| File name: | ATLauncher-setup-1.2.0.0.exe |
| Full analysis: | https://app.any.run/tasks/d3aaf32b-6c36-49a7-9d99-b63c8ef2d12d |
| Verdict: | Malicious activity |
| Analysis date: | October 30, 2023, 17:09:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 9515A0D3A9DFA2C861BAEE86EE447419 |
| SHA1: | 6FA7B3341F3FA7D9BD38A194C80AE8077E842524 |
| SHA256: | D051B434836408A72C8B8D9BE423C30BF51CEF3DF2F954B5B099740954845CCD |
| SSDEEP: | 98304:D+cD4dn2yWzeZD/ydyQhIVhSWvmwZ4yc773U3lDn5cTTWLElAllTdfo7BZGP8lIP:yj6UT1P |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 15:54:16+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 459776 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.0.0 |
| ProductVersionNumber: | 1.2.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | ATLauncher |
| FileDescription: | ATLauncher Setup |
| FileVersion: | 1.2.0.0 |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | ATLauncher |
| ProductVersion: | 1.2.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 964 | "C:\Program Files\Java\jre1.8.0_271\bin\java.exe" -version | C:\Program Files\Java\jre1.8.0_271\bin\java.exe | — | javaw.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.2710.9 Modules
| |||||||||||||||
| 1836 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2088 | C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw -version | C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe | — | javaw.exe | |||||||||||
User: admin Company: Eclipse Adoptium Integrity Level: MEDIUM Description: OpenJDK Platform binary Exit code: 0 Version: 17.0.3.0 Modules
| |||||||||||||||
| 2120 | "C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp" /SL5="$110168,1526961,1202688,C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe" | C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp | ATLauncher-setup-1.2.0.0.exe | ||||||||||||
User: admin Company: ATLauncher Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2204 | reg query HKEY_LOCAL_MACHINE\Software\JavaSoft\ /f Home /t REG_SZ /s /reg:32 | C:\Windows\System32\reg.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe" | C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe | — | explorer.exe | |||||||||||
User: admin Company: ATLauncher Integrity Level: MEDIUM Description: ATLauncher Setup Exit code: 0 Version: 1.2.0.0 Modules
| |||||||||||||||
| 2516 | "C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -Djna.nosys=true -Djava.net.preferIPv4Stack=true -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true -classpath "C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe;lib\oshi-core-6.4.4.jar;lib\jna-platform-5.13.0.jar;lib\jna-5.13.0.jar;lib\authlib-1.5.21.jar;lib\gson-2.10.1.jar;lib\guava-32.1.1-jre.jar;lib\xz-1.9.jar;lib\base64-2.3.9.jar;lib\discord-rpc-1.6.2.jar;lib\jopt-simple-5.0.4.jar;lib\zt-zip-1.15.jar;lib\okhttp-tls-4.11.0.jar;lib\apollo-rx3-support-2.5.14.jar;lib\apollo-runtime-2.5.14.jar;lib\apollo-http-cache-2.5.14.jar;lib\okhttp-4.11.0.jar;lib\sentry-6.25.0.jar;lib\gettext-lib-88ae68d897.jar;lib\log4j-core-2.20.0.jar;lib\log4j-api-2.20.0.jar;lib\murmur-1.0.0.jar;lib\commons-text-1.10.0.jar;lib\commons-lang3-3.12.0.jar;lib\commons-compress-1.23.0.jar;lib\flatlaf-extras-3.1.1.jar;lib\flatlaf-3.1.1.jar;lib\jlhttp-2.6.jar;lib\joda-time-2.12.5.jar;lib\commonmark-0.21.0.jar;lib\dbus-java-3.3.2.jar;lib\nekodetector-Version-1.1-pre.jar;lib\rxswing-a5749ad421.jar;lib\rxjava-3.1.6.jar;lib\failureaccess-1.0.1.jar;lib\apollo-normalized-cache-jvm-2.5.14.jar;lib\cache-2.0.2.jar;lib\jsr305-3.0.2.jar;lib\checker-qual-3.33.0.jar;lib\error_prone_annotations-2.18.0.jar;lib\commons-codec-1.9.jar;lib\commons-io-2.4.jar;lib\slf4j-api-2.0.7.jar;lib\apollo-http-cache-api-2.5.14.jar;lib\apollo-normalized-cache-api-jvm-2.5.14.jar;lib\apollo-api-jvm-2.5.14.jar;lib\okio-jvm-3.2.0.jar;lib\kotlin-stdlib-jdk8-1.6.20.jar;lib\kotlin-stdlib-jdk7-1.6.20.jar;lib\uuid-jvm-0.2.0.jar;lib\kotlin-stdlib-1.6.20.jar;lib\antlr4-runtime-4.7.3.jar;lib\svgSalamander-1.1.3.jar;lib\jnr-unixsocket-0.38.17.jar;lib\jnr-enxio-0.32.13.jar;lib\jnr-posix-3.1.15.jar;lib\jnr-ffi-2.2.11.jar;lib\asm-commons-9.2.jar;lib\asm-util-9.2.jar;lib\asm-analysis-9.2.jar;lib\asm-tree-9.5.jar;lib\asm-9.5.jar;lib\reactive-streams-1.0.4.jar;lib\kotlin-stdlib-common-1.6.20.jar;lib\annotations-13.0.jar;lib\jnr-constants-0.10.3.jar;lib\jffi-1.3.9.jar;lib\jffi-1.3.9-native.jar;lib\jnr-a64asm-1.0.0.jar;lib\jnr-x86asm-1.0.2.jar" com.atlauncher.App | C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe | ATLauncher.exe | ||||||||||||
User: admin Company: Eclipse Adoptium Integrity Level: MEDIUM Description: OpenJDK Platform binary Exit code: 0 Version: 17.0.3.0 Modules
| |||||||||||||||
| 3204 | "C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe" | C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe | — | ATLauncher-setup-1.2.0.0.tmp | |||||||||||
User: admin Company: ATLauncher Integrity Level: MEDIUM Description: ATLauncher Exit code: 0 Version: 3.4.34.2 Modules
| |||||||||||||||
| 3240 | C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | C:\Windows\System32\icacls.exe | — | java.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3424 | "C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -version | C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe | — | ATLauncher.exe | |||||||||||
User: admin Company: Eclipse Adoptium Integrity Level: MEDIUM Description: OpenJDK Platform binary Exit code: 0 Version: 17.0.3.0 Modules
| |||||||||||||||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1836) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{85ADB03E-2289-4223-915B-D70873E78221}\{7EF5C15D-7085-4D43-B620-12A4A734C881} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1836) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{85ADB03E-2289-4223-915B-D70873E78221} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1836) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{0A06F38F-026A-4C0C-9912-23FFB8D72FFA} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: F8F52ED52A4AEADFE5301C48BF1DC149FA80D23C4D31C8D0BA945190523682B9 | |||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\7za.exe | |||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 1023688750A33E91C7407610B8849B9F4C78E273FC89F15C8E2CB04C07F67232 | |||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 48080000C4CFF1DA530BDA01 | |||
| (PID) Process: | (2120) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-ESVUO.tmp | — | |
MD5:— | SHA256:— | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\jre.zip | — | |
MD5:— | SHA256:— | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-17C2J.tmp | — | |
MD5:— | SHA256:— | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Roaming\ATLauncher\is-0O9SK.tmp | executable | |
MD5:2068497455AC45C110CFBC3FA7BB724D | SHA256:3FD61B0EC5DF2BB0F68DC1705E97D10DA7180C83E22D592A3E490E25610FB037 | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\ATLauncher.exe | executable | |
MD5:1551CC253E73A5C0DE95CA6726ACE9E3 | SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Roaming\ATLauncher\is-QC6RV.tmp | executable | |
MD5:1551CC253E73A5C0DE95CA6726ACE9E3 | SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe | executable | |
MD5:1551CC253E73A5C0DE95CA6726ACE9E3 | SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-UEJTD.tmp | executable | |
MD5:1551CC253E73A5C0DE95CA6726ACE9E3 | SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A | |||
| 2472 | ATLauncher-setup-1.2.0.0.exe | C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp | executable | |
MD5:FDDFC2FD95D94FCC4F4C3D3ABC482DD7 | SHA256:5B15C5D2B573D06A78B1774A6B5ED549FEF9EACE60B1B137F5186A3DAC25AB68 | |||
| 2120 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\7za.exe | executable | |
MD5:43141E85E7C36E31B52B22AB94D5E574 | SHA256:EA308C76A2F927B160A143D94072B0DCE232E04B751F0C6432A94E05164E716D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | ATLauncher-setup-1.2.0.0.tmp | 104.22.69.118:443 | download.nodecdn.net | CLOUDFLARENET | — | unknown |
2120 | ATLauncher-setup-1.2.0.0.tmp | 140.82.114.4:443 | github.com | GITHUB | US | unknown |
2120 | ATLauncher-setup-1.2.0.0.tmp | 185.199.108.133:443 | objects.githubusercontent.com | FASTLY | US | unknown |
Domain | IP | Reputation |
|---|---|---|
download.nodecdn.net |
| unknown |
github.com |
| shared |
objects.githubusercontent.com |
| shared |