File name: | Manuals_AceLauncher.exe |
Full analysis: | https://app.any.run/tasks/3ffbb3ca-c18d-4797-a567-034724807a9a |
Verdict: | Malicious activity |
Analysis date: | June 04, 2025, 22:36:58 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections |
MD5: | 67F609E648D0F05EAB4504CE4A78531B |
SHA1: | B21CE1A65360F93D923F41040DFD9B78114AE645 |
SHA256: | D49EEE811EF94B52DDE3200C156C6C3156AC94F2F09059FE8C0CA9603C2FC97A |
SSDEEP: | 98304:3LVIF8P3n1BLHxtD59KEKjSvk43sCwVTk9E28IHboxIEBNwymlVH/nLAac2e6yRR:m23ccdKT |
.exe | | | Inno Setup installer (65.1) |
---|---|---|
.exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
.dll | | | Win32 Dynamic Link Library (generic) (3.9) |
.exe | | | Win32 Executable (generic) (2.6) |
.exe | | | Win16/32 Executable Delphi generic (1.2) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2025:03:13 06:55:45+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 704512 |
InitializedDataSize: | 137216 |
UninitializedDataSize: | - |
EntryPoint: | 0xacfe0 |
OSVersion: | 6.1 |
ImageVersion: | - |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 0.0.0.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | Sunstream Labs |
FileDescription: | AceLauncherInstaller Setup |
FileVersion: | |
LegalCopyright: | |
OriginalFileName: | |
ProductName: | AceLauncherInstaller |
ProductVersion: | 1.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
236 | "C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=network --disable-quic --start-stack-profiler --metrics-shmem-handle=2196,i,3459698101917424114,8235676587889194887,524288 --field-trial-handle=2016,i,5513286750923170692,9792630325955484550,262144 --variations-seed-version --mojo-platform-channel-handle=2328 /prefetch:3 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe | AceLauncher.exe | ||||||||||||
User: admin Company: Sunstream Labs Integrity Level: LOW Description: AceLauncher Version: 134.0.6998.210 Modules
| |||||||||||||||
760 | "C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\SetupHelper\AceLauncherInstaller.exe" Manuals prompt | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\SetupHelper\AceLauncherInstaller.exe | — | Manuals_AceLauncher.tmp | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 1 Version: 1.0.19 Modules
| |||||||||||||||
896 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\AceLauncher\User Data" /prefetch:4 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\AceLauncher\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=AceLauncher --annotation=ver=134.0.6998.210 --initial-client-data=0x1bc,0x1c0,0x1c4,0x16c,0x1c8,0x7ff7a5191540,0x7ff7a519154c,0x7ff7a5191558 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe | — | AceLauncher.exe | |||||||||||
User: admin Company: Sunstream Labs Integrity Level: MEDIUM Description: AceLauncher Exit code: 0 Version: 134.0.6998.210 Modules
| |||||||||||||||
1240 | "C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=network --disable-quic --start-stack-profiler --metrics-shmem-handle=2172,i,15089248304294961997,15891488714509784547,524288 --field-trial-handle=1964,i,13070173194145431458,17827005827196847369,262144 --variations-seed-version --mojo-platform-channel-handle=2132 /prefetch:3 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe | AceLauncher.exe | ||||||||||||
User: admin Company: Sunstream Labs Integrity Level: LOW Description: AceLauncher Exit code: 4294967295 Version: 134.0.6998.210 Modules
| |||||||||||||||
1268 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=5476 --field-trial-handle=2024,i,18014103453777084650,4111751366971146302,262144 --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
1852 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4600 --field-trial-handle=2024,i,18014103453777084650,4111751366971146302,262144 --variations-seed-version /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 122.0.6261.70 Modules
| |||||||||||||||
2040 | "C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --metrics-shmem-handle=5816,i,12735763881283850085,11926758197542416013,524288 --field-trial-handle=1964,i,13070173194145431458,17827005827196847369,262144 --variations-seed-version --mojo-platform-channel-handle=1872 /prefetch:8 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe | — | AceLauncher.exe | |||||||||||
User: admin Company: Sunstream Labs Integrity Level: LOW Description: AceLauncher Exit code: 0 Version: 134.0.6998.210 Modules
| |||||||||||||||
2088 | "C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --metrics-shmem-handle=6604,i,11668144152920629860,13401804862433465583,524288 --field-trial-handle=1964,i,13070173194145431458,17827005827196847369,262144 --variations-seed-version --mojo-platform-channel-handle=6584 /prefetch:8 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe | — | AceLauncher.exe | |||||||||||
User: admin Company: Sunstream Labs Integrity Level: LOW Description: AceLauncher Exit code: 0 Version: 134.0.6998.210 Modules
| |||||||||||||||
2240 | "C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --metrics-shmem-handle=3768,i,7001257071233650276,498677159298376823,2097152 --field-trial-handle=1964,i,13070173194145431458,17827005827196847369,262144 --variations-seed-version --mojo-platform-channel-handle=3764 /prefetch:1 | C:\Users\admin\AppData\Local\AceLauncher\Application\AceLauncher.exe | — | AceLauncher.exe | |||||||||||
User: admin Company: Sunstream Labs Integrity Level: LOW Description: AceLauncher Exit code: 4294967295 Version: 134.0.6998.210 Modules
| |||||||||||||||
2244 | "C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\CR_84C3E.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\CR_84C3E.tmp\CHROME.PACKED.7Z" | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\CR_84C3E.tmp\setup.exe | mini_installer.exe | ||||||||||||
User: admin Company: Sunstream Labs Integrity Level: MEDIUM Description: AceLauncher Installer Exit code: 0 Version: 134.0.6998.210 Modules
|
(PID) Process: | (760) AceLauncherInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncherUpdater\BrowserSettings |
Operation: | write | Name: | WakeUp |
Value: true | |||
(PID) Process: | (760) AceLauncherInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DockSettings |
Operation: | delete value | Name: | ClosedByUser |
Value: | |||
(PID) Process: | (760) AceLauncherInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncherUpdater\BrowserSettings |
Operation: | write | Name: | RunInBackgroundEnabled |
Value: true | |||
(PID) Process: | (760) AceLauncherInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\ImportBrowserData |
Operation: | write | Name: | ShouldImport |
Value: true | |||
(PID) Process: | (760) AceLauncherInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncherUpdater\BrowserSettings |
Operation: | write | Name: | NewTabStyle |
Value: Chrome | |||
(PID) Process: | (760) AceLauncherInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DownloadStage |
Operation: | write | Name: | Mode |
Value: start | |||
(PID) Process: | (7316) Manuals_AceLauncher.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DownloadProgress |
Operation: | write | Name: | Progress |
Value: 0/100823464/mini_installer.exe | |||
(PID) Process: | (7316) Manuals_AceLauncher.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DownloadProgress |
Operation: | write | Name: | Progress |
Value: 0/1 | |||
(PID) Process: | (7316) Manuals_AceLauncher.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DownloadProgress |
Operation: | write | Name: | Progress |
Value: 529684/100823464/mini_installer.exe | |||
(PID) Process: | (7316) Manuals_AceLauncher.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\AceLauncher\DownloadProgress |
Operation: | write | Name: | Progress |
Value: 1058004/100823464/mini_installer.exe |
PID | Process | Filename | Type | |
---|---|---|---|---|
7316 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\is-F63SB.tmp | — | |
MD5:— | SHA256:— | |||
7316 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\mini_installer.exe | — | |
MD5:— | SHA256:— | |||
5232 | AceLauncherInstaller.exe | C:\Users\admin\AppData\Local\AceLauncher\User Data\Local State | — | |
MD5:— | SHA256:— | |||
3036 | Manuals_AceLauncher.exe | C:\Users\admin\AppData\Local\Temp\is-RF4D4.tmp\Manuals_AceLauncher.tmp | executable | |
MD5:685239A5636FBE11926667BE887C41F0 | SHA256:2AC443733F10FD3789609576376AF6544DBC6C8FADD5EE407CF736C04A8690D8 | |||
5096 | Manuals_AceLauncher.exe | C:\Users\admin\AppData\Local\Temp\is-7MN4U.tmp\Manuals_AceLauncher.tmp | executable | |
MD5:685239A5636FBE11926667BE887C41F0 | SHA256:2AC443733F10FD3789609576376AF6544DBC6C8FADD5EE407CF736C04A8690D8 | |||
6040 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-2T4HK.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
7316 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
7316 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\SetupHelper\Newtonsoft.Json.dll | executable | |
MD5:195FFB7167DB3219B217C4FD439EEDD6 | SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D | |||
7316 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\SetupHelper\AceLauncherInstaller.exe.config | xml | |
MD5:2A2DF45A07478A1C77D5834C21F3D7FD | SHA256:051099983B896673909E01A1F631B6652ABB88DA95C9F06F3EFEF4BE033091FA | |||
7316 | Manuals_AceLauncher.tmp | C:\Users\admin\AppData\Local\Temp\is-AHK3M.tmp\is-QEK7T.tmp | compressed | |
MD5:94869F0E9C21DE4236E02017F1ACBB03 | SHA256:6A3C4FBA8F51D0A3818E8F2C90BAF468067DFBB6B4EE81BEDEB60AC3C7E2DFC9 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.18.121.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1240 | AceLauncher.exe | GET | 200 | 142.250.186.174:80 | http://clients2.google.com/time/1/current?cup2key=8:FugAcSkeRBuk3R6yrAJm9sg-Pq8R7puayfSn5H7hatQ&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
8028 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8028 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
236 | AceLauncher.exe | GET | 200 | 142.250.186.174:80 | http://clients2.google.com/time/1/current?cup2key=8:rJwopWv6aqSTLB6GqcDKlyaRbpNgMsoNFrfvqXoq_do&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | unknown | — | — | whitelisted |
7916 | AceLauncher.exe | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAqZYVkpXnDOCn45Pde5S1U%3D | unknown | — | — | whitelisted |
7916 | AceLauncher.exe | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
7916 | AceLauncher.exe | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2516 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5408 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.18.121.139:80 | crl.microsoft.com | AKAMAI-AS | FR | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7316 | Manuals_AceLauncher.tmp | 52.203.92.28:443 | analytics.acelauncher.com | AMAZON-AES | US | unknown |
7316 | Manuals_AceLauncher.tmp | 18.66.147.102:443 | download.acelauncher.com | AMAZON-02 | US | unknown |
6544 | svchost.exe | 40.126.32.134:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
---|---|---|
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
analytics.acelauncher.com |
| unknown |
download.acelauncher.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |