File name:

OneStart.exe

Full analysis: https://app.any.run/tasks/6a02deaf-56c6-4f5e-a1e6-d62b6be726c8
Verdict: Malicious activity
Analysis date: May 10, 2025, 08:06:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-reg
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

3C3780FFE6340A9A4F04D5D150021579

SHA1:

3E586E130C2D53D6322F90F004AAA302995645F6

SHA256:

8A9B4DF432C31E5D55D031A892E420734B63B3DD511C9F6DD5B4E86BD49399EE

SSDEEP:

3072:Rz8yr0sM69y4bN3pWvSes0T7wq1ha6ffffGfdbCQyTNhmfM69ywEN3pWMSe10T7U:dy69yIp0v1haHbC9N69yL50v1htWSU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • UpdaterSetup.exe (PID: 5800)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 1164)
      • updater.exe (PID: 3888)
      • updater.exe (PID: 4696)
      • updater.exe (PID: 1912)
      • updater.exe (PID: 5680)
      • updater.exe (PID: 5436)
      • updater.exe (PID: 5260)
      • updater.exe (PID: 7620)
      • updater.exe (PID: 7640)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • setup.exe (PID: 7912)
      • setup.exe (PID: 8028)
      • setup.exe (PID: 8060)
      • setup.exe (PID: 7892)
      • onestart.exe (PID: 8116)
      • onestart.exe (PID: 8148)
      • onestart.exe (PID: 8184)
      • onestart.exe (PID: 6044)
      • onestart.exe (PID: 6668)
      • onestart.exe (PID: 7200)
      • onestart.exe (PID: 7208)
      • onestart.exe (PID: 7000)
      • onestart.exe (PID: 7648)
      • onestart.exe (PID: 5600)
      • onestart.exe (PID: 6828)
      • onestart.exe (PID: 1188)
      • onestart.exe (PID: 7748)
      • onestart.exe (PID: 6112)
      • onestart.exe (PID: 6592)
      • onestart.exe (PID: 2656)
      • onestart.exe (PID: 8036)
      • onestart.exe (PID: 7984)
      • onestart.exe (PID: 8008)
      • onestart.exe (PID: 8084)
      • onestart.exe (PID: 7928)
      • onestart.exe (PID: 7936)
      • onestart.exe (PID: 7848)
      • onestart.exe (PID: 5048)
      • onestart.exe (PID: 8064)
      • onestart.exe (PID: 1280)
      • onestart.exe (PID: 3304)
    • Changes the autorun value in the registry

      • updater.exe (PID: 4812)
      • onestart.exe (PID: 8116)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • OneStart.exe (PID: 4944)
      • updater.exe (PID: 4812)
    • Executable content was dropped or overwritten

      • OneStart.exe (PID: 4944)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 3888)
      • setup.exe (PID: 7892)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • onestart.exe (PID: 1280)
    • Application launched itself

      • updater.exe (PID: 4812)
      • updater.exe (PID: 3888)
      • updater.exe (PID: 1912)
      • updater.exe (PID: 5260)
      • updater.exe (PID: 7620)
      • setup.exe (PID: 7892)
      • onestart.exe (PID: 8148)
      • setup.exe (PID: 8028)
      • onestart.exe (PID: 7208)
      • onestart.exe (PID: 6044)
      • onestart.exe (PID: 8116)
      • onestart.exe (PID: 8084)
      • onestart.exe (PID: 7936)
    • Creates a software uninstall entry

      • setup.exe (PID: 7892)
    • Searches for installed software

      • setup.exe (PID: 7892)
    • The process checks if it is being run in the virtual environment

      • onestart.exe (PID: 8116)
  • INFO

    • Disables trace logs

      • OneStart.exe (PID: 4944)
    • Reads the software policy settings

      • OneStart.exe (PID: 4944)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 5260)
      • slui.exe (PID: 4784)
    • Checks supported languages

      • OneStart.exe (PID: 4944)
      • UpdaterSetup.exe (PID: 5800)
      • updater.exe (PID: 1164)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 3888)
      • updater.exe (PID: 4696)
      • updater.exe (PID: 1912)
      • updater.exe (PID: 5260)
      • updater.exe (PID: 5436)
      • updater.exe (PID: 5680)
      • updater.exe (PID: 7620)
      • updater.exe (PID: 7640)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • setup.exe (PID: 7912)
      • notification_helper.exe (PID: 7964)
      • setup.exe (PID: 8028)
      • setup.exe (PID: 7892)
      • onestart.exe (PID: 8148)
      • setup.exe (PID: 8060)
      • onestart.exe (PID: 8116)
      • onestart.exe (PID: 8184)
      • onestart.exe (PID: 7200)
      • onestart.exe (PID: 7208)
      • onestart.exe (PID: 6044)
      • onestart.exe (PID: 6668)
      • onestart.exe (PID: 7000)
      • onestart.exe (PID: 1188)
      • onestart.exe (PID: 7648)
      • onestart.exe (PID: 5600)
      • onestart.exe (PID: 6828)
      • onestart.exe (PID: 6592)
      • onestart.exe (PID: 8036)
      • onestart.exe (PID: 2656)
      • onestart.exe (PID: 8008)
      • onestart.exe (PID: 7984)
      • onestart.exe (PID: 7748)
      • onestart.exe (PID: 6112)
      • onestart.exe (PID: 8084)
      • onestart.exe (PID: 7928)
      • onestart.exe (PID: 7848)
      • onestart.exe (PID: 7936)
      • onestart.exe (PID: 5048)
      • onestart.exe (PID: 8064)
      • onestart.exe (PID: 1280)
      • onestart.exe (PID: 3304)
    • Reads the machine GUID from the registry

      • OneStart.exe (PID: 4944)
      • updater.exe (PID: 4812)
      • onestart.exe (PID: 8116)
    • Checks proxy server information

      • OneStart.exe (PID: 4944)
      • updater.exe (PID: 5260)
      • updater.exe (PID: 4812)
      • onestart.exe (PID: 8116)
    • Reads the computer name

      • OneStart.exe (PID: 4944)
      • UpdaterSetup.exe (PID: 5800)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 3888)
      • updater.exe (PID: 1912)
      • updater.exe (PID: 5260)
      • updater.exe (PID: 7620)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • setup.exe (PID: 7892)
      • notification_helper.exe (PID: 7964)
      • setup.exe (PID: 8028)
      • onestart.exe (PID: 8116)
      • onestart.exe (PID: 8148)
      • onestart.exe (PID: 7208)
      • onestart.exe (PID: 6044)
      • onestart.exe (PID: 7000)
      • onestart.exe (PID: 6668)
      • onestart.exe (PID: 6112)
      • onestart.exe (PID: 8084)
      • onestart.exe (PID: 7936)
    • The sample compiled with english language support

      • OneStart.exe (PID: 4944)
      • UpdaterSetup.exe (PID: 5800)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 3888)
      • setup.exe (PID: 7892)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • onestart.exe (PID: 1280)
    • Create files in a temporary directory

      • UpdaterSetup.exe (PID: 5800)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • updater.exe (PID: 4812)
      • updater.exe (PID: 5260)
      • onestart.exe (PID: 8116)
    • Manual execution by a user

      • updater.exe (PID: 1912)
      • updater.exe (PID: 7620)
      • cmd.exe (PID: 7472)
      • WinRAR.exe (PID: 7400)
      • onestart.exe (PID: 8084)
    • Auto-launch of the file from Registry key

      • updater.exe (PID: 4812)
      • onestart.exe (PID: 8116)
    • Creates files or folders in the user directory

      • updater.exe (PID: 4812)
      • onestart_installer_134.0.6998.113.exe (PID: 7844)
      • setup.exe (PID: 7892)
      • notification_helper.exe (PID: 7964)
      • setup.exe (PID: 8028)
      • onestart.exe (PID: 8116)
      • onestart.exe (PID: 6044)
      • onestart.exe (PID: 6668)
      • onestart.exe (PID: 8084)
    • Process checks computer location settings

      • onestart.exe (PID: 6828)
      • onestart.exe (PID: 5600)
      • onestart.exe (PID: 8116)
      • onestart.exe (PID: 3304)
    • Reads CPU info

      • onestart.exe (PID: 8116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2101:05:02 04:38:29+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 271360
InitializedDataSize: 179200
UninitializedDataSize: -
EntryPoint: 0x4426a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 6.0.31.0
ProductVersionNumber: 6.0.31.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: OneStartBrowser
CompanyName: OneStart.ai
FileDescription: OneStartBrowser
FileVersion: 6.0.31.0
InternalName: OneStart.exe
LegalCopyright: Copyright © OneStart.ai 2025
LegalTrademarks: -
OriginalFileName: OneStart.exe
ProductName: OneStartBrowser
ProductVersion: 6.0.31.0
AssemblyVersion: 6.0.31.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
189
Monitored processes
52
Malicious processes
15
Suspicious processes
29

Behavior graph

Click at the process to see the details
start onestart.exe sppextcomobj.exe no specs slui.exe updatersetup.exe updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs updater.exe updater.exe no specs winrar.exe no specs cmd.exe no specs conhost.exe no specs updater.exe no specs updater.exe no specs onestart_installer_134.0.6998.113.exe setup.exe setup.exe no specs notification_helper.exe no specs chrome.exe no specs setup.exe no specs setup.exe no specs onestart.exe onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe no specs onestart.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1164C:\Users\admin\AppData\Local\Temp\OneStart.ai5800_121483454\bin\updater.exe --crash-handler --database=C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\Crashpad --url=https://onestartapi.com/ --annotation=prod=OneStartUpdater --annotation=ver=134.0.6998.111 --initial-client-data=0x234,0x238,0x23c,0x214,0x240,0x7ff6a77b357c,0x7ff6a77b3588,0x7ff6a77b3598C:\Users\admin\AppData\Local\Temp\OneStart.ai5800_121483454\bin\updater.exeupdater.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.111
Modules
Images
c:\users\admin\appdata\local\temp\onestart.ai5800_121483454\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1188"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,4893286488761504835,1546110733694770729,262144 --variations-seed-version --mojo-platform-channel-handle=4848 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.113
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.113\onestart_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
1280"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,4893286488761504835,1546110733694770729,262144 --variations-seed-version --mojo-platform-channel-handle=6092 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exe
onestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.113
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.113\onestart_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
1912"C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exe" --wakeC:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exeexplorer.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.111
Modules
Images
c:\users\admin\onestart.ai\onestartupdater\134.0.6998.111\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
2656"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2012,i,4893286488761504835,1546110733694770729,262144 --variations-seed-version --mojo-platform-channel-handle=5456 /prefetch:8C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.113
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.113\onestart_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
3304"C:\Users\admin\OneStart.ai\OneStart\onestart.exe" --type=renderer --extension-process --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=18 --field-trial-handle=2012,i,4893286488761504835,1546110733694770729,262144 --variations-seed-version --mojo-platform-channel-handle=5740 /prefetch:2C:\Users\admin\OneStart.ai\OneStart\onestart.exeonestart.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
LOW
Description:
OneStart
Exit code:
0
Version:
134.0.6998.113
Modules
Images
c:\users\admin\onestart.ai\onestart\onestart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\onestart.ai\onestart\134.0.6998.113\onestart_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
3888"C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exe" --server --service=update-internal -EmbeddingC:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exe
svchost.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.111
Modules
Images
c:\users\admin\onestart.ai\onestartupdater\134.0.6998.111\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4696C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exe --crash-handler --database=C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\Crashpad --url=https://onestartapi.com/ --annotation=prod=OneStartUpdater --annotation=ver=134.0.6998.111 --initial-client-data=0x23c,0x240,0x244,0x218,0x248,0x7ff704d5357c,0x7ff704d53588,0x7ff704d53598C:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exeupdater.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.111
Modules
Images
c:\users\admin\onestart.ai\onestartupdater\134.0.6998.111\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4784"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4812"C:\Users\admin\AppData\Local\Temp\OneStart.ai5800_121483454\bin\updater.exe" --install --install-dir="C:\Users\admin\OneStart.ai" --install-pref=15-2-1-1 --app-id={8060F172-F5A8-4798-B813-D0DA39CCFF06} --enable-logging --vmodule=*/components/winhttp/*=1,*/components/update_client/*=2,*/chrome/enterprise_companion/*=2,*/chrome/updater/*=2C:\Users\admin\AppData\Local\Temp\OneStart.ai5800_121483454\bin\updater.exe
UpdaterSetup.exe
User:
admin
Company:
OneStart.ai
Integrity Level:
MEDIUM
Description:
OneStart Updater
Exit code:
0
Version:
134.0.6998.111
Modules
Images
c:\users\admin\appdata\local\temp\onestart.ai5800_121483454\bin\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
10 947
Read events
10 689
Write events
251
Delete events
7

Modification events

(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4944) OneStart.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\OneStart_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
13
Suspicious files
149
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
4812updater.exeC:\Users\admin\OneStart.ai\OneStartUpdater\6812b965-614a-49dd-8a21-7c972531ea79.tmpbinary
MD5:76839DA073B65882D51E09A35C8D4829
SHA256:C814F5986A69FFAE688A85FA0942BD2B2E31AF5B81D4A3F1D6668C718EFA3F27
3888updater.exeC:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\4b500c67-1e70-4503-ae8c-778cf1cd4289.tmpbinary
MD5:AA2D0C0C72BB528CF4168EA91C1C9A56
SHA256:E03E9D262CA3B7D19E37C3A69C7D8B46BD3F5542AA555A17D864071C28257B2C
3888updater.exeC:\Users\admin\OneStart.ai\OneStartUpdater\prefs.json~RF10e800.TMPbinary
MD5:76839DA073B65882D51E09A35C8D4829
SHA256:C814F5986A69FFAE688A85FA0942BD2B2E31AF5B81D4A3F1D6668C718EFA3F27
5260updater.exeC:\Users\admin\AppData\Local\Temp\chrome_url_fetcher_5260_1027075250\onestart_installer_134.0.6998.113.crx3
MD5:
SHA256:
5260updater.exeC:\Users\admin\OneStart.ai\OneStartUpdater\crx_cache\{8060F172-F5A8-4798-B813-D0DA39CCFF06}_1.de4270bed5c282c27cab9915504790b6090e458414c5acbe6448e3efb8b47b68
MD5:
SHA256:
5260updater.exeC:\Users\admin\AppData\Local\Temp\chrome_Unpacker_BeginUnzipping5260_1713526913\onestart_installer_134.0.6998.113.exe
MD5:
SHA256:
4812updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\83D863F495E7D991917B3ABB3E1EB382_7001EEE3BEC13CC4D9EF5C21F5DA8121binary
MD5:00B7307E3C1E76E57EDC2420C56DC94E
SHA256:6485B569C38AA71A3582C9F58BAD4299E8604A1AADF72787644412EFEE917FCA
3888updater.exeC:\Users\admin\OneStart.ai\Update\OneStartUpdate.exeexecutable
MD5:B2FBAC91207E1C710EBDE9EB6007FE84
SHA256:F096E35DD960448C80A236C022A17F24A2E4D9C853BAB3B4A934FC4EABAFECC4
4812updater.exeC:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\updater.exeexecutable
MD5:B2FBAC91207E1C710EBDE9EB6007FE84
SHA256:F096E35DD960448C80A236C022A17F24A2E4D9C853BAB3B4A934FC4EABAFECC4
4812updater.exeC:\Users\admin\OneStart.ai\OneStartUpdater\134.0.6998.111\uninstall.cmdtext
MD5:B9E7FE76A4554E7B62DB3CEA7051FC99
SHA256:53D0F5AD04F1912AC5DCF6E30CD21021CA1A71F4BA86578DBA31EF7EBAD012CF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
69
DNS requests
60
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.66:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.66:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4812
updater.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
whitelisted
4812
updater.exe
GET
200
18.173.208.27:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEAUeYCB5Mhnf7bUC9imrhnY%3D
unknown
whitelisted
7708
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7708
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7844
onestart_installer_134.0.6998.113.exe
POST
200
13.35.58.119:80
http://event.onestartapi.com/
unknown
unknown
6668
onestart.exe
GET
200
142.250.185.110:80
http://clients2.google.com/time/1/current?cup2key=8:hfidi3GgnCzsYDCwdXBDxj83d87egWOKMfJej_4tbzE&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.66:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.16.164.66:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4944
OneStart.exe
13.35.58.119:443
event.onestartapi.com
US
unknown
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.66
  • 2.16.164.32
  • 2.16.164.83
  • 2.16.164.74
  • 2.16.164.51
  • 2.16.164.16
  • 2.16.164.75
  • 2.16.164.81
  • 2.16.164.33
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.219.150.101
whitelisted
google.com
  • 142.250.185.78
whitelisted
event.onestartapi.com
  • 13.35.58.119
  • 13.35.58.124
  • 13.35.58.53
  • 13.35.58.73
unknown
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.20
  • 20.190.160.131
  • 40.126.32.74
  • 20.190.160.66
  • 40.126.32.72
  • 40.126.32.76
  • 20.190.160.130
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
resources.onestartapi.com
  • 18.245.46.31
  • 18.245.46.106
  • 18.245.46.43
  • 18.245.46.115
unknown
updates.onestartapi.com
  • 13.32.121.95
  • 13.32.121.75
  • 13.32.121.19
  • 13.32.121.3
unknown

Threats

PID
Process
Class
Message
6668
onestart.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6668
onestart.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info