File name:

OneLaunch - Fast Print_seaq2.exe

Full analysis: https://app.any.run/tasks/6456a2ec-47c9-4190-90a3-c6b6f5f40e6a
Verdict: Malicious activity
Analysis date: February 11, 2024, 18:45:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6A05CD2D9491EF255C709724B782B476

SHA1:

6CE3F0F26A1E3FEFE7DDB63E838D90908929C0B6

SHA256:

B5A9381D8EA317BA2BEDBDA0D9B858A3CAD1B09528F63761FE5C4BD0DE5098A8

SSDEEP:

98304:3+QqZ8fXafUQd0HpxI6OD673KPAsBxY1uLFqahgSQsLXGT1npdTZm1gd533ha13M:JhnL5GK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OneLaunch - Fast Print_seaq2.exe (PID: 2472)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch - Fast Print_seaq2.exe (PID: 2848)
      • OneLaunch Setup_seaq2.exe (PID: 3932)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
    • Changes the autorun value in the registry

      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch.exe (PID: 3984)
    • Actions looks like stealing of personal data

      • chromium.exe (PID: 3800)
      • OneLaunch.exe (PID: 3984)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OneLaunch - Fast Print_seaq2.exe (PID: 2472)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.exe (PID: 2848)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch Setup_seaq2.exe (PID: 3932)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
    • Reads the Windows owner or organization settings

      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
    • Reads settings of System Certificates

      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch.exe (PID: 3984)
    • Reads the Internet Settings

      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch.exe (PID: 3984)
      • onelaunchtray.exe (PID: 2760)
    • Reads security settings of Internet Explorer

      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch.exe (PID: 3984)
    • Uses TASKKILL.EXE to kill process

      • OneLaunch Setup_seaq2.tmp (PID: 3304)
    • The process drops Mozilla's DLL files

      • OneLaunch Setup_seaq2.tmp (PID: 3304)
    • Process drops legitimate windows executable

      • OneLaunch Setup_seaq2.tmp (PID: 3304)
  • INFO

    • Checks supported languages

      • OneLaunch - Fast Print_seaq2.exe (PID: 2472)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch - Fast Print_seaq2.exe (PID: 2848)
      • OneLaunch Setup_seaq2.exe (PID: 3932)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch.exe (PID: 3984)
      • onelaunchtray.exe (PID: 2760)
    • Reads the computer name

      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch.exe (PID: 3984)
      • onelaunchtray.exe (PID: 2760)
    • Create files in a temporary directory

      • OneLaunch - Fast Print_seaq2.exe (PID: 2472)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch - Fast Print_seaq2.exe (PID: 2848)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch Setup_seaq2.exe (PID: 3932)
    • Reads the software policy settings

      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch.exe (PID: 3984)
    • Reads the machine GUID from the registry

      • OneLaunch - Fast Print_seaq2.tmp (PID: 2840)
      • OneLaunch - Fast Print_seaq2.tmp (PID: 3864)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • OneLaunch.exe (PID: 3984)
      • onelaunchtray.exe (PID: 2760)
    • Creates a software uninstall entry

      • OneLaunch Setup_seaq2.tmp (PID: 3304)
    • Creates files in the program directory

      • OneLaunch.exe (PID: 3984)
    • Creates files or folders in the user directory

      • OneLaunch.exe (PID: 3984)
      • OneLaunch Setup_seaq2.tmp (PID: 3304)
      • onelaunchtray.exe (PID: 2760)
    • Reads Environment values

      • OneLaunch.exe (PID: 3984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 09:48:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.27.0.0
ProductVersionNumber: 5.27.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.27.0
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.27.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
18
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start onelaunch - fast print_seaq2.exe onelaunch - fast print_seaq2.tmp onelaunch - fast print_seaq2.exe onelaunch - fast print_seaq2.tmp onelaunch setup_seaq2.exe onelaunch setup_seaq2.tmp taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs onelaunch.exe chromium.exe onelaunchtray.exe

Process information

PID
CMD
Path
Indicators
Parent process
1236"schtasks" /Delete /TN "OneLaunchLaunchTask" /FC:\Windows\System32\schtasks.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1496"C:\Windows\System32\taskkill.exe" /f /im onelaunchtray.exeC:\Windows\System32\taskkill.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1772"schtasks" /delete /tn ChromiumLaunchTask /fC:\Windows\System32\schtasks.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1816"schtasks" /delete /tn OneLaunchUpdateTask /fC:\Windows\System32\schtasks.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1844"schtasks" /Delete /TN "OneLaunchUpdateTask" /FC:\Windows\System32\schtasks.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2100"schtasks" /Delete /TN "ChromiumLaunchTask" /FC:\Windows\System32\schtasks.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2292"C:\Windows\System32\taskkill.exe" /f /im chromium.exeC:\Windows\System32\taskkill.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2472"C:\Users\admin\AppData\Local\Temp\OneLaunch - Fast Print_seaq2.exe" C:\Users\admin\AppData\Local\Temp\OneLaunch - Fast Print_seaq2.exe
explorer.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
0
Version:
5.27.0
Modules
Images
c:\users\admin\appdata\local\temp\onelaunch - fast print_seaq2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2760"C:\Users\admin\AppData\Local\OneLaunch\5.27.0\onelaunchtray.exe" C:\Users\admin\AppData\Local\OneLaunch\5.27.0\onelaunchtray.exe
OneLaunch.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunchTray
Exit code:
0
Version:
5.27.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.27.0\onelaunchtray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2788"schtasks" /delete /tn OneLaunchLaunchTask /fC:\Windows\System32\schtasks.exeOneLaunch Setup_seaq2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
26 536
Read events
26 353
Write events
183
Delete events
0

Modification events

(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
180F00007688F2831A5DDA01
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
441E2C142A8B9BAF5F6C8400B508695D557F8D108BA389CD4648F7E0D62AA9B0
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3864) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2840) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
180B00003C55A3A91A5DDA01
(PID) Process:(2840) OneLaunch - Fast Print_seaq2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
5182481E7B7B081C283267744C50B94E56F44644679900A7DE8C8B7073E1E811
Executable files
247
Suspicious files
145
Text files
136
Unknown types
17

Dropped files

PID
Process
Filename
Type
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\is-AM8L0.tmp
MD5:
SHA256:
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\OneLaunch Setup.exe
MD5:
SHA256:
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
2840OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_seaq2.exe
MD5:
SHA256:
2472OneLaunch - Fast Print_seaq2.exeC:\Users\admin\AppData\Local\Temp\is-DTR53.tmp\OneLaunch - Fast Print_seaq2.tmpexecutable
MD5:0859BE57626D393B36096262E1881E8F
SHA256:C406DECC37AD9CC8A96B73A0526016D19235367A420A1F82B8D8D3F76FE0C4F1
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\print.bmpimage
MD5:D3B1C114AAC1FE8CF374DBC68F9A4F07
SHA256:AC8AD339DDA53038043B2C7BD087B28C344C4CCD784C81E0C6A9CCCF162EF219
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\onelaunch.bmpimage
MD5:6A360D71735931F6DEED2F1FC0D1E0A0
SHA256:98F2C973DF13A6B642274E76F9DF0E5C04D213958BDDB0693A7C4F689C64DFCB
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\min-10-dark.pngimage
MD5:14CA04108E5AC6A1B8C7A2B689382E44
SHA256:9CB22401A923DFECAFC5F51DACEF5CBAE440B53B9932217C6BC4626F04920929
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\min-hover.bmpimage
MD5:E08B0A658E4A166C5461C542BE2B0D2F
SHA256:6F696C0C59CEDD0456270BCC868B6B3D7CBCA43911390904014F532CD7B131D5
3864OneLaunch - Fast Print_seaq2.tmpC:\Users\admin\AppData\Local\Temp\is-JFBSG.tmp\onelaunch.pngimage
MD5:D3110FB775EE7FD24426503D67840C25
SHA256:F8392390DC81756E79EC5F359DBDCAC3B4BD219B5188A429B814FC51AABB6E36
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
19
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3984
OneLaunch.exe
GET
200
2.19.11.13:80
http://api.accuweather.com/locations/v1/cities/ipaddress?&apikey=7f64ed3093d8436e994f9dc7e382a06a
unknown
binary
1.06 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3864
OneLaunch - Fast Print_seaq2.tmp
18.164.52.57:443
attribution.onelaunch.com
US
unknown
3864
OneLaunch - Fast Print_seaq2.tmp
104.26.13.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
3864
OneLaunch - Fast Print_seaq2.tmp
44.231.151.4:443
api.keen.io
AMAZON-02
US
unknown
3864
OneLaunch - Fast Print_seaq2.tmp
107.178.240.159:443
api.mixpanel.com
GOOGLE
US
whitelisted
2840
OneLaunch - Fast Print_seaq2.tmp
104.26.13.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
3304
OneLaunch Setup_seaq2.tmp
44.231.151.4:443
api.keen.io
AMAZON-02
US
unknown
3304
OneLaunch Setup_seaq2.tmp
107.178.240.159:443
api.mixpanel.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
attribution.onelaunch.com
  • 18.164.52.57
  • 18.164.52.62
  • 18.164.52.40
  • 18.164.52.118
whitelisted
update.onelaunch.com
  • 104.26.13.224
  • 172.67.68.170
  • 104.26.12.224
unknown
api.keen.io
  • 44.231.151.4
  • 52.33.19.142
  • 54.186.176.79
whitelisted
api.mixpanel.com
  • 107.178.240.159
  • 130.211.34.183
  • 35.186.241.51
  • 35.190.25.25
whitelisted
release-cdn.onelaunch.com
  • 104.26.13.224
  • 172.67.68.170
  • 104.26.12.224
unknown
api.accuweather.com
  • 2.19.11.13
  • 2.19.11.9
  • 2.19.11.11
unknown
youtube.com
  • 142.250.74.206
whitelisted
facebook.com
  • 157.240.252.35
whitelisted
www.youtube.com
  • 142.250.185.238
  • 142.250.185.142
  • 172.217.16.142
  • 216.58.212.142
  • 142.250.181.238
  • 172.217.23.110
  • 142.250.185.78
  • 142.250.185.174
  • 142.250.185.110
  • 142.250.186.174
  • 142.250.186.46
  • 142.250.186.78
  • 142.250.185.206
  • 142.250.184.206
  • 142.250.186.142
  • 142.250.184.238
whitelisted
www.facebook.com
  • 157.240.253.35
whitelisted

Threats

No threats detected
Process
Message
OneLaunch.exe
2024-02-11 18:47:34,665 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.27.0.0
OneLaunch.exe
2024-02-11 18:47:34,978 DEBUG [ 1] (Com.WebBar.Popups.PopupScheduler+PopupSchedule: 0) - scheduled popup slot app_wizard with ViewModel type AppWizardPopupViewModel to be shown at 02/11/2024 19:17:34 +00:00
onelaunchtray.exe
log4net:ERROR XmlHierarchyConfigurator: No appender named [Analytics] could be found.
onelaunchtray.exe
log4net:ERROR Appender named [Analytics] not found.
OneLaunch.exe
2024-02-11 18:47:35,337 DEBUG [ 1] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
onelaunchtray.exe
Rebase.OneLaunch.Tray.TrayApp: 2024-02-11 18:47:35,353 [1] INFO - starting up
OneLaunch.exe
2024-02-11 18:47:35,625 DEBUG [ 5] (Com.WebBar.Util.UserActivityDetector: 0) - first run or minimum interval expired
OneLaunch.exe
2024-02-11 18:47:35,625 DEBUG [ 5] (Com.WebBar.Util.UserActivityDetector: 0) - idle for 0:00:54.734