File name:

CloudAppLauncher_Installer.zip

Full analysis: https://app.any.run/tasks/a223a86f-633b-44c5-86ea-cdc336bcc424
Verdict: Malicious activity
Analysis date: November 07, 2023, 17:17:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

17250497A00FF27FD9E6872D90F6AD80

SHA1:

9403150068F0FAA7A6B90E147CDEAEDD36C2639D

SHA256:

A1376DD6150D1A177BB8B2D6E182FE8AC8390EFF86CCE4E4CCE66AF08832DA73

SSDEEP:

98304:rtSzDpFXzMHSPNlMzcc/viCEvViJQ6PNJnyok82HHMElZZY2tZWlSEXK0ZY5YDWs:RyybAYKjtiBxd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • LauncherSetup.exe (PID: 3164)
      • SetupProgress.exe (PID: 3500)
      • LauncherSetup.exe (PID: 3604)
      • LauncherSetup.exe (PID: 3496)
      • LauncherSetup.exe (PID: 3664)
  • SUSPICIOUS

    • Reads the Internet Settings

      • CloudAppLauncher_Installer.exe (PID: 3140)
      • CloudAppLauncher_Installer.exe (PID: 3596)
    • Reads the Windows owner or organization settings

      • LauncherSetup.exe (PID: 3496)
    • Process drops legitimate windows executable

      • LauncherSetup.exe (PID: 3496)
      • LauncherSetup.exe (PID: 3664)
    • The process drops C-runtime libraries

      • LauncherSetup.exe (PID: 3496)
      • LauncherSetup.exe (PID: 3664)
    • Searches for installed software

      • LauncherSetup.exe (PID: 3496)
      • LauncherSetup.exe (PID: 3604)
      • LauncherSetup.exe (PID: 3664)
    • Creates a software uninstall entry

      • LauncherSetup.exe (PID: 3664)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3156)
    • Reads the computer name

      • CloudAppLauncher_Installer.exe (PID: 3140)
      • LauncherSetup.exe (PID: 3164)
      • LauncherSetup.exe (PID: 3496)
      • CloudAppLauncher_Installer.exe (PID: 3596)
      • LauncherSetup.exe (PID: 3604)
      • LauncherSetup.exe (PID: 3664)
    • Checks supported languages

      • LauncherSetup.exe (PID: 3164)
      • CloudAppLauncher_Installer.exe (PID: 3140)
      • LauncherSetup.exe (PID: 3496)
      • execmd_bak.exe (PID: 3468)
      • execmd_bak.exe (PID: 3572)
      • SetupProgress.exe (PID: 3500)
      • execmd_bak.exe (PID: 3408)
      • CloudAppLauncher_Installer.exe (PID: 3596)
      • execmd_bak.exe (PID: 3412)
      • LauncherSetup.exe (PID: 3604)
      • LauncherSetup.exe (PID: 3664)
      • execmd_bak.exe (PID: 3884)
      • execmd_bak.exe (PID: 3844)
      • SetupProgress.exe (PID: 3864)
      • execmd_bak.exe (PID: 3828)
    • Creates files or folders in the user directory

      • CloudAppLauncher_Installer.exe (PID: 3140)
      • LauncherSetup.exe (PID: 3496)
      • SetupProgress.exe (PID: 3500)
      • LauncherSetup.exe (PID: 3664)
    • Create files in a temporary directory

      • CloudAppLauncher_Installer.exe (PID: 3140)
      • LauncherSetup.exe (PID: 3164)
      • LauncherSetup.exe (PID: 3496)
      • CloudAppLauncher_Installer.exe (PID: 3596)
      • LauncherSetup.exe (PID: 3604)
      • LauncherSetup.exe (PID: 3664)
    • Reads the machine GUID from the registry

      • LauncherSetup.exe (PID: 3496)
      • LauncherSetup.exe (PID: 3664)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:11:07 13:12:48
ZipCRC: 0x79f61944
ZipCompressedSize: 10458013
ZipUncompressedSize: 17197792
ZipFileName: CloudAppLauncher_Installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
16
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
3140"C:\Users\admin\AppData\Local\Temp\Rar$EXa3156.42291\CloudAppLauncher_Installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3156.42291\CloudAppLauncher_Installer.exeWinRAR.exe
User:
admin
Company:
Appeon Inc.
Integrity Level:
MEDIUM
Description:
Cloud App Launcher Installer
Exit code:
0
Version:
22.1.0.2819
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3156.42291\cloudapplauncher_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3156"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CloudAppLauncher_Installer.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3164"C:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\LauncherSetup.exe" /sC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\LauncherSetup.exeCloudAppLauncher_Installer.exe
User:
admin
Company:
Appeon Inc.
Integrity Level:
MEDIUM
Description:
Cloud App Launcher Installer
Exit code:
0
Version:
22.1.0.2819
Modules
Images
c:\users\admin\appdata\local\temp\cal_installer_20231107-171721\launchersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3408-check C:\Users\admin\AppData\Local\CloudAppLauncher_V2\execmd_bak.exeSetupProgress.exe
User:
admin
Company:
Appeon
Integrity Level:
MEDIUM
Description:
execmd Application
Exit code:
0
Version:
22.1.0.0000
Modules
Images
c:\users\admin\appdata\local\cloudapplauncher_v2\execmd_bak.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3412-check C:\Users\admin\AppData\Roaming\PBApps\execmd_bak.exeSetupProgress.exe
User:
admin
Company:
Appeon
Integrity Level:
MEDIUM
Description:
execmd Application
Exit code:
0
Version:
22.1.0.0000
Modules
Images
c:\users\admin\appdata\roaming\pbapps\execmd_bak.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3468C:\Users\admin\AppData\Local\CloudAppLauncher_V2\execmd_bak.exe -check C:\Users\admin\AppData\Local\CloudAppLauncher_V2\execmd_bak.exeLauncherSetup.exe
User:
admin
Company:
Appeon
Integrity Level:
MEDIUM
Description:
execmd Application
Exit code:
0
Version:
22.1.0.0000
Modules
Images
c:\users\admin\appdata\local\cloudapplauncher_v2\execmd_bak.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3496C:\Users\admin\AppData\Local\Temp\{414F5E9B-1CC2-47E8-9F95-D46D6C158F49}\LauncherSetup.exe /s -package:"C:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\LauncherSetup.exe" -no_selfdeleter -IS_temp -media_path:"C:\Users\admin\AppData\Local\Temp\{414F5E9B-1CC2-47E8-9F95-D46D6C158F49}\Disk1\" -tempdisk1folder:"C:\Users\admin\AppData\Local\Temp\{414F5E9B-1CC2-47E8-9F95-D46D6C158F49}\" -IS_OriginalLauncher:"C:\Users\admin\AppData\Local\Temp\{414F5E9B-1CC2-47E8-9F95-D46D6C158F49}\Disk1\LauncherSetup.exe"C:\Users\admin\AppData\Local\Temp\{414F5E9B-1CC2-47E8-9F95-D46D6C158F49}\LauncherSetup.exe
LauncherSetup.exe
User:
admin
Company:
Appeon Inc.
Integrity Level:
MEDIUM
Description:
Cloud App Launcher Installer
Exit code:
0
Version:
22.1.0.2819
Modules
Images
c:\users\admin\appdata\local\temp\{414f5e9b-1cc2-47e8-9f95-d46d6c158f49}\launchersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3500C:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\SetupProgress.exe "C:\Users\admin\AppData\Local\Appeon\appeoninstalllog_V2\Progresslog\PCASProgress.ini" "/mem=Local\ShrMemory1107-171722"C:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\SetupProgress.exeLauncherSetup.exe
User:
admin
Company:
Appeon
Integrity Level:
MEDIUM
Description:
Cloud App Launcher
Exit code:
0
Version:
22.1.0.2301
Modules
Images
c:\users\admin\appdata\local\temp\cal_installer_20231107-171721\setupprogress.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3572C:\Users\admin\AppData\Roaming\PBApps\execmd_bak.exe -check C:\Users\admin\AppData\Roaming\PBApps\execmd_bak.exeLauncherSetup.exe
User:
admin
Company:
Appeon
Integrity Level:
MEDIUM
Description:
execmd Application
Exit code:
0
Version:
22.1.0.0000
Modules
Images
c:\users\admin\appdata\roaming\pbapps\execmd_bak.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3596"C:\Users\admin\AppData\Local\Temp\Rar$EXa3156.44532\CloudAppLauncher_Installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3156.44532\CloudAppLauncher_Installer.exeWinRAR.exe
User:
admin
Company:
Appeon Inc.
Integrity Level:
MEDIUM
Description:
Cloud App Launcher Installer
Exit code:
0
Version:
22.1.0.2819
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3156.44532\cloudapplauncher_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
Total events
2 878
Read events
2 808
Write events
62
Delete events
8

Modification events

(PID) Process:(3156) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3156) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
207
Suspicious files
41
Text files
85
Unknown types
0

Dropped files

PID
Process
Filename
Type
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\LauncherSetup.exe
MD5:
SHA256:
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\pcas.icoimage
MD5:FFCC644409E8CE9DC9BDECDDAA99F090
SHA256:BD15BE60A360DC393DEDE82F57D15336752880558FAE56E4F6795212CDCE78E9
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\setup.cabcompressed
MD5:BAC503D22D6A5BC74E0FE205557B2678
SHA256:79634D89E2B0BE51C270BED8F310562278919B2D64E342FDE84ECF54716EC3DA
3164LauncherSetup.exeC:\Users\admin\AppData\Local\Temp\{414F5E9B-1CC2-47E8-9F95-D46D6C158F49}\Disk1\data1.hdrcompressed
MD5:1B9A677728020061C0D30662A038A3C0
SHA256:350551D6D8AC4E25948F91065D67F1F29B54BBA6692A31C112BD9AE7AF59FE0B
3156WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3156.42291\CloudAppLauncher_Installer.exeexecutable
MD5:F23747EDAC5025CD14028EAC213A2FD3
SHA256:F4B999A50F75A646AA5E4C8CA1FD17177DE9A6FFC8F768075BF3C0C1BFF5AA13
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Appeon\appeoninstalllog_V2\CAL_unzip.logtext
MD5:1D91FDA1AAA877FF28AC0239ED8D1BAF
SHA256:069809EFA6542E82AA1E681358FF94AF4701B0C9F2BDFD58A5061C9D68FC5B6B
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\background.bmpimage
MD5:652122516109444CB1515673B599480F
SHA256:2552A34E8D8E791639F4966612561B296F8796C3B4605D475148D94F8B931571
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\LauncherCfg.initext
MD5:7B65DC0AD8D37EA57B16D4FE71FA057E
SHA256:B947E7D8EF2C22174FC820344B601BD65628F822B52E830FB0AB9AE690A37CB1
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\update.bmpimage
MD5:2DDE4C48E555DB20726240CF4149A7C2
SHA256:D5C2956114F5147C9A9D6D2F47D53395AD54D6053E2719B111D425D16D17527E
3140CloudAppLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\CAL_Installer_20231107-171721\loading_ica.gifimage
MD5:46A63CEB55CAFF5AD28C3D8E5878EEA8
SHA256:67CE220F13345E482DD66E97E38DBB695793923AE3334933CA60CB7B959AC437
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
Process
Message
LauncherSetup.exe
Getting existing security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2'
LauncherSetup.exe
Getting existing security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2'
LauncherSetup.exe
Setting new security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2'
LauncherSetup.exe
Setting new security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2'
LauncherSetup.exe
Setting new security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2\'
LauncherSetup.exe
Setting new security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2\'
LauncherSetup.exe
Getting existing security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2\'
LauncherSetup.exe
Getting existing security descriptor for 'C:\Users\admin\AppData\Local\CloudAppLauncher_V2\'