| File name: | Launcher.exe |
| Full analysis: | https://app.any.run/tasks/43cf5d7f-1a5e-4600-abe7-ae13a5891e65 |
| Verdict: | Malicious activity |
| Analysis date: | July 24, 2024, 01:22:41 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 968B9FE8A83A058B6794B3C3AE4C4BCA |
| SHA1: | 7259756216CE6E841244F68D2929B1D9FAF3167F |
| SHA256: | C2B6239C217A9A45A6503088ACBAC95EE64F5995E634FDA3BADB89B8934D069A |
| SSDEEP: | 98304:htTyn/BzJG89xqhJ2zc2AA72x5NJNfrjcZo4fJW57zZ7U7SAbLnyT1eI5zx6rRvl:azXF6xYxWH67Q83RVFGW5hmGZ |
| .exe | | | Win32 EXE PECompact compressed (generic) (49.3) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (32.7) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.8) |
| .exe | | | Win32 Executable (generic) (5.3) |
| .exe | | | Generic Win/DOS Executable (2.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:09 19:33:08+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 7576576 |
| InitializedDataSize: | 3716096 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x6f4d99 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2256 | "C:\Users\admin\AppData\Local\Temp\Launcher.exe" | C:\Users\admin\AppData\Local\Temp\Launcher.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| 6140 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6592 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2256 -s 2456 | C:\Windows\SysWOW64\WerFault.exe | Launcher.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2256) Launcher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6592 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Launcher.exe_unk_f4eca5d352919dee65787cc484c6fd26a869e6a_8d590276_a7f5cc23-25f6-4ffd-b56f-85cce7cf5491\Report.wer | — | |
MD5:— | SHA256:— | |||
| 6592 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER3342.tmp.WERInternalMetadata.xml | xml | |
MD5:71376E43910A4A873EC605A63CF4086F | SHA256:D51716C55A8573C4949E68A67A78765D0CBAF022BEFDD574C9BD08592119936B | |||
| 6592 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\Launcher.exe.2256.dmp | binary | |
MD5:E9E93396177B5496AB39E38B8FE1CF8F | SHA256:AD660444AA529E01091EB7F0826F83B56A760229252632F601C018D38011416C | |||
| 6592 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER3371.tmp.xml | xml | |
MD5:CF8B551F3564100CAD9BCB8C95214BCB | SHA256:64C85C5D09DAD34FB5E1803FC6BBC0E56F761476C43F0E88669BF91FCD1D9E6F | |||
| 6592 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER31CA.tmp.dmp | binary | |
MD5:C63500C1437B6DD000EDCBFBB7AE918F | SHA256:440261433F515C96A54B9E8B2D6879B9B2ADA204AE8F280056F2613A98B784FB | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3952 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6012 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.23.209.133:443 | — | Akamai International B.V. | GB | unknown |
— | — | 4.208.221.206:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2256 | Launcher.exe | 149.154.164.13:443 | telegra.ph | Telegram Messenger Inc | GB | unknown |
6592 | WerFault.exe | 52.182.143.212:443 | watson.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
telegra.ph |
| malicious |
watson.events.data.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
Launcher.exe | url before fix: https://telegra.ph/bigmachonok-07-09
|
Launcher.exe | url after fix: https://telegra.ph/bigmachonok-07-09
|