File name:

SKlauncher-3.2.10.exe

Full analysis: https://app.any.run/tasks/c6745cc3-6470-41e4-9655-17cf8fba1471
Verdict: Malicious activity
Analysis date: January 18, 2025, 20:14:28
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

EBB40145A6BFBED88859E41689315D82

SHA1:

7BB2C82EF24EF919D04592930BCEAE039F78AEBF

SHA256:

E4BAEAA3C58628ACFD7058B9D434AB2E6A7400445F55685169A79F045810298C

SSDEEP:

98304:Ye32eSHCF+TviOsmxu4BKv1XfOppYmhDbVlE0j46F66NS9N1yahSaCsM6Fm08lFN:4YFIz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for Java to be installed

      • SKlauncher-3.2.10.exe (PID: 6464)
    • There is functionality for taking screenshot (YARA)

      • SKlauncher-3.2.10.exe (PID: 6464)
    • Executable content was dropped or overwritten

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Uses RUNDLL32.EXE to load library

      • SKlauncher-3.2.10.exe (PID: 6464)
    • Process drops legitimate windows executable

      • SKlauncher-3.2.10.exe (PID: 6464)
    • The process drops C-runtime libraries

      • SKlauncher-3.2.10.exe (PID: 6464)
    • The process checks if it is being run in the virtual environment

      • MinecraftJava.exe (PID: 4188)
    • The process creates files with name similar to system file names

      • SKlauncher-3.2.10.exe (PID: 6464)
  • INFO

    • Checks supported languages

      • SKlauncher-3.2.10.exe (PID: 6464)
      • java.exe (PID: 6508)
      • identity_helper.exe (PID: 6652)
      • javaw.exe (PID: 1356)
      • MinecraftJava.exe (PID: 4188)
    • Creates files in the program directory

      • java.exe (PID: 6508)
    • Reads the machine GUID from the registry

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Creates files or folders in the user directory

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Create files in a temporary directory

      • java.exe (PID: 6508)
      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
      • javaw.exe (PID: 1356)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 3608)
    • Application launched itself

      • msedge.exe (PID: 4228)
      • msedge.exe (PID: 6672)
    • Reads the computer name

      • identity_helper.exe (PID: 6652)
      • MinecraftJava.exe (PID: 4188)
    • Reads Environment values

      • identity_helper.exe (PID: 6652)
    • The sample compiled with english language support

      • SKlauncher-3.2.10.exe (PID: 6464)
      • MinecraftJava.exe (PID: 4188)
    • Reads CPU info

      • MinecraftJava.exe (PID: 4188)
      • javaw.exe (PID: 1356)
    • Process checks computer location settings

      • MinecraftJava.exe (PID: 4188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2022:11:18 17:55:10+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 9
CodeSize: 244736
InitializedDataSize: 171520
UninitializedDataSize: -
EntryPoint: 0x21394
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 3.2.10.0
ProductVersionNumber: 3.2.10.0
FileFlagsMask: 0x0017
FileFlags: Debug
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Mojang
FileDescription: The Minecraft Launcher
FileVersion: 3.2.10.0
LegalCopyright: -
ProductName: SKlauncher
ProductVersion: 3.2.10
OriginalFileName: SKlauncher-3.2.10.exe
InternalName: SKlauncher
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
184
Monitored processes
52
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sklauncher-3.2.10.exe java.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs javaw.exe no specs minecraftjava.exe

Process information

PID
CMD
Path
Indicators
Parent process
512"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4504 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1356C:\Users\admin\AppData\Roaming\.minecraft\runtime\java-runtime-delta\bin\javaw.exe -XshowSettings:properties -versionC:\Users\admin\AppData\Roaming\.minecraft\runtime\java-runtime-delta\bin\javaw.exeSKlauncher-3.2.10.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
0
Version:
21.0.3.0
Modules
Images
c:\users\admin\appdata\roaming\.minecraft\runtime\java-runtime-delta\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\.minecraft\runtime\java-runtime-delta\bin\jli.dll
c:\windows\system32\user32.dll
c:\users\admin\appdata\roaming\.minecraft\runtime\java-runtime-delta\bin\vcruntime140.dll
c:\windows\system32\win32u.dll
1400"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4288 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1740"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6084 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1828"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4280 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --no-appcompat-clear --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAABEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1096 --field-trial-handle=2356,i,5336657708179757845,7458103568068280045,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3532 --field-trial-handle=2340,i,1658149207250289694,14358601866806820362,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5532 --field-trial-handle=2356,i,5336657708179757845,7458103568068280045,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2676"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5460 --field-trial-handle=2356,i,5336657708179757845,7458103568068280045,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2744reg query "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v AppsUseLightThemeC:\Windows\System32\reg.exeSKlauncher-3.2.10.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
8 597
Read events
8 568
Write events
29
Delete events
0

Modification events

(PID) Process:(6464) SKlauncher-3.2.10.exeKey:HKEY_CURRENT_USER\SOFTWARE\ej-technologies\exe4j\jvms2\c:/program files/java/jre1.8.0_271/bin/java.exe
Operation:writeName:LastWriteTime
Value:
FE850DA0993CD901
(PID) Process:(6464) SKlauncher-3.2.10.exeKey:HKEY_CURRENT_USER\SOFTWARE\ej-technologies\exe4j\jvms2\c:/program files/java/jre1.8.0_271/bin/java.exe
Operation:writeName:Version
Value:
1.8.0_271
(PID) Process:(6464) SKlauncher-3.2.10.exeKey:HKEY_CURRENT_USER\SOFTWARE\ej-technologies\exe4j\jvms2\c:/program files/java/jre1.8.0_271/bin/java.exe
Operation:writeName:Machine
Value:
34404
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3608) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(6672) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(6672) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(6672) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
Executable files
224
Suspicious files
4 591
Text files
410
Unknown types
0

Dropped files

PID
Process
Filename
Type
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\.minecraft\sklauncher\sklauncher-fx.jar.xz
MD5:
SHA256:
6508java.exeC:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8061.timestamptext
MD5:11CF085923151C7554140E1AF43FADE6
SHA256:CDC3AB2371612C2C3E6608581FCD691E8B646426344649D3686BBECB26E22AF0
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\e4j5538.tmp_dir1737231273\i4jdel.exeexecutable
MD5:802D1182A4685E1B86C0A9DCB3F2BE36
SHA256:E48EF14933F4EB6071497A5311CA0AC6E115F7A0D57A60E519296F8FD42AD4FE
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\e4j5538.tmp_dir1737231273\SKlauncher-3.2.10.jarcompressed
MD5:1495E81AA573744050268CB330AF8281
SHA256:3CE7E5AFF85320E1D393EB34E918A6B71A667BCCF08252FBDD512443E5D62F9A
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\+JXF1215077514895364766.tmpbinary
MD5:FF5FDC6F42C720A3EBD7B60F6D605888
SHA256:1936D24CB0F4CE7006E08C6EF4243D2E42A7B45F2249F8FE54D92F76A317DFD1
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\.minecraft\sklauncher-fx.jarcompressed
MD5:4096093FE4602F579B1DF6841503CE63
SHA256:97301C4B18102ABE200E1E78B4D05618683A0C74DE08485B3D672E06E5196880
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\flatlaf.temp\flatlaf-windows-x86_64-12703153037600.dllexecutable
MD5:8B9F16320499ECE60D7FF0C1249C6DF7
SHA256:F8A3AF19341AC0F12F55AD28169D22B75AA66ED818692541307393C22F986727
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Roaming\.minecraft\sklauncher\accounts.jsonbinary
MD5:29E2584555867768ED55FD94A5F69CA1
SHA256:0F8EF90B02076E3D5EAEE12C0C30E6906CE2C29BCB5AAE06DA654F9FFAC297AD
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\+JXF2469443996716833051.tmpbinary
MD5:FDB50E0D48CDCF775FA1AC0DC3C33BD4
SHA256:64F8BE6E55C37E32EF03DA99714BF3AA58B8F2099BFE4F759A7578E3B8291123
6464SKlauncher-3.2.10.exeC:\Users\admin\AppData\Local\Temp\+JXF8361237691377838277.tmpbinary
MD5:8F2869A84AD71F156A17BB66611EBE22
SHA256:0CB1BC1335372D9E3A0CF6F5311C7CCE87AF90D2A777FDEEC18BE605A2A70BC1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
374
DNS requests
123
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
880
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6424
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5540
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5540
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7140
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
7140
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
7140
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
7140
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/68591036-2289-4858-9f7f-9149e89c8a08?P1=1737478796&P2=404&P3=2&P4=JT5vTzQPDEmPD0aW5fsUbi23CHndlkp0X3NKK5CgNJBIrtSTccXfDIRU9Wwo7YFj3kT3TRfJ5f6MXg6D5vwL9Q%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
880
svchost.exe
184.30.21.171:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.218.210.69:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6464
SKlauncher-3.2.10.exe
104.21.16.1:443
files.skmedix.pl
CLOUDFLARENET
suspicious
1176
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
www.bing.com
  • 104.126.37.137
  • 104.126.37.177
  • 104.126.37.144
  • 104.126.37.128
  • 104.126.37.178
  • 104.126.37.123
  • 104.126.37.130
  • 104.126.37.184
  • 104.126.37.179
  • 2.21.65.157
  • 2.21.65.153
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
go.microsoft.com
  • 23.218.210.69
  • 184.28.89.167
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.72
  • 40.126.32.138
  • 20.190.160.20
  • 40.126.32.74
  • 40.126.32.133
  • 20.190.160.22
  • 40.126.32.68
whitelisted
files.skmedix.pl
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.112.1
unknown
textures.skmedix.pl
  • 104.21.112.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.16.1
  • 104.21.96.1
unknown
beta.skmedix.pl
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.112.1
unknown
sessionserver.skmedix.pl
  • 104.21.96.1
  • 104.21.32.1
  • 104.21.112.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.16.1
  • 104.21.48.1
unknown
meta.skmedix.pl
  • 104.21.16.1
  • 104.21.32.1
  • 104.21.48.1
  • 104.21.64.1
  • 104.21.80.1
  • 104.21.96.1
  • 104.21.112.1
unknown

Threats

No threats detected
No debug info