| File name: | ATLauncher-setup-1.2.0.0.exe |
| Full analysis: | https://app.any.run/tasks/ee9fa16c-0833-4196-81f0-b09078c97b50 |
| Verdict: | Malicious activity |
| Analysis date: | January 24, 2024, 12:59:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 9515A0D3A9DFA2C861BAEE86EE447419 |
| SHA1: | 6FA7B3341F3FA7D9BD38A194C80AE8077E842524 |
| SHA256: | D051B434836408A72C8B8D9BE423C30BF51CEF3DF2F954B5B099740954845CCD |
| SSDEEP: | 98304:D+cD4dn2yWzeZD/ydyQhIVhSWvmwZ4yc773U3lDn5cTTWLElAllTdfo7BZGP8lIP:yj6UT1P |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 15:54:16+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 459776 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.0.0 |
| ProductVersionNumber: | 1.2.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | ATLauncher |
| FileDescription: | ATLauncher Setup |
| FileVersion: | 1.2.0.0 |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | ATLauncher |
| ProductVersion: | 1.2.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 984 | "C:\Users\admin\AppData\Local\Temp\is-C3VQQ.tmp\ATLauncher-setup-1.2.0.0.tmp" /SL5="$B017A,1526961,1202688,C:\Users\admin\AppData\Local\Temp\ATLauncher-setup-1.2.0.0.exe" | C:\Users\admin\AppData\Local\Temp\is-C3VQQ.tmp\ATLauncher-setup-1.2.0.0.tmp | ATLauncher-setup-1.2.0.0.exe | ||||||||||||
User: admin Company: ATLauncher Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2640 | "C:\Users\admin\AppData\Local\Temp\ATLauncher-setup-1.2.0.0.exe" | C:\Users\admin\AppData\Local\Temp\ATLauncher-setup-1.2.0.0.exe | explorer.exe | ||||||||||||
User: admin Company: ATLauncher Integrity Level: MEDIUM Description: ATLauncher Setup Exit code: 0 Version: 1.2.0.0 Modules
| |||||||||||||||
| (PID) Process: | (984) ATLauncher-setup-1.2.0.0.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 984 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-C1AKH.tmp\is-HCSH8.tmp | compressed | |
MD5:74950BABDE1BA4FD83281BAE2C8FCC71 | SHA256:2A236ADE9A67F866E20C9F35EA152D7B48A2F4742C20AF90860BD6BD6039DD9C | |||
| 984 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-C1AKH.tmp\ATLauncher.exe | executable | |
MD5:CDFC1F909AE90006C99ACFFD71A21671 | SHA256:2B3FCAE7486CB2A82E951C481E45CACC6AD12AC1DD94531772AC1A071250AD65 | |||
| 2640 | ATLauncher-setup-1.2.0.0.exe | C:\Users\admin\AppData\Local\Temp\is-C3VQQ.tmp\ATLauncher-setup-1.2.0.0.tmp | executable | |
MD5:FDDFC2FD95D94FCC4F4C3D3ABC482DD7 | SHA256:5B15C5D2B573D06A78B1774A6B5ED549FEF9EACE60B1B137F5186A3DAC25AB68 | |||
| 984 | ATLauncher-setup-1.2.0.0.tmp | C:\Users\admin\AppData\Local\Temp\is-C1AKH.tmp\is-JLPQK.tmp | executable | |
MD5:CDFC1F909AE90006C99ACFFD71A21671 | SHA256:2B3FCAE7486CB2A82E951C481E45CACC6AD12AC1DD94531772AC1A071250AD65 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
984 | ATLauncher-setup-1.2.0.0.tmp | 104.22.68.118:443 | download.nodecdn.net | CLOUDFLARENET | — | unknown |
984 | ATLauncher-setup-1.2.0.0.tmp | 140.82.121.4:443 | github.com | GITHUB | US | unknown |
984 | ATLauncher-setup-1.2.0.0.tmp | 185.199.108.133:443 | objects.githubusercontent.com | FASTLY | US | unknown |
Domain | IP | Reputation |
|---|---|---|
download.nodecdn.net |
| unknown |
github.com |
| shared |
objects.githubusercontent.com |
| shared |