reads the computer name

      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
      • wmpnscfg.exe (PID: 3484)
    • Reads the machine GUID from the registry

      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
      • wmpnscfg.exe (PID: 3484)
    • Create files in a temporary directory

      • OneLaunch - Manuals Search_jnyvi.exe (PID: 3440)
      • OneLaunch - Manuals Search_jnyvi.tmp (PID: 3212)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 10:48:30+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.23.0.0
ProductVersionNumber: 5.23.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.23.0
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.23.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start onelaunch - manuals search_jnyvi.exe no specs onelaunch - manuals search_jnyvi.tmp wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3212"C:\Users\admin\AppData\Local\Temp\is-BHQ1F.tmp\OneLaunch - Manuals Search_jnyvi.tmp" /SL5="$60134,2269840,893952,C:\Users\admin\AppData\Local\Temp\OneLaunch - Manuals Search_jnyvi.exe" C:\Users\admin\AppData\Local\Temp\is-BHQ1F.tmp\OneLaunch - Manuals Search_jnyvi.tmp
OneLaunch - Manuals Search_jnyvi.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-bhq1f.tmp\onelaunch - manuals search_jnyvi.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3440"C:\Users\admin\AppData\Local\Temp\OneLaunch - Manuals Search_jnyvi.exe" C:\Users\admin\AppData\Local\Temp\OneLaunch - Manuals Search_jnyvi.exeexplorer.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
1
Version:
5.23.0
Modules
Images
c:\users\admin\appdata\local\temp\onelaunch - manuals search_jnyvi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3484"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
2 997
Read events
2 978
Write events
12
Delete events
7

Modification events

(PID) Process:(3212) OneLaunch - Manuals Search_jnyvi.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3484) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{F88AA23B-0A15-4B79-8197-A30B00E648C4}\{C4D8A320-F03B-49CB-8471-13897F0AACC9}
Operation:delete keyName:(default)
Value:
(PID) Process:(3484) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{F88AA23B-0A15-4B79-8197-A30B00E648C4}
Operation:delete keyName:(default)
Value:
(PID) Process:(3484) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{3ECB59F4-6629-4B76-980D-12CCD9741B5D}
Operation:delete keyName:(default)
Value:
(PID) Process:(3212) OneLaunch - Manuals Search_jnyvi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3212) OneLaunch - Manuals Search_jnyvi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
2359D3816CF3C52D16AF4E1CD5A2677A823CCEB06ADAAA012B39A9FAC060618C
(PID) Process:(3212) OneLaunch - Manuals Search_jnyvi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
8C0C000016AC10E8BC10DA01
(PID) Process:(3212) OneLaunch - Manuals Search_jnyvi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
3
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3212OneLaunch - Manuals Search_jnyvi.tmpC:\Users\admin\AppData\Local\Temp\is-7AO4N.tmp\Win32Library.dllexecutable
MD5:CDA6F362ED0D6AE143F11153D5087602
SHA256:601CFEC58D1042C4588FDF7E1467C0C36E3315ED4C56123162CEFAB8770642F3
3440OneLaunch - Manuals Search_jnyvi.exeC:\Users\admin\AppData\Local\Temp\is-BHQ1F.tmp\OneLaunch - Manuals Search_jnyvi.tmpexecutable
MD5:D37CBC8FF63E68D15D3DF0A72B05E2DC
SHA256:20CA5222C72646846875385837CAC3340E5337980ADDCB5387F315231FEB1EC5
3212OneLaunch - Manuals Search_jnyvi.tmpC:\Users\admin\AppData\Local\Temp\is-7AO4N.tmp\split_tests.jsontext
MD5:4C2CAAA13F9A7DA52B7A5DE88BE63918
SHA256:D148FC0FB5AF1CC9FD6F65C40B7568D905B67F98E0E77EDB5D170BFCB0722FF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3212
OneLaunch - Manuals Search_jnyvi.tmp
13.32.99.57:443
attribution.onelaunch.com
AMAZON-02
US
unknown
3212
OneLaunch - Manuals Search_jnyvi.tmp
172.67.68.170:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
attribution.onelaunch.com
  • 13.32.99.57
  • 13.32.99.31
  • 13.32.99.71
  • 13.32.99.117
whitelisted
update.onelaunch.com
  • 172.67.68.170
  • 104.26.13.224
  • 104.26.12.224
unknown

Threats

No threats detected
No debug info