File name:

Onelaunch Software.exe

Full analysis: https://app.any.run/tasks/d2ac3278-09c6-4968-bcc2-c632c75bf47e
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 17, 2024, 18:21:52
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B907F2F66B47B18242FB1AB1E463BF1E

SHA1:

A342EAFA89778266E307854ED07AE817AA3A1594

SHA256:

BC8B3EFB3297AAD70136E0DA5FF709CCA2CF94DF2A15F2867577868E9107856E

SSDEEP:

98304:8+QqZ8fXQ9IDOAovynSqfLQ8M99jveVyHuDf8xJ9GDpDle0cug3JUUs4xF0/mCRG:gYXGQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • OneLaunch Setup_.tmp (PID: 7036)
      • chromium.exe (PID: 6412)
      • chromium.exe (PID: 6388)
      • chromium.exe (PID: 6404)
      • OneLaunch.exe (PID: 6552)
      • chromium.exe (PID: 7112)
      • chromium.exe (PID: 964)
      • chromium.exe (PID: 876)
      • chromium.exe (PID: 6832)
      • chromium.exe (PID: 532)
      • chromium.exe (PID: 2208)
      • chromium.exe (PID: 6460)
      • chromium.exe (PID: 1372)
      • chromium.exe (PID: 2152)
      • chromium.exe (PID: 4760)
      • chromium.exe (PID: 6380)
      • chromium.exe (PID: 5976)
      • chromium.exe (PID: 6260)
      • chromium.exe (PID: 6596)
      • chromium.exe (PID: 2464)
      • chromium.exe (PID: 3476)
      • chromium.exe (PID: 4056)
      • chromium.exe (PID: 7052)
      • chromium.exe (PID: 5064)
      • chromium.exe (PID: 7400)
      • chromium.exe (PID: 1288)
    • Changes the autorun value in the registry

      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
    • Steals credentials from Web Browsers

      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6832)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Onelaunch Software.exe (PID: 6448)
      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.exe (PID: 6032)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.exe (PID: 6964)
      • OneLaunch Setup_.tmp (PID: 7036)
    • Drops the executable file immediately after the start

      • Onelaunch Software.exe (PID: 6448)
      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.exe (PID: 6032)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.exe (PID: 6964)
      • OneLaunch Setup_.tmp (PID: 7036)
    • Reads the Windows owner or organization settings

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
    • There is functionality for taking screenshot (YARA)

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
    • Reads the date of Windows installation

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
    • Reads security settings of Internet Explorer

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
      • onelaunchtray.exe (PID: 6948)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6832)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 5588)
      • schtasks.exe (PID: 6816)
      • schtasks.exe (PID: 2532)
      • schtasks.exe (PID: 6600)
      • schtasks.exe (PID: 6740)
      • schtasks.exe (PID: 1248)
    • The process drops Mozilla's DLL files

      • OneLaunch Setup_.tmp (PID: 7036)
    • Uses TASKKILL.EXE to kill process

      • OneLaunch Setup_.tmp (PID: 7036)
    • Process drops legitimate windows executable

      • OneLaunch Setup_.tmp (PID: 7036)
    • Application launched itself

      • chromium.exe (PID: 6412)
      • chromium.exe (PID: 6404)
    • Starts CMD.EXE for commands execution

      • OneLaunch Setup_.tmp (PID: 7036)
    • Executing commands from a ".bat" file

      • OneLaunch Setup_.tmp (PID: 7036)
    • Executes application which crashes

      • OneLaunch Setup_.tmp (PID: 7036)
    • The process checks if it is being run in the virtual environment

      • chromium.exe (PID: 6404)
    • Potential Corporate Privacy Violation

      • OneLaunch.exe (PID: 6552)
  • INFO

    • Checks supported languages

      • Onelaunch Software.exe (PID: 6448)
      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.exe (PID: 6032)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.exe (PID: 6964)
      • OneLaunch Setup_.tmp (PID: 7036)
      • chromium.exe (PID: 6388)
      • OneLaunch.exe (PID: 6552)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6412)
      • onelaunchtray.exe (PID: 6948)
      • chromium.exe (PID: 964)
      • chromium.exe (PID: 7112)
      • chromium.exe (PID: 876)
      • chromium.exe (PID: 6832)
      • chromium.exe (PID: 2208)
      • chromium.exe (PID: 6460)
      • chromium.exe (PID: 532)
      • chromium.exe (PID: 4760)
      • chromium.exe (PID: 1372)
      • chromium.exe (PID: 6380)
      • chromium.exe (PID: 2152)
      • chromium.exe (PID: 5976)
      • chromium.exe (PID: 6260)
      • chromium.exe (PID: 3476)
      • chromium.exe (PID: 2464)
      • chromium.exe (PID: 4056)
      • TextInputHost.exe (PID: 6124)
      • chromium.exe (PID: 7052)
      • chromium.exe (PID: 1288)
      • chromium.exe (PID: 6596)
      • chromium.exe (PID: 5064)
      • chromium.exe (PID: 7400)
    • Create files in a temporary directory

      • Onelaunch Software.exe (PID: 6448)
      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.exe (PID: 6032)
      • OneLaunch Setup_.exe (PID: 6964)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6832)
    • Reads the software policy settings

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
      • chromium.exe (PID: 6832)
      • chromium.exe (PID: 6404)
      • WerFault.exe (PID: 7092)
      • WerFault.exe (PID: 3104)
    • Checks proxy server information

      • Onelaunch Software.tmp (PID: 6472)
      • OneLaunch.exe (PID: 6552)
      • chromium.exe (PID: 6404)
      • WerFault.exe (PID: 7092)
      • WerFault.exe (PID: 3104)
    • Reads the computer name

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6412)
      • onelaunchtray.exe (PID: 6948)
      • chromium.exe (PID: 964)
      • chromium.exe (PID: 876)
      • chromium.exe (PID: 6832)
      • TextInputHost.exe (PID: 6124)
      • chromium.exe (PID: 5064)
    • Reads the machine GUID from the registry

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
      • onelaunchtray.exe (PID: 6948)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6832)
    • Process checks computer location settings

      • Onelaunch Software.tmp (PID: 6472)
      • Onelaunch Software.tmp (PID: 6808)
      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 6460)
      • chromium.exe (PID: 532)
      • chromium.exe (PID: 2464)
      • chromium.exe (PID: 7052)
      • chromium.exe (PID: 4056)
      • chromium.exe (PID: 1288)
    • Creates files or folders in the user directory

      • OneLaunch Setup_.tmp (PID: 7036)
      • OneLaunch.exe (PID: 6552)
      • onelaunchtray.exe (PID: 6948)
      • chromium.exe (PID: 6404)
      • chromium.exe (PID: 876)
      • chromium.exe (PID: 6832)
      • WerFault.exe (PID: 7092)
      • WerFault.exe (PID: 3104)
    • Creates a software uninstall entry

      • OneLaunch Setup_.tmp (PID: 7036)
    • Creates files in the program directory

      • OneLaunch.exe (PID: 6552)
      • onelaunchtray.exe (PID: 6948)
    • Disables trace logs

      • OneLaunch.exe (PID: 6552)
    • Reads Environment values

      • OneLaunch.exe (PID: 6552)
    • Reads Microsoft Office registry keys

      • chromium.exe (PID: 6404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 09:48:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.32.1.0
ProductVersionNumber: 5.32.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.32.1
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.32.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
196
Monitored processes
55
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start onelaunch software.exe THREAT onelaunch software.tmp onelaunch software.exe THREAT onelaunch software.tmp onelaunch setup_.exe THREAT onelaunch setup_.tmp taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs THREAT onelaunch.exe chromium.exe chromium.exe chromium.exe onelaunchtray.exe chromium.exe chromium.exe chromium.exe chromium.exe cmd.exe no specs conhost.exe no specs chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe werfault.exe chromium.exe chromium.exe chromium.exe textinputhost.exe no specs chromium.exe chromium.exe chromium.exe werfault.exe chromium.exe chromium.exe

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --no-pre-read-main-dll --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --metrics-shmem-handle=4480,i,6964235873131136946,5413801330716582147,2097152 --field-trial-handle=4100,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=4488 /prefetch:1C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\124.1.0.0\chrome_elf.dll
c:\windows\syswow64\version.dll
876"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --metrics-shmem-handle=1780,i,4709068993731354205,5035162378364957783,524288 --field-trial-handle=3084,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=3080 /prefetch:3C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
964"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=gpu-process --no-pre-read-main-dll --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --metrics-shmem-handle=1960,i,7639196420350219388,7045613744681286881,262144 --field-trial-handle=2192,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=2128 /prefetch:2C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1248"schtasks" /delete /tn OneLaunchUpdateTask /fC:\Windows\System32\schtasks.exeOneLaunch Setup_.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1288"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --no-pre-read-main-dll --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --metrics-shmem-handle=5896,i,17375509361259328746,6485884188470292166,2097152 --field-trial-handle=5960,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=3956 /prefetch:1C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\124.1.0.0\chrome_elf.dll
c:\windows\syswow64\version.dll
1372"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --metrics-shmem-handle=5476,i,582447842462000400,3045188538109155351,524288 --field-trial-handle=5468,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=5472 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Exit code:
0
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1884\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2152"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --metrics-shmem-handle=5612,i,5773656490183648965,2476109881782263622,524288 --field-trial-handle=4000,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=3992 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Exit code:
0
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2208"C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-pre-read-main-dll --metrics-shmem-handle=3888,i,1002621267023659095,12748971930572320361,524288 --field-trial-handle=3892,i,1061769642995104006,8380953699799783876,262144 --variations-seed-version --mojo-platform-channel-handle=3824 /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.32.1\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
LOW
Description:
OneLaunch
Exit code:
0
Version:
124.1.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.32.1\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2384\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
38 361
Read events
38 150
Write events
208
Delete events
3

Modification events

(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
4819000035C35659D2F0DA01
(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
A8276617100E85674D7FA0A16ECA28583E29AEC566AE97B4486409BA5949959C
(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6472) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6808) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
981A00000EA19483D2F0DA01
(PID) Process:(6808) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
2021509A9EA686F51713B007D1FF7E6D7F11B4F6487E389E37F15FE0B2754AB9
(PID) Process:(6808) Onelaunch Software.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
Executable files
255
Suspicious files
356
Text files
297
Unknown types
16

Dropped files

PID
Process
Filename
Type
6472Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-H6HF5.tmp\is-VN703.tmp
MD5:
SHA256:
6472Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-H6HF5.tmp\OneLaunch Setup.exe
MD5:
SHA256:
6472Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
6808Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe
MD5:
SHA256:
7036OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-APIEL.tmp\exit-hover.bmpimage
MD5:D33F497718C0BF3C5705941BA5666A5A
SHA256:C61FB1333511D8E78C4606DD2A800F1CF9D94307B26C01862128FF11C0B5E333
7036OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-APIEL.tmp\exit-rest.bmpimage
MD5:B8AD3B36AE539BBB3D8C41FAA57FE4F6
SHA256:33BD571330E590730A52C6880EA744A63B8D5342A0C8BF2DF871C41D190D57F0
6472Onelaunch Software.tmpC:\Users\admin\AppData\Local\Temp\is-H6HF5.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
7036OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-APIEL.tmp\exit-10-light.pngimage
MD5:2CCE6763F61DDDB4599CB058D6761C56
SHA256:0FC8E40A3B0E7A516E108DC0F3267DCCCB4DE04D28A21EB68A45A8AC1BB9DF8F
7036OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-APIEL.tmp\exit-pressed.bmpimage
MD5:53178FD9661AE74BBFA7A562653A7773
SHA256:FFE6D8F0EA0ACB8660389C9E7F399133BC570803789638AA884AE2F247D8BF10
7036OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-APIEL.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
270
DNS requests
206
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3276
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6832
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6128
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6552
OneLaunch.exe
HEAD
301
2.19.225.87:80
http://pages.ebay.com/messages/page_not_responding.html
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6552
OneLaunch.exe
HEAD
301
2.19.225.87:80
http://pages.ebay.com/messages/page_not_responding.html
unknown
whitelisted
6552
OneLaunch.exe
HEAD
301
2.19.225.87:80
http://pages.ebay.com/messages/page_not_responding.html
unknown
whitelisted
6552
OneLaunch.exe
GET
200
2.16.238.25:80
http://api.accuweather.com/locations/v1/cities/ipaddress?&apikey=7f64ed3093d8436e994f9dc7e382a06a
unknown
whitelisted
6552
OneLaunch.exe
HEAD
301
2.19.225.87:80
http://pages.ebay.com/messages/page_not_responding.html
unknown
whitelisted
6552
OneLaunch.exe
HEAD
301
2.19.225.87:80
http://pages.ebay.com/messages/page_not_responding.html
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2464
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5240
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
6472
Onelaunch Software.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
6472
Onelaunch Software.tmp
52.26.244.245:443
api.keen.io
AMAZON-02
US
unknown
6472
Onelaunch Software.tmp
172.67.68.170:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
5240
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.206
whitelisted
update.onelaunch.com
  • 104.26.12.224
  • 172.67.68.170
  • 104.26.13.224
unknown
api.keen.io
  • 52.26.244.245
  • 35.167.90.140
  • 44.236.84.59
whitelisted
release-cdn.onelaunch.com
  • 172.67.68.170
  • 104.26.13.224
  • 104.26.12.224
unknown
client.wns.windows.com
  • 40.115.3.253
  • 20.198.162.78
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.75
  • 40.126.31.71
  • 20.190.159.64
  • 20.190.159.23
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

PID
Process
Class
Message
6552
OneLaunch.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
6552
OneLaunch.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
Process
Message
chromium.exe
[0817/182356.482:ERROR:registration_protocol_win.cc(136)] TransactNamedPipe: The pipe has been ended. (0x6D)
chromium.exe
[0817/182356.482:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad: The system cannot find the path specified. (0x3)
chromium.exe
[0817/182356.482:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad: The system cannot find the path specified. (0x3)
OneLaunch.exe
2024-08-17 18:23:57,638 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.32.1.0
OneLaunch.exe
2024-08-17 18:23:57,950 DEBUG [ 1] (Com.WebBar.Popups.PopupScheduler+PopupSchedule: 0) - scheduled popup slot app_wizard with ViewModel type AppWizardPopupViewModel to be shown at 08/17/2024 18:53:57 +00:00
onelaunchtray.exe
log4net:ERROR XmlHierarchyConfigurator: No appender named [Analytics] could be found.
onelaunchtray.exe
log4net:ERROR Appender named [Analytics] not found.
onelaunchtray.exe
Rebase.OneLaunch.Tray.TrayApp: 2024-08-17 18:23:58,341 [1] INFO - starting up
OneLaunch.exe
2024-08-17 18:23:58,747 DEBUG [ 1] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
OneLaunch.exe
2024-08-17 18:23:59,492 DEBUG [ 7] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location