File name:

ATLauncher-setup-1.2.0.0.exe

Full analysis: https://app.any.run/tasks/d3aaf32b-6c36-49a7-9d99-b63c8ef2d12d
Verdict: Malicious activity
Analysis date: October 30, 2023, 17:09:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9515A0D3A9DFA2C861BAEE86EE447419

SHA1:

6FA7B3341F3FA7D9BD38A194C80AE8077E842524

SHA256:

D051B434836408A72C8B8D9BE423C30BF51CEF3DF2F954B5B099740954845CCD

SSDEEP:

98304:D+cD4dn2yWzeZD/ydyQhIVhSWvmwZ4yc773U3lDn5cTTWLElAllTdfo7BZGP8lIP:yj6UT1P

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ATLauncher-setup-1.2.0.0.exe (PID: 2472)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • javaw.exe (PID: 2516)
      • 7za.exe (PID: 3796)
    • Application was dropped or rewritten from another process

      • ATLauncher.exe (PID: 3204)
      • javaw.exe (PID: 3424)
      • javaw.exe (PID: 2516)
      • javaw.exe (PID: 2088)
    • Actions looks like stealing of personal data

      • javaw.exe (PID: 2516)
    • Loads dropped or rewritten executable

      • ATLauncher.exe (PID: 3204)
      • javaw.exe (PID: 3424)
      • javaw.exe (PID: 2516)
      • javaw.exe (PID: 2088)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • Reads the Windows owner or organization settings

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • Reads the Internet Settings

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 3796)
    • The process drops C-runtime libraries

      • 7za.exe (PID: 3796)
    • Application launched itself

      • javaw.exe (PID: 2516)
    • Uses REG/REGEDIT.EXE to modify registry

      • javaw.exe (PID: 2516)
    • Drops 7-zip archiver for unpacking

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
  • INFO

    • Checks supported languages

      • ATLauncher-setup-1.2.0.0.exe (PID: 2472)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • wmpnscfg.exe (PID: 1836)
      • 7za.exe (PID: 3796)
      • ATLauncher.exe (PID: 3204)
      • javaw.exe (PID: 3424)
      • javaw.exe (PID: 2516)
      • java.exe (PID: 964)
      • javaw.exe (PID: 2088)
    • Reads the computer name

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • 7za.exe (PID: 3796)
      • javaw.exe (PID: 2516)
      • wmpnscfg.exe (PID: 1836)
    • Application was dropped or rewritten from another process

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • 7za.exe (PID: 3796)
    • Reads the machine GUID from the registry

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • wmpnscfg.exe (PID: 1836)
      • javaw.exe (PID: 2516)
    • Create files in a temporary directory

      • ATLauncher-setup-1.2.0.0.exe (PID: 2472)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • javaw.exe (PID: 3424)
      • javaw.exe (PID: 2516)
      • java.exe (PID: 964)
      • javaw.exe (PID: 2088)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1836)
    • Creates files or folders in the user directory

      • 7za.exe (PID: 3796)
      • javaw.exe (PID: 2516)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • Process checks computer location settings

      • javaw.exe (PID: 2516)
    • Reads CPU info

      • javaw.exe (PID: 2516)
    • Creates files in the program directory

      • java.exe (PID: 964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 459776
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.0
ProductVersionNumber: 1.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ATLauncher
FileDescription: ATLauncher Setup
FileVersion: 1.2.0.0
LegalCopyright:
OriginalFileName:
ProductName: ATLauncher
ProductVersion: 1.2.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
11
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start atlauncher-setup-1.2.0.0.exe no specs atlauncher-setup-1.2.0.0.tmp wmpnscfg.exe no specs 7za.exe no specs atlauncher.exe no specs javaw.exe no specs javaw.exe reg.exe no specs java.exe no specs icacls.exe no specs javaw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
964"C:\Program Files\Java\jre1.8.0_271\bin\java.exe" -versionC:\Program Files\Java\jre1.8.0_271\bin\java.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\java.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2088C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw -versionC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exejavaw.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2120"C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp" /SL5="$110168,1526961,1202688,C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe" C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp
ATLauncher-setup-1.2.0.0.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rcape.tmp\atlauncher-setup-1.2.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mpr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2204reg query HKEY_LOCAL_MACHINE\Software\JavaSoft\ /f Home /t REG_SZ /s /reg:32C:\Windows\System32\reg.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
2472"C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe" C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exeexplorer.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
ATLauncher Setup
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\downloads\atlauncher-setup-1.2.0.0.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2516"C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -Djna.nosys=true -Djava.net.preferIPv4Stack=true -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true -classpath "C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe;lib\oshi-core-6.4.4.jar;lib\jna-platform-5.13.0.jar;lib\jna-5.13.0.jar;lib\authlib-1.5.21.jar;lib\gson-2.10.1.jar;lib\guava-32.1.1-jre.jar;lib\xz-1.9.jar;lib\base64-2.3.9.jar;lib\discord-rpc-1.6.2.jar;lib\jopt-simple-5.0.4.jar;lib\zt-zip-1.15.jar;lib\okhttp-tls-4.11.0.jar;lib\apollo-rx3-support-2.5.14.jar;lib\apollo-runtime-2.5.14.jar;lib\apollo-http-cache-2.5.14.jar;lib\okhttp-4.11.0.jar;lib\sentry-6.25.0.jar;lib\gettext-lib-88ae68d897.jar;lib\log4j-core-2.20.0.jar;lib\log4j-api-2.20.0.jar;lib\murmur-1.0.0.jar;lib\commons-text-1.10.0.jar;lib\commons-lang3-3.12.0.jar;lib\commons-compress-1.23.0.jar;lib\flatlaf-extras-3.1.1.jar;lib\flatlaf-3.1.1.jar;lib\jlhttp-2.6.jar;lib\joda-time-2.12.5.jar;lib\commonmark-0.21.0.jar;lib\dbus-java-3.3.2.jar;lib\nekodetector-Version-1.1-pre.jar;lib\rxswing-a5749ad421.jar;lib\rxjava-3.1.6.jar;lib\failureaccess-1.0.1.jar;lib\apollo-normalized-cache-jvm-2.5.14.jar;lib\cache-2.0.2.jar;lib\jsr305-3.0.2.jar;lib\checker-qual-3.33.0.jar;lib\error_prone_annotations-2.18.0.jar;lib\commons-codec-1.9.jar;lib\commons-io-2.4.jar;lib\slf4j-api-2.0.7.jar;lib\apollo-http-cache-api-2.5.14.jar;lib\apollo-normalized-cache-api-jvm-2.5.14.jar;lib\apollo-api-jvm-2.5.14.jar;lib\okio-jvm-3.2.0.jar;lib\kotlin-stdlib-jdk8-1.6.20.jar;lib\kotlin-stdlib-jdk7-1.6.20.jar;lib\uuid-jvm-0.2.0.jar;lib\kotlin-stdlib-1.6.20.jar;lib\antlr4-runtime-4.7.3.jar;lib\svgSalamander-1.1.3.jar;lib\jnr-unixsocket-0.38.17.jar;lib\jnr-enxio-0.32.13.jar;lib\jnr-posix-3.1.15.jar;lib\jnr-ffi-2.2.11.jar;lib\asm-commons-9.2.jar;lib\asm-util-9.2.jar;lib\asm-analysis-9.2.jar;lib\asm-tree-9.5.jar;lib\asm-9.5.jar;lib\reactive-streams-1.0.4.jar;lib\kotlin-stdlib-common-1.6.20.jar;lib\annotations-13.0.jar;lib\jnr-constants-0.10.3.jar;lib\jffi-1.3.9.jar;lib\jffi-1.3.9-native.jar;lib\jnr-a64asm-1.0.0.jar;lib\jnr-x86asm-1.0.2.jar" com.atlauncher.AppC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe
ATLauncher.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
3204"C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe"C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exeATLauncher-setup-1.2.0.0.tmp
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
ATLauncher
Exit code:
0
Version:
3.4.34.2
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\atlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
3240C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ntmarta.dll
3424"C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -versionC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exeATLauncher.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
5 703
Read events
5 682
Write events
12
Delete events
9

Modification events

(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1836) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{85ADB03E-2289-4223-915B-D70873E78221}\{7EF5C15D-7085-4D43-B620-12A4A734C881}
Operation:delete keyName:(default)
Value:
(PID) Process:(1836) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{85ADB03E-2289-4223-915B-D70873E78221}
Operation:delete keyName:(default)
Value:
(PID) Process:(1836) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{0A06F38F-026A-4C0C-9912-23FFB8D72FFA}
Operation:delete keyName:(default)
Value:
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
F8F52ED52A4AEADFE5301C48BF1DC149FA80D23C4D31C8D0BA945190523682B9
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\7za.exe
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
1023688750A33E91C7407610B8849B9F4C78E273FC89F15C8E2CB04C07F67232
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
48080000C4CFF1DA530BDA01
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
110
Suspicious files
23
Text files
384
Unknown types
0

Dropped files

PID
Process
Filename
Type
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-ESVUO.tmp
MD5:
SHA256:
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\jre.zip
MD5:
SHA256:
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-17C2J.tmp
MD5:
SHA256:
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Roaming\ATLauncher\is-0O9SK.tmpexecutable
MD5:2068497455AC45C110CFBC3FA7BB724D
SHA256:3FD61B0EC5DF2BB0F68DC1705E97D10DA7180C83E22D592A3E490E25610FB037
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\ATLauncher.exeexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Roaming\ATLauncher\is-QC6RV.tmpexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exeexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-UEJTD.tmpexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
2472ATLauncher-setup-1.2.0.0.exeC:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmpexecutable
MD5:FDDFC2FD95D94FCC4F4C3D3ABC482DD7
SHA256:5B15C5D2B573D06A78B1774A6B5ED549FEF9EACE60B1B137F5186A3DAC25AB68
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\7za.exeexecutable
MD5:43141E85E7C36E31B52B22AB94D5E574
SHA256:EA308C76A2F927B160A143D94072B0DCE232E04B751F0C6432A94E05164E716D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2120
ATLauncher-setup-1.2.0.0.tmp
104.22.69.118:443
download.nodecdn.net
CLOUDFLARENET
unknown
2120
ATLauncher-setup-1.2.0.0.tmp
140.82.114.4:443
github.com
GITHUB
US
unknown
2120
ATLauncher-setup-1.2.0.0.tmp
185.199.108.133:443
objects.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
download.nodecdn.net
  • 104.22.69.118
  • 172.67.11.201
  • 104.22.68.118
unknown
github.com
  • 140.82.114.4
shared
objects.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared

Threats

No threats detected
No debug info