File name:

PrismLauncher-Windows-MSVC-Setup-6.1.exe

Full analysis: https://app.any.run/tasks/4b597de2-8d99-47bf-b286-9bdc975378f5
Verdict: Malicious activity
Analysis date: August 02, 2024, 15:51:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

3A9E82A34241CC1074B5ACDBA96DE397

SHA1:

753FAC5C5E7AA94A026465C148354AA50E980A2A

SHA256:

9915886397DCDC3AB005E677C7ECAA2227F107E953A6CE3F0FE9DA5AA24E99BA

SSDEEP:

196608:b1Zq/twK7Yaj7Ig0mZGj7UECKD0yFBNkQmQT:b1Zq/tz7YEZ0j2KD0yjNzmQT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • The process creates files with name similar to system file names

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • Uses TASKKILL.EXE to kill process

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • Creates a software uninstall entry

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
  • INFO

    • Create files in a temporary directory

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • Checks supported languages

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • Reads the computer name

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
    • Creates files or folders in the user directory

      • PrismLauncher-Windows-MSVC-Setup-6.1.exe (PID: 6496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.1.0.0
ProductVersionNumber: 6.1.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: Prism Launcher Installer
FileVersion: 6.1.0.0
LegalCopyright: Prism Launcher Contributors\n© 2021-2022 PolyMC Contributors \n© 2012-2021 MultiMC Contributors
ProductName: Prism Launcher
ProductVersion: 6.1.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
122
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start prismlauncher-windows-msvc-setup-6.1.exe taskkill.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6496"C:\Users\admin\AppData\Local\Temp\PrismLauncher-Windows-MSVC-Setup-6.1.exe" C:\Users\admin\AppData\Local\Temp\PrismLauncher-Windows-MSVC-Setup-6.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Prism Launcher Installer
Exit code:
0
Version:
6.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\prismlauncher-windows-msvc-setup-6.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6584TaskKill /IM prismlauncher.exe /FC:\Windows\SysWOW64\taskkill.exePrismLauncher-Windows-MSVC-Setup-6.1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6592\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
3 592
Read events
3 567
Write events
25
Delete events
0

Modification events

(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\PrismLauncher
Operation:writeName:InstallDir
Value:
C:\Users\admin\AppData\Local\Programs\PrismLauncher
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:DisplayName
Value:
Prism Launcher
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\PrismLauncher\prismlauncher.exe
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\PrismLauncher\uninstall.exe"
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\PrismLauncher\uninstall.exe" /S
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\PrismLauncher
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:Publisher
Value:
Prism Launcher Contributors
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:Version
Value:
6.1.0.0
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:DisplayVersion
Value:
6.1
(PID) Process:(6496) PrismLauncher-Windows-MSVC-Setup-6.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PrismLauncher
Operation:writeName:VersionMajor
Value:
6
Executable files
26
Suspicious files
3
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Temp\nse52A1.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Temp\nse52A1.tmp\nsExec.dllexecutable
MD5:675C4948E1EFC929EDCABFE67148EDDD
SHA256:1076CA39C449ED1A968021B76EF31F22A5692DFAFEEA29460E8D970A63C59906
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\Qt6Widgets.dllexecutable
MD5:FB4F282DA22FF082FDAA957698C079B1
SHA256:226E112BCB5A00F576DB2278C993D4BAD299826C3AECBAB1ABBFA9F6D281D850
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\qt.confbinary
MD5:7215EE9C7D9DC229D2921A40E899EC5F
SHA256:36A9E7F1C95B82FFB99743E0C5C4CE95D83C9A430AAC59F84EF3CBFAB6145068
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Temp\nse52A1.tmp\nsDialogs.dllexecutable
MD5:6C3F8C94D0727894D706940A8A980543
SHA256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\Qt6Core.dllexecutable
MD5:7EB1E9956AB6A6EB41D7EBB48F073527
SHA256:D037DD5176F7A404CD42DEC2F6E172BC0938D431039E023080CBB1E6E0E62485
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\Qt6Core5Compat.dllexecutable
MD5:437387095D26C79102464239CC9DE940
SHA256:35014A415937A819B697A360C2C0D08AC8F79E3C71E34D789927C61125562E2B
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\Qt6Network.dllexecutable
MD5:1D3E8947DFE774292FF86BE36D75F584
SHA256:6CD325C8EA7CC757260D288C49BF362092DA0159AA45685E774EF8B9E448E30F
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\Qt6Gui.dllexecutable
MD5:6478C16E7FB5CDD73DB8D9459F2202E0
SHA256:78285161C08AAB7ECE80C2AB8E34A1F1455D07B368DB88FD26B8C52352D28757
6496PrismLauncher-Windows-MSVC-Setup-6.1.exeC:\Users\admin\AppData\Local\Programs\PrismLauncher\Qt6Svg.dllexecutable
MD5:E25AA9BB3DF70191F7C5A569D2B75915
SHA256:125E0BAFABAE04FA8E0EF3FF6EDEA2AF90807DC10CE6952789DD3B8E5E51E1ED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info