download:

/download

Full analysis: https://app.any.run/tasks/6f69f64f-1294-4cab-9ebc-cf88cf0645bd
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 30, 2023, 15:56:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

32DB554F79C7A923B886E1FE1CB376BA

SHA1:

215C63A2ABB7AB489A6EE4685B039ADFD3E82965

SHA256:

CC381F0912A60111386B47C0FD253E56CE87B62A9B638F3B1410D4478E21D9E2

SSDEEP:

98304:S+QqZ8fXOUfnZsiyimcfseOiQPNuYf5hoO3v4e1cp2g6LPkQ3U6twiGboSMwDdnW:biNHSG+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • download.exe (PID: 4024)
      • download.tmp (PID: 2088)
      • download.exe (PID: 120)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.tmp (PID: 2452)
      • OneLaunch Setup_.exe (PID: 276)
      • NetFrameworkInstaller.exe (PID: 1940)
      • msiexec.exe (PID: 3180)
    • Loads dropped or rewritten executable

      • download.tmp (PID: 2088)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.tmp (PID: 2452)
      • Setup.exe (PID: 3672)
      • msiexec.exe (PID: 3180)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3672)
      • SetupUtility.exe (PID: 3176)
      • SetupUtility.exe (PID: 1536)
    • Creates a writable file the system directory

      • msiexec.exe (PID: 3180)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • download.tmp (PID: 2088)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.tmp (PID: 2452)
      • msiexec.exe (PID: 3180)
    • Reads settings of System Certificates

      • download.tmp (PID: 2088)
      • OneLaunch Setup_.tmp (PID: 2452)
      • download.tmp (PID: 2960)
      • Setup.exe (PID: 3672)
    • Reads the Internet Settings

      • download.tmp (PID: 2088)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.tmp (PID: 2452)
      • Setup.exe (PID: 3672)
    • Process drops legitimate windows executable

      • NetFrameworkInstaller.exe (PID: 1940)
      • msiexec.exe (PID: 3180)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 3672)
      • msiexec.exe (PID: 3180)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 3672)
    • Adds/modifies Windows certificates

      • NetFrameworkInstaller.exe (PID: 1940)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 3180)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 3180)
  • INFO

    • Checks supported languages

      • download.exe (PID: 4024)
      • download.tmp (PID: 2088)
      • download.exe (PID: 120)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.exe (PID: 276)
      • OneLaunch Setup_.tmp (PID: 2452)
      • NetFrameworkInstaller.exe (PID: 1940)
      • Setup.exe (PID: 3672)
      • SetupUtility.exe (PID: 3176)
      • SetupUtility.exe (PID: 1536)
      • msiexec.exe (PID: 3180)
      • msiexec.exe (PID: 976)
      • msiexec.exe (PID: 2056)
    • Create files in a temporary directory

      • download.exe (PID: 4024)
      • download.tmp (PID: 2088)
      • download.exe (PID: 120)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.exe (PID: 276)
      • NetFrameworkInstaller.exe (PID: 1940)
      • Setup.exe (PID: 3672)
      • SetupUtility.exe (PID: 3176)
      • msiexec.exe (PID: 3180)
      • OneLaunch Setup_.tmp (PID: 2452)
    • Application was dropped or rewritten from another process

      • download.tmp (PID: 2960)
      • download.tmp (PID: 2088)
      • OneLaunch Setup_.tmp (PID: 2452)
    • Reads the computer name

      • download.tmp (PID: 2088)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.tmp (PID: 2452)
      • NetFrameworkInstaller.exe (PID: 1940)
      • Setup.exe (PID: 3672)
      • SetupUtility.exe (PID: 3176)
      • SetupUtility.exe (PID: 1536)
      • msiexec.exe (PID: 3180)
      • msiexec.exe (PID: 976)
      • msiexec.exe (PID: 2056)
    • Reads the machine GUID from the registry

      • download.tmp (PID: 2088)
      • download.tmp (PID: 2960)
      • OneLaunch Setup_.tmp (PID: 2452)
      • NetFrameworkInstaller.exe (PID: 1940)
      • Setup.exe (PID: 3672)
      • SetupUtility.exe (PID: 3176)
      • msiexec.exe (PID: 3180)
      • msiexec.exe (PID: 976)
      • msiexec.exe (PID: 2056)
    • Reads CPU info

      • Setup.exe (PID: 3672)
    • Reads Environment values

      • Setup.exe (PID: 3672)
    • Creates files or folders in the user directory

      • Setup.exe (PID: 3672)
    • Application launched itself

      • msiexec.exe (PID: 3180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 10:48:30+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.22.2.0
ProductVersionNumber: 5.22.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.22.2
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.22.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
13
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start download.exe no specs download.tmp download.exe no specs download.tmp onelaunch setup_.exe no specs onelaunch setup_.tmp netframeworkinstaller.exe setup.exe setuputility.exe no specs setuputility.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\download.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE2OTg2ODE0MjMsImRpc3RpbmN0X2lkIjoiODFFQTI1NjQtMzhGOC00QzNFLUE2OTQtODg1MTE1Rjc3MzVBIiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjIuMi4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImEiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNlcnZlcl9zaWRlX3NwbGl0XzIzXzEwX250cF9kaXN0cmlidXRpb25fYSI6ImNvbnRyb2wiLCJzcGxpdF8yMl8xMl9tb3JlX2VkdWNhdGlvbmFsX21pbmlwcm9tcHRzIjoidmFyaWF0aW9uIiwiZW5jb2RlZF9zcGxpdHMiOiIwMDAifQ== /LAUNCHER /VERYSILENTC:\Users\admin\AppData\Local\Temp\download.exedownload.tmp
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
0
Version:
5.22.2
Modules
Images
c:\users\admin\appdata\local\temp\download.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usp10.dll
276"C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE2OTg2ODE0MjMsImRpc3RpbmN0X2lkIjoiODFFQTI1NjQtMzhGOC00QzNFLUE2OTQtODg1MTE1Rjc3MzVBIiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjIuMi4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImEiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNlcnZlcl9zaWRlX3NwbGl0XzIzXzEwX250cF9kaXN0cmlidXRpb25fYSI6ImNvbnRyb2wiLCJzcGxpdF8yMl8xMl9tb3JlX2VkdWNhdGlvbmFsX21pbmlwcm9tcHRzIjoidmFyaWF0aW9uIiwiZW5jb2RlZF9zcGxpdHMiOiIwMDAifQ==C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exedownload.tmp
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch Setup
Exit code:
0
Version:
5.22.2
Modules
Images
c:\users\admin\appdata\local\temp\onelaunch setup_.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
976C:\Windows\system32\MsiExec.exe -Embedding 71B73CDBC02E03242717F3491822F281C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1536SetupUtility.exe /screbootC:\88676dbc575978f387\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.8.4110.0 built by: NET48REL1LAST_B
Modules
Images
c:\88676dbc575978f387\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1940"C:\Users\admin\AppData\Local\Temp\is-GEUNS.tmp\NetFrameworkInstaller.exe" /passive /norestartC:\Users\admin\AppData\Local\Temp\is-GEUNS.tmp\NetFrameworkInstaller.exe
OneLaunch Setup_.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.8 Setup
Exit code:
0
Version:
4.8.04115.00
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-geuns.tmp\netframeworkinstaller.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2056C:\Windows\system32\MsiExec.exe -Embedding AA0F0331DCD0E9520596A7F48551DC27 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2088"C:\Users\admin\AppData\Local\Temp\is-IP9FN.tmp\download.tmp" /SL5="$40300,2267582,893952,C:\Users\admin\AppData\Local\Temp\download.exe" C:\Users\admin\AppData\Local\Temp\is-IP9FN.tmp\download.tmp
download.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-ip9fn.tmp\download.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2452"C:\Users\admin\AppData\Local\Temp\is-J8RMN.tmp\OneLaunch Setup_.tmp" /SL5="$30302,99176315,893952,C:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE2OTg2ODE0MjMsImRpc3RpbmN0X2lkIjoiODFFQTI1NjQtMzhGOC00QzNFLUE2OTQtODg1MTE1Rjc3MzVBIiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjIuMi4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImEiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNlcnZlcl9zaWRlX3NwbGl0XzIzXzEwX250cF9kaXN0cmlidXRpb25fYSI6ImNvbnRyb2wiLCJzcGxpdF8yMl8xMl9tb3JlX2VkdWNhdGlvbmFsX21pbmlwcm9tcHRzIjoidmFyaWF0aW9uIiwiZW5jb2RlZF9zcGxpdHMiOiIwMDAifQ==C:\Users\admin\AppData\Local\Temp\is-J8RMN.tmp\OneLaunch Setup_.tmp
OneLaunch Setup_.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-j8rmn.tmp\onelaunch setup_.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2960"C:\Users\admin\AppData\Local\Temp\is-7I42A.tmp\download.tmp" /SL5="$30304,2267582,893952,C:\Users\admin\AppData\Local\Temp\download.exe" /PDATA=eyJpbnN0YWxsX3RpbWUiOjE2OTg2ODE0MjMsImRpc3RpbmN0X2lkIjoiODFFQTI1NjQtMzhGOC00QzNFLUE2OTQtODg1MTE1Rjc3MzVBIiwiZGVmYXVsdF9icm93c2VyIjoiTVNFZGdlSFRNIiwiaW5pdGluYWxfdmVyc2lvbiI6IjUuMjIuMi4wIiwicGFja2FnZWRfYnJvd3NlciI6Ik5vbmUiLCJzcGxpdCI6ImEiLCJub19zcGxpdCI6ZmFsc2UsInNwbGl0MiI6ImEiLCJzZXJ2ZXJfc2lkZV9zcGxpdF8yM18wNl9yb3VuZGVkX3NlYXJjaGJhciI6InZhcmlhdGlvbiIsInNlcnZlcl9zaWRlX3NwbGl0XzIzXzEwX250cF9kaXN0cmlidXRpb25fYSI6ImNvbnRyb2wiLCJzcGxpdF8yMl8xMl9tb3JlX2VkdWNhdGlvbmFsX21pbmlwcm9tcHRzIjoidmFyaWF0aW9uIiwiZW5jb2RlZF9zcGxpdHMiOiIwMDAifQ== /LAUNCHER /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-7I42A.tmp\download.tmp
download.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7i42a.tmp\download.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3176SetupUtility.exe /aupauseC:\88676dbc575978f387\SetupUtility.exeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Framework 4.5 Setup
Exit code:
0
Version:
14.8.4110.0 built by: NET48REL1LAST_B
Modules
Images
c:\88676dbc575978f387\setuputility.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
25 977
Read events
25 863
Write events
99
Delete events
15

Modification events

(PID) Process:(2088) download.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2088) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2088) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2088) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2088) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2960) download.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2960) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2960) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2960) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2960) download.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
994
Suspicious files
24
Text files
235
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088download.tmpC:\Users\admin\AppData\Local\Temp\is-J2A3V.tmp\is-HTQJI.tmp
MD5:
SHA256:
2088download.tmpC:\Users\admin\AppData\Local\Temp\is-J2A3V.tmp\OneLaunch Setup.exe
MD5:
SHA256:
2088download.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
2960download.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe
MD5:
SHA256:
2088download.tmpC:\Users\admin\AppData\Local\Temp\is-J2A3V.tmp\onelaunch.bmpimage
MD5:6A360D71735931F6DEED2F1FC0D1E0A0
SHA256:98F2C973DF13A6B642274E76F9DF0E5C04D213958BDDB0693A7C4F689C64DFCB
2088download.tmpC:\Users\admin\AppData\Local\Temp\is-J2A3V.tmp\split_tests.jsontext
MD5:4C2CAAA13F9A7DA52B7A5DE88BE63918
SHA256:D148FC0FB5AF1CC9FD6F65C40B7568D905B67F98E0E77EDB5D170BFCB0722FF7
2452OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-GEUNS.tmp\exit-rest.bmpimage
MD5:668DB032964764959DC4D657415BA38D
SHA256:18CD9ED2D1282ED25F41E54F2E3DBACFFD6428156BC7AA91B5BDA051C5B82F20
2088download.tmpC:\Users\admin\AppData\Local\Temp\is-J2A3V.tmp\onelaunch.pngimage
MD5:D3110FB775EE7FD24426503D67840C25
SHA256:F8392390DC81756E79EC5F359DBDCAC3B4BD219B5188A429B814FC51AABB6E36
2452OneLaunch Setup_.tmpC:\Users\admin\AppData\Local\Temp\is-GEUNS.tmp\split_tests.jsontext
MD5:4C2CAAA13F9A7DA52B7A5DE88BE63918
SHA256:D148FC0FB5AF1CC9FD6F65C40B7568D905B67F98E0E77EDB5D170BFCB0722FF7
2088download.tmpC:\Users\admin\AppData\Local\Temp\is-J2A3V.tmp\min-rest.bmpimage
MD5:C32BFC11F1A32BAB6A1ED327C8A89E0E
SHA256:24BEE6D5DA65DC8A65EB639E3C189F257BC4B231940BD078BBEA23BA985EABB5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
20
DNS requests
11
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3672
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
binary
1.11 Kb
unknown
2452
OneLaunch Setup_.tmp
GET
302
23.36.158.125:80
http://go.microsoft.com/fwlink/?linkid=2088631
unknown
unknown
3672
Setup.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
binary
1.05 Kb
unknown
3672
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
binary
824 b
unknown
3672
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
binary
555 b
unknown
3672
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
binary
519 b
unknown
3672
Setup.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
binary
767 b
unknown
3672
Setup.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?17139c9c5265827d
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2088
download.tmp
104.26.13.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2088
download.tmp
54.213.159.187:443
api.keen.io
AMAZON-02
US
unknown
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2088
download.tmp
130.211.34.183:443
api.mixpanel.com
GOOGLE
US
whitelisted
2088
download.tmp
52.88.255.56:443
api.keen.io
AMAZON-02
US
unknown
2960
download.tmp
104.26.13.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
2452
OneLaunch Setup_.tmp
54.213.159.187:443
api.keen.io
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
update.onelaunch.com
  • 104.26.13.224
  • 104.26.12.224
  • 172.67.68.170
unknown
api.keen.io
  • 54.213.159.187
  • 52.88.255.56
  • 54.187.195.83
whitelisted
api.mixpanel.com
  • 130.211.34.183
  • 107.178.240.159
  • 35.186.241.51
  • 35.190.25.25
whitelisted
release-cdn.onelaunch.com
  • 104.26.13.224
  • 104.26.12.224
  • 172.67.68.170
unknown
go.microsoft.com
  • 23.36.158.125
whitelisted
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

PID
Process
Class
Message
2452
OneLaunch Setup_.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
No debug info