File name:

OneLaunch - Easy PDF_nhhxi.exe

Full analysis: https://app.any.run/tasks/4839578a-c41b-4005-9c51-9bb85786111a
Verdict: Malicious activity
Analysis date: October 20, 2023, 12:27:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

32DB554F79C7A923B886E1FE1CB376BA

SHA1:

215C63A2ABB7AB489A6EE4685B039ADFD3E82965

SHA256:

CC381F0912A60111386B47C0FD253E56CE87B62A9B638F3B1410D4478E21D9E2

SSDEEP:

98304:S+QqZ8fXOUfnZsiyimcfseOiQPNuYf5hoO3v4e1cp2g6LPkQ3U6twiGboSMwDdnW:biNHSG+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OneLaunch - Easy PDF_nhhxi.exe (PID: 3412)
      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
    • Loads dropped or rewritten executable

      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
    • Reads settings of System Certificates

      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
  • INFO

    • Checks supported languages

      • OneLaunch - Easy PDF_nhhxi.exe (PID: 3412)
      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
    • Create files in a temporary directory

      • OneLaunch - Easy PDF_nhhxi.exe (PID: 3412)
      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
    • Reads the computer name

      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
    • Reads the machine GUID from the registry

      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
    • Application was dropped or rewritten from another process

      • OneLaunch - Easy PDF_nhhxi.tmp (PID: 3520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 10:48:30+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.22.2.0
ProductVersionNumber: 5.22.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.22.2
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.22.2
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start onelaunch - easy pdf_nhhxi.exe no specs onelaunch - easy pdf_nhhxi.tmp

Process information

PID
CMD
Path
Indicators
Parent process
3412"C:\Users\admin\AppData\Local\Temp\OneLaunch - Easy PDF_nhhxi.exe" C:\Users\admin\AppData\Local\Temp\OneLaunch - Easy PDF_nhhxi.exeexplorer.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
1
Version:
5.22.2
Modules
Images
c:\users\admin\appdata\local\temp\onelaunch - easy pdf_nhhxi.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
3520"C:\Users\admin\AppData\Local\Temp\is-VD0IS.tmp\OneLaunch - Easy PDF_nhhxi.tmp" /SL5="$5035E,2267582,893952,C:\Users\admin\AppData\Local\Temp\OneLaunch - Easy PDF_nhhxi.exe" C:\Users\admin\AppData\Local\Temp\is-VD0IS.tmp\OneLaunch - Easy PDF_nhhxi.tmp
OneLaunch - Easy PDF_nhhxi.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vd0is.tmp\onelaunch - easy pdf_nhhxi.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 964
Read events
2 948
Write events
12
Delete events
4

Modification events

(PID) Process:(3520) OneLaunch - Easy PDF_nhhxi.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3520) OneLaunch - Easy PDF_nhhxi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3520) OneLaunch - Easy PDF_nhhxi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
659229E38E1BA381A58AC7DAD17A1CA8C5BDEFE352BD9E1D8742266A9C8EA2E9
(PID) Process:(3520) OneLaunch - Easy PDF_nhhxi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
C00D00002CF206C45003DA01
(PID) Process:(3520) OneLaunch - Easy PDF_nhhxi.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
3
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3520OneLaunch - Easy PDF_nhhxi.tmpC:\Users\admin\AppData\Local\Temp\is-MM7NL.tmp\split_tests.jsontext
MD5:4C2CAAA13F9A7DA52B7A5DE88BE63918
SHA256:D148FC0FB5AF1CC9FD6F65C40B7568D905B67F98E0E77EDB5D170BFCB0722FF7
3412OneLaunch - Easy PDF_nhhxi.exeC:\Users\admin\AppData\Local\Temp\is-VD0IS.tmp\OneLaunch - Easy PDF_nhhxi.tmpexecutable
MD5:A41109BBB1A18EC5319BEE7DF176FD42
SHA256:FADE5CB19A582C236DD9E173718D6B3BB581C655C37B6E4930EFC668AAFB26D4
3520OneLaunch - Easy PDF_nhhxi.tmpC:\Users\admin\AppData\Local\Temp\is-MM7NL.tmp\Win32Library.dllexecutable
MD5:D7489D7722A843FF8659996FFAA99584
SHA256:3A97EE76EA95610FAB0CA52E37829E593CB7B572CAC17FEE3E474C24FEB71825
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3520
OneLaunch - Easy PDF_nhhxi.tmp
13.32.99.117:443
attribution.onelaunch.com
AMAZON-02
US
unknown
3520
OneLaunch - Easy PDF_nhhxi.tmp
172.67.68.170:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
attribution.onelaunch.com
  • 13.32.99.117
  • 13.32.99.57
  • 13.32.99.71
  • 13.32.99.31
whitelisted
update.onelaunch.com
  • 172.67.68.170
  • 104.26.13.224
  • 104.26.12.224
unknown

Threats

No threats detected
No debug info