File name:

SKlauncher-3.2.10.exe

Full analysis: https://app.any.run/tasks/c6745cc3-6470-41e4-9655-17cf8fba1471
Verdict: Malicious activity
Analysis date: January 18, 2025, 20:14:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

EBB40145A6BFBED88859E41689315D82

SHA1:

7BB2C82EF24EF919D04592930BCEAE039F78AEBF

SHA256:

E4BAEAA3C58628ACFD7058B9D434AB2E6A7400445F55685169A79F045810298C

SSDEEP:

98304:Ye32eSHCF+TviOsmxu4BKv1XfOppYmhDbVlE0j46F66NS9N1yahSaCsM6Fm08lFN:4YFIz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for Java to be installed

      • SKlauncher-3.2.10.exe (PID: 6464)
    • Executable content was dropped or overwritten

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • There is functionality for taking screenshot (YARA)

      • SKlauncher-3.2.10.exe (PID: 6464)
    • Uses RUNDLL32.EXE to load library

      • SKlauncher-3.2.10.exe (PID: 6464)
    • Process drops legitimate windows executable

      • SKlauncher-3.2.10.exe (PID: 6464)
    • The process creates files with name similar to system file names

      • SKlauncher-3.2.10.exe (PID: 6464)
    • The process drops C-runtime libraries

      • SKlauncher-3.2.10.exe (PID: 6464)
    • The process checks if it is being run in the virtual environment

      • MinecraftJava.exe (PID: 4188)
  • INFO

    • Creates files in the program directory

      • java.exe (PID: 6508)
    • Checks supported languages

      • SKlauncher-3.2.10.exe (PID: 6464)
      • java.exe (PID: 6508)
      • identity_helper.exe (PID: 6652)
      • MinecraftJava.exe (PID: 4188)
      • javaw.exe (PID: 1356)
    • Creates files or folders in the user directory

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Reads the machine GUID from the registry

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Create files in a temporary directory

      • java.exe (PID: 6508)
      • SKlauncher-3.2.10.exe (PID: 6464)
      • javaw.exe (PID: 1356)
      • MinecraftJava.exe (PID: 4188)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 3608)
    • Application launched itself

      • msedge.exe (PID: 6672)
      • msedge.exe (PID: 4228)
    • Reads Environment values

      • identity_helper.exe (PID: 6652)
    • Reads the computer name

      • identity_helper.exe (PID: 6652)
      • MinecraftJava.exe (PID: 4188)
    • The sample compiled with english language support

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Reads CPU info

      • javaw.exe (PID: 1356)
      • MinecraftJava.exe (PID: 4188)
    • Process checks computer location settings

      • MinecraftJava.exe (PID: 4188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2022:11:18 17:55:10+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 9
CodeSize: 244736
InitializedDataSize: 171520
UninitializedDataSize: -
EntryPoint: 0x21394
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 3.2.10.0
ProductVersionNumber: 3.2.10.0
FileFlagsMask: 0x0017
FileFlags: Debug
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Mojang
FileDescription: The Minecraft Launcher
FileVersion: 3.2.10.0
LegalCopyright: -
ProductName: SKlauncher
ProductVersion: 3.2.10
OriginalFileName: SKlauncher-3.2.10.exe
InternalName: SKlauncher
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
184
Monitored processes
52
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sklauncher-3.2.10.exe java.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs javaw.exe no specs minecraftjava.exe

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4504 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1356C:\Users\admin\AppData\Roaming\.minecraft\runtime\java-runtime-delta\bin\javaw.exe -XshowSettings:properties -versionC:\Users\admin\AppData\Roaming\.minecraft\runtime\java-runtime-delta\bin\javaw.exeSKlauncher-3.2.10.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
21.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\.minecraft\runtime\java-runtime-delta\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\.minecraft\runtime\java-runtime-delta\bin\jli.dll
c:\windows\system32\user32.dll
c:\users\admin\appdata\roaming\.minecraft\runtime\java-runtime-delta\bin\vcruntime140.dll
c:\windows\system32\win32u.dll
1400"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4288 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1740"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6084 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1828"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4280 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1096 --field-trial-handle=2356,i,5336657708179757845,7458103568068280045,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3532 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5532 --field-trial-handle=2356,i,5336657708179757845,7458103568068280045,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2676"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5460 --field-trial-handle=2356,i,5336657708179757845,7458103568068280045,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2744reg query "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v AppsUseLightThemeC:\Windows\System32\reg.exeSKlauncher-3.2.10.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
8 597
Read events
8 568
Write events
29
Delete events
0

Modification events

(PID) Process:(6464) SKlauncher-3.2.10.exeKey:HKEY_CURRENT_USER\SOFTWARE\ej-technologies\exe4j\jvms2\c:/program files/java/jre1.8.0_271/bin/java.exe
Operation:writeName:LastWriteTime
Value:
FE850DA0993CD901
(PID) Process:(6464) SKlauncher-3.2.10.exeKey:HKEY_CURRENT_USER\SOFTWARE\ej-technologies\exe4j\jvms2\c:/program files/java/jre1.8.0_271/bin/java.exe
Operation:writeName:Version
Value:
1.8.0_271
(PID) Process:(6464) SKlauncher-3.2.10.exeKey:HKEY_CURRENT_USER\SOFTWARE\ej-technologies\exe4j\jvms2\c:/program files/java/jre1.8.0_271/bin/java.exe
Operation:writeName:Machine
Value:
34404
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(6672) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6672) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6672) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
Executable files
224
Suspicious files
4 591
Text files
410
Unknown types
0

Dropped files

PID
Process
Filename
Type
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\.minecraft\sklauncher\sklauncher-fx.jar.xz
MD5:
SHA256:
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\imageio9076975324295311258.tmpimage
MD5:4BC22D05B225A34A3DDB4F17D2469B77
SHA256:FACE76C9C4FAD9476A1D80483D41772C805808A1383012B1C22065E30D32EDE6
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
6508java.exeC:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8061.timestamptext
MD5:11CF085923151C7554140E1AF43FADE6
SHA256:CDC3AB2371612C2C3E6608581FCD691E8B646426344649D3686BBECB26E22AF0
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\flatlaf.temp\flatlaf-windows-x86_64-12703153037600.dllexecutable
MD5:8B9F16320499ECE60D7FF0C1249C6DF7
SHA256:F8A3AF19341AC0F12F55AD28169D22B75AA66ED818692541307393C22F986727
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\.minecraft\sklauncher\sklauncher.vmoptionstext
MD5:BC1A9C2EEE2A390645B649E004E696FF
SHA256:651E9EB5261EC8944F0B0014CA6591950080F6AB69D3917703D5923594AE9491
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\imageio7154221958779282739.tmpimage
MD5:8EE50698797304540FC85117D67FE39A
SHA256:90F1E2BCC7B6C2E9B5ACBF3211ECB0B58F9E36B4F3DB56ACFC07F2A3577B644A
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\.minecraft\sklauncher-fx.jarcompressed
MD5:4096093FE4602F579B1DF6841503CE63
SHA256:97301C4B18102ABE200E1E78B4D05618683A0C74DE08485B3D672E06E5196880
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\e4j5538.tmp_dir1737231273\exe4jlib.jarjava
MD5:BD8451491A92B1AA5FE6D44BC9F3E1C6
SHA256:8A416DAB7B3028F3E79B41521B65432AB2D25DEC9F85E220ADE0157BADC0DD41
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\e4j5538.tmp_dir1737231273\SKlauncher-3.2.10.jarcompressed
MD5:1495E81AA573744050268CB330AF8281
SHA256:3CE7E5AFF85320E1D393EB34E918A6B71A667BCCF08252FBDD512443E5D62F9A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
374
DNS requests
123
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
880
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5540
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6424
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5540
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7140
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7140
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
7140
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
7140
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
880
svchost.exe
184.30.21.171:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.218.210.69:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6464
SKlauncher-3.2.10.exe
104.21.16.1:443
files.skmedix.pl
CLOUDFLARENET
suspicious
1176
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
www.bing.com
  • 104.126.37.137
  • 104.126.37.177
  • 104.126.37.144
  • 104.126.37.128
  • 104.126.37.178
  • 104.126.37.123
  • 104.126.37.130
  • 104.126.37.184
  • 104.126.37.179
  • 2.21.65.157
  • 2.21.65.153
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
go.microsoft.com
  • 23.218.210.69
  • 184.28.89.167
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.74
  • 40.126.32.133
  • 20.190.160.22
  • 40.126.32.68
whitelisted
files.skmedix.pl
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.112.1
unknown
textures.skmedix.pl
  • 104.21.112.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.16.1
  • 104.21.96.1
unknown
beta.skmedix.pl
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.112.1
unknown
sessionserver.skmedix.pl
  • 104.21.96.1
  • 104.21.32.1
  • 104.21.112.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.16.1
  • 104.21.48.1
unknown
meta.skmedix.pl
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.112.1
unknown

Threats

No threats detected
No debug info