File name:

ATLauncher-setup-1.2.0.0.exe

Full analysis: https://app.any.run/tasks/d3aaf32b-6c36-49a7-9d99-b63c8ef2d12d
Verdict: Malicious activity
Analysis date: October 30, 2023, 17:09:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9515A0D3A9DFA2C861BAEE86EE447419

SHA1:

6FA7B3341F3FA7D9BD38A194C80AE8077E842524

SHA256:

D051B434836408A72C8B8D9BE423C30BF51CEF3DF2F954B5B099740954845CCD

SSDEEP:

98304:D+cD4dn2yWzeZD/ydyQhIVhSWvmwZ4yc773U3lDn5cTTWLElAllTdfo7BZGP8lIP:yj6UT1P

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ATLauncher-setup-1.2.0.0.exe (PID: 2472)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • javaw.exe (PID: 2516)
      • 7za.exe (PID: 3796)
    • Application was dropped or rewritten from another process

      • ATLauncher.exe (PID: 3204)
      • javaw.exe (PID: 3424)
      • javaw.exe (PID: 2516)
      • javaw.exe (PID: 2088)
    • Loads dropped or rewritten executable

      • javaw.exe (PID: 3424)
      • javaw.exe (PID: 2516)
      • ATLauncher.exe (PID: 3204)
      • javaw.exe (PID: 2088)
    • Actions looks like stealing of personal data

      • javaw.exe (PID: 2516)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • Drops 7-zip archiver for unpacking

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • Reads the Internet Settings

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
    • The process drops C-runtime libraries

      • 7za.exe (PID: 3796)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 3796)
    • Uses REG/REGEDIT.EXE to modify registry

      • javaw.exe (PID: 2516)
    • Application launched itself

      • javaw.exe (PID: 2516)
    • Reads the Windows owner or organization settings

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
  • INFO

    • Checks supported languages

      • ATLauncher-setup-1.2.0.0.exe (PID: 2472)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • wmpnscfg.exe (PID: 1836)
      • 7za.exe (PID: 3796)
      • ATLauncher.exe (PID: 3204)
      • javaw.exe (PID: 3424)
      • java.exe (PID: 964)
      • javaw.exe (PID: 2088)
      • javaw.exe (PID: 2516)
    • Create files in a temporary directory

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • ATLauncher-setup-1.2.0.0.exe (PID: 2472)
      • javaw.exe (PID: 3424)
      • java.exe (PID: 964)
      • javaw.exe (PID: 2516)
      • javaw.exe (PID: 2088)
    • Reads the machine GUID from the registry

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • wmpnscfg.exe (PID: 1836)
      • javaw.exe (PID: 2516)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1836)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • 7za.exe (PID: 3796)
      • javaw.exe (PID: 2516)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1836)
    • Creates files or folders in the user directory

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • 7za.exe (PID: 3796)
      • javaw.exe (PID: 2516)
    • Application was dropped or rewritten from another process

      • ATLauncher-setup-1.2.0.0.tmp (PID: 2120)
      • 7za.exe (PID: 3796)
    • Process checks computer location settings

      • javaw.exe (PID: 2516)
    • Creates files in the program directory

      • java.exe (PID: 964)
    • Reads CPU info

      • javaw.exe (PID: 2516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 459776
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.0
ProductVersionNumber: 1.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ATLauncher
FileDescription: ATLauncher Setup
FileVersion: 1.2.0.0
LegalCopyright:
OriginalFileName:
ProductName: ATLauncher
ProductVersion: 1.2.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
11
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start atlauncher-setup-1.2.0.0.exe no specs atlauncher-setup-1.2.0.0.tmp wmpnscfg.exe no specs 7za.exe no specs atlauncher.exe no specs javaw.exe no specs javaw.exe reg.exe no specs java.exe no specs icacls.exe no specs javaw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
964"C:\Program Files\Java\jre1.8.0_271\bin\java.exe" -versionC:\Program Files\Java\jre1.8.0_271\bin\java.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\java.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
1836"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2088C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw -versionC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exejavaw.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2120"C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp" /SL5="$110168,1526961,1202688,C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe" C:\Users\admin\AppData\Local\Temp\is-RCAPE.tmp\ATLauncher-setup-1.2.0.0.tmp
ATLauncher-setup-1.2.0.0.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rcape.tmp\atlauncher-setup-1.2.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mpr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2204reg query HKEY_LOCAL_MACHINE\Software\JavaSoft\ /f Home /t REG_SZ /s /reg:32C:\Windows\System32\reg.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
2472"C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exe" C:\Users\admin\Downloads\ATLauncher-setup-1.2.0.0.exeexplorer.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
ATLauncher Setup
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\downloads\atlauncher-setup-1.2.0.0.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2516"C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -Djna.nosys=true -Djava.net.preferIPv4Stack=true -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true -classpath "C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe;lib\oshi-core-6.4.4.jar;lib\jna-platform-5.13.0.jar;lib\jna-5.13.0.jar;lib\authlib-1.5.21.jar;lib\gson-2.10.1.jar;lib\guava-32.1.1-jre.jar;lib\xz-1.9.jar;lib\base64-2.3.9.jar;lib\discord-rpc-1.6.2.jar;lib\jopt-simple-5.0.4.jar;lib\zt-zip-1.15.jar;lib\okhttp-tls-4.11.0.jar;lib\apollo-rx3-support-2.5.14.jar;lib\apollo-runtime-2.5.14.jar;lib\apollo-http-cache-2.5.14.jar;lib\okhttp-4.11.0.jar;lib\sentry-6.25.0.jar;lib\gettext-lib-88ae68d897.jar;lib\log4j-core-2.20.0.jar;lib\log4j-api-2.20.0.jar;lib\murmur-1.0.0.jar;lib\commons-text-1.10.0.jar;lib\commons-lang3-3.12.0.jar;lib\commons-compress-1.23.0.jar;lib\flatlaf-extras-3.1.1.jar;lib\flatlaf-3.1.1.jar;lib\jlhttp-2.6.jar;lib\joda-time-2.12.5.jar;lib\commonmark-0.21.0.jar;lib\dbus-java-3.3.2.jar;lib\nekodetector-Version-1.1-pre.jar;lib\rxswing-a5749ad421.jar;lib\rxjava-3.1.6.jar;lib\failureaccess-1.0.1.jar;lib\apollo-normalized-cache-jvm-2.5.14.jar;lib\cache-2.0.2.jar;lib\jsr305-3.0.2.jar;lib\checker-qual-3.33.0.jar;lib\error_prone_annotations-2.18.0.jar;lib\commons-codec-1.9.jar;lib\commons-io-2.4.jar;lib\slf4j-api-2.0.7.jar;lib\apollo-http-cache-api-2.5.14.jar;lib\apollo-normalized-cache-api-jvm-2.5.14.jar;lib\apollo-api-jvm-2.5.14.jar;lib\okio-jvm-3.2.0.jar;lib\kotlin-stdlib-jdk8-1.6.20.jar;lib\kotlin-stdlib-jdk7-1.6.20.jar;lib\uuid-jvm-0.2.0.jar;lib\kotlin-stdlib-1.6.20.jar;lib\antlr4-runtime-4.7.3.jar;lib\svgSalamander-1.1.3.jar;lib\jnr-unixsocket-0.38.17.jar;lib\jnr-enxio-0.32.13.jar;lib\jnr-posix-3.1.15.jar;lib\jnr-ffi-2.2.11.jar;lib\asm-commons-9.2.jar;lib\asm-util-9.2.jar;lib\asm-analysis-9.2.jar;lib\asm-tree-9.5.jar;lib\asm-9.5.jar;lib\reactive-streams-1.0.4.jar;lib\kotlin-stdlib-common-1.6.20.jar;lib\annotations-13.0.jar;lib\jnr-constants-0.10.3.jar;lib\jffi-1.3.9.jar;lib\jffi-1.3.9-native.jar;lib\jnr-a64asm-1.0.0.jar;lib\jnr-x86asm-1.0.2.jar" com.atlauncher.AppC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe
ATLauncher.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
3204"C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exe"C:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exeATLauncher-setup-1.2.0.0.tmp
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
ATLauncher
Exit code:
0
Version:
3.4.34.2
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\atlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
3240C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ntmarta.dll
3424"C:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exe" -versionC:\Users\admin\AppData\Roaming\ATLauncher\jre\bin\javaw.exeATLauncher.exe
User:
admin
Company:
Eclipse Adoptium
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
17.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\atlauncher\jre\bin\javaw.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\roaming\atlauncher\jre\bin\jli.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
5 703
Read events
5 682
Write events
12
Delete events
9

Modification events

(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1836) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{85ADB03E-2289-4223-915B-D70873E78221}\{7EF5C15D-7085-4D43-B620-12A4A734C881}
Operation:delete keyName:(default)
Value:
(PID) Process:(1836) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{85ADB03E-2289-4223-915B-D70873E78221}
Operation:delete keyName:(default)
Value:
(PID) Process:(1836) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{0A06F38F-026A-4C0C-9912-23FFB8D72FFA}
Operation:delete keyName:(default)
Value:
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
F8F52ED52A4AEADFE5301C48BF1DC149FA80D23C4D31C8D0BA945190523682B9
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\7za.exe
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
1023688750A33E91C7407610B8849B9F4C78E273FC89F15C8E2CB04C07F67232
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
48080000C4CFF1DA530BDA01
(PID) Process:(2120) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
110
Suspicious files
23
Text files
384
Unknown types
0

Dropped files

PID
Process
Filename
Type
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-ESVUO.tmp
MD5:
SHA256:
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\jre.zip
MD5:
SHA256:
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-17C2J.tmp
MD5:
SHA256:
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Roaming\ATLauncher\is-0O9SK.tmpexecutable
MD5:2068497455AC45C110CFBC3FA7BB724D
SHA256:3FD61B0EC5DF2BB0F68DC1705E97D10DA7180C83E22D592A3E490E25610FB037
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\is-UEJTD.tmpexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Roaming\ATLauncher\ATLauncher.exeexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-G8DSP.tmp\ATLauncher.exeexecutable
MD5:1551CC253E73A5C0DE95CA6726ACE9E3
SHA256:BDF6D6745F3DDFE511FDC4D47678D92933A7EF04B039AF0100CC20A01DA5F32A
37967za.exeC:\Users\admin\AppData\Roaming\ATLauncher\jdk-17.0.3+7-jre\bin\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:58E85F32AE30A93EEE331186F82DCC66
SHA256:3125A6F64A18383B605CF8664E919A3D1876FCA25B17E04EEA91B543802B42DF
37967za.exeC:\Users\admin\AppData\Roaming\ATLauncher\jdk-17.0.3+7-jre\bin\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:86C4C122366632A6E70B73A2242C3173
SHA256:0A7AECB785D5E38F17DD54C3A907F4F838B98AB8B121CE3B95391E03D20E584D
2120ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ATLauncher\ATLauncher.lnkbinary
MD5:8E64D243DEB8A2CB043BB46048B4B452
SHA256:721F192D4319EBBA9A074A14EEAD24097F1F0E6D0B057E57AAA9FD6ACEFFC923
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2120
ATLauncher-setup-1.2.0.0.tmp
104.22.69.118:443
download.nodecdn.net
CLOUDFLARENET
unknown
2120
ATLauncher-setup-1.2.0.0.tmp
140.82.114.4:443
github.com
GITHUB
US
unknown
2120
ATLauncher-setup-1.2.0.0.tmp
185.199.108.133:443
objects.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
download.nodecdn.net
  • 104.22.69.118
  • 172.67.11.201
  • 104.22.68.118
unknown
github.com
  • 140.82.114.4
shared
objects.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared

Threats

No threats detected
No debug info