File name:

ATLauncher-setup-1.2.0.0.exe

Full analysis: https://app.any.run/tasks/ee9fa16c-0833-4196-81f0-b09078c97b50
Verdict: Malicious activity
Analysis date: January 24, 2024, 12:59:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9515A0D3A9DFA2C861BAEE86EE447419

SHA1:

6FA7B3341F3FA7D9BD38A194C80AE8077E842524

SHA256:

D051B434836408A72C8B8D9BE423C30BF51CEF3DF2F954B5B099740954845CCD

SSDEEP:

98304:D+cD4dn2yWzeZD/ydyQhIVhSWvmwZ4yc773U3lDn5cTTWLElAllTdfo7BZGP8lIP:yj6UT1P

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ATLauncher-setup-1.2.0.0.exe (PID: 2640)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ATLauncher-setup-1.2.0.0.exe (PID: 2640)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
    • Reads the Windows owner or organization settings

      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
    • Reads settings of System Certificates

      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
    • Reads the Internet Settings

      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
  • INFO

    • Checks supported languages

      • ATLauncher-setup-1.2.0.0.exe (PID: 2640)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
    • Reads the computer name

      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
    • Create files in a temporary directory

      • ATLauncher-setup-1.2.0.0.exe (PID: 2640)
      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
    • Reads the machine GUID from the registry

      • ATLauncher-setup-1.2.0.0.tmp (PID: 984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 459776
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.0
ProductVersionNumber: 1.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: ATLauncher
FileDescription: ATLauncher Setup
FileVersion: 1.2.0.0
LegalCopyright:
OriginalFileName:
ProductName: ATLauncher
ProductVersion: 1.2.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start atlauncher-setup-1.2.0.0.exe atlauncher-setup-1.2.0.0.tmp

Process information

PID
CMD
Path
Indicators
Parent process
984"C:\Users\admin\AppData\Local\Temp\is-C3VQQ.tmp\ATLauncher-setup-1.2.0.0.tmp" /SL5="$B017A,1526961,1202688,C:\Users\admin\AppData\Local\Temp\ATLauncher-setup-1.2.0.0.exe" C:\Users\admin\AppData\Local\Temp\is-C3VQQ.tmp\ATLauncher-setup-1.2.0.0.tmp
ATLauncher-setup-1.2.0.0.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-c3vqq.tmp\atlauncher-setup-1.2.0.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2640"C:\Users\admin\AppData\Local\Temp\ATLauncher-setup-1.2.0.0.exe" C:\Users\admin\AppData\Local\Temp\ATLauncher-setup-1.2.0.0.exe
explorer.exe
User:
admin
Company:
ATLauncher
Integrity Level:
MEDIUM
Description:
ATLauncher Setup
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\atlauncher-setup-1.2.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
3 111
Read events
3 097
Write events
14
Delete events
0

Modification events

(PID) Process:(984) ATLauncher-setup-1.2.0.0.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
3
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
984ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-C1AKH.tmp\is-HCSH8.tmpcompressed
MD5:74950BABDE1BA4FD83281BAE2C8FCC71
SHA256:2A236ADE9A67F866E20C9F35EA152D7B48A2F4742C20AF90860BD6BD6039DD9C
984ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-C1AKH.tmp\ATLauncher.exeexecutable
MD5:CDFC1F909AE90006C99ACFFD71A21671
SHA256:2B3FCAE7486CB2A82E951C481E45CACC6AD12AC1DD94531772AC1A071250AD65
2640ATLauncher-setup-1.2.0.0.exeC:\Users\admin\AppData\Local\Temp\is-C3VQQ.tmp\ATLauncher-setup-1.2.0.0.tmpexecutable
MD5:FDDFC2FD95D94FCC4F4C3D3ABC482DD7
SHA256:5B15C5D2B573D06A78B1774A6B5ED549FEF9EACE60B1B137F5186A3DAC25AB68
984ATLauncher-setup-1.2.0.0.tmpC:\Users\admin\AppData\Local\Temp\is-C1AKH.tmp\is-JLPQK.tmpexecutable
MD5:CDFC1F909AE90006C99ACFFD71A21671
SHA256:2B3FCAE7486CB2A82E951C481E45CACC6AD12AC1DD94531772AC1A071250AD65
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
984
ATLauncher-setup-1.2.0.0.tmp
104.22.68.118:443
download.nodecdn.net
CLOUDFLARENET
unknown
984
ATLauncher-setup-1.2.0.0.tmp
140.82.121.4:443
github.com
GITHUB
US
unknown
984
ATLauncher-setup-1.2.0.0.tmp
185.199.108.133:443
objects.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
download.nodecdn.net
  • 104.22.68.118
  • 104.22.69.118
  • 172.67.11.201
unknown
github.com
  • 140.82.121.4
shared
objects.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
shared

Threats

No threats detected
No debug info