File name:

fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe

Full analysis: https://app.any.run/tasks/4b7b9529-3f78-4212-9d46-1fb4a9f7805e
Verdict: Malicious activity
Analysis date: May 30, 2024, 01:31:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

13CA60D73776B420ADA5CC15848F8DFB

SHA1:

22BECE82795E9C60D76C19F22F777F3B19AF10D8

SHA256:

FBB5302B06F7E6824ECDAF59162F3A08557CAC0EFE6B40B4502EAB60ECD04D82

SSDEEP:

98304:u+QqZ8fXEn0IOfbsPk6rJl+KazHnzXM5YJhjsFA+QGfVxk3OUfpdTZTWwqE6SxbT:ff37GT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 6384)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 4148)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.exe (PID: 4288)
      • OneLaunch Setup_.tmp (PID: 6236)
    • Changes the autorun value in the registry

      • OneLaunch Setup_.tmp (PID: 6236)
      • OneLaunch.exe (PID: 608)
    • Actions looks like stealing of personal data

      • chromium.exe (PID: 720)
      • chromium.exe (PID: 6844)
      • chromium.exe (PID: 6312)
      • chromium.exe (PID: 6724)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 6700)
      • chromium.exe (PID: 5340)
      • chromium.exe (PID: 5304)
      • chromium.exe (PID: 1392)
      • OneLaunch Setup_.tmp (PID: 6236)
      • chromium.exe (PID: 4720)
      • chromium.exe (PID: 3728)
      • chromium.exe (PID: 2008)
      • chromium.exe (PID: 6304)
      • chromium.exe (PID: 5996)
      • chromium.exe (PID: 4032)
      • chromium.exe (PID: 6888)
      • chromium.exe (PID: 6780)
      • chromium.exe (PID: 2544)
      • chromium.exe (PID: 6304)
      • chromium.exe (PID: 3936)
    • Steals credentials from Web Browsers

      • chromium.exe (PID: 6844)
      • chromium.exe (PID: 1392)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.tmp (PID: 6236)
    • Reads security settings of Internet Explorer

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.tmp (PID: 6236)
      • chromium.exe (PID: 6844)
      • OneLaunch.exe (PID: 608)
      • onelaunchtray.exe (PID: 6072)
      • chromium.exe (PID: 1392)
    • Executable content was dropped or overwritten

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 6384)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 4148)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.exe (PID: 4288)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • OneLaunch Setup_.tmp (PID: 6236)
    • Reads the date of Windows installation

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.tmp (PID: 6236)
      • OneLaunch.exe (PID: 608)
    • Process drops legitimate windows executable

      • OneLaunch Setup_.tmp (PID: 6236)
    • Uses TASKKILL.EXE to kill process

      • OneLaunch Setup_.tmp (PID: 6236)
    • The process drops Mozilla's DLL files

      • OneLaunch Setup_.tmp (PID: 6236)
    • Application launched itself

      • chromium.exe (PID: 6844)
    • Executing commands from a ".bat" file

      • OneLaunch Setup_.tmp (PID: 6236)
    • Starts CMD.EXE for commands execution

      • OneLaunch Setup_.tmp (PID: 6236)
    • Executes application which crashes

      • OneLaunch Setup_.tmp (PID: 6236)
  • INFO

    • Create files in a temporary directory

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 6384)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 4148)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.exe (PID: 4288)
      • OneLaunch Setup_.tmp (PID: 6236)
      • chromium.exe (PID: 6844)
      • chromium.exe (PID: 1392)
    • Reads the software policy settings

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.tmp (PID: 6236)
      • slui.exe (PID: 4940)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 1392)
      • chromium.exe (PID: 6844)
    • Reads the machine GUID from the registry

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.tmp (PID: 6236)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 6844)
      • onelaunchtray.exe (PID: 6072)
      • chromium.exe (PID: 1392)
    • Checks supported languages

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 4148)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe (PID: 6384)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.exe (PID: 4288)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • OneLaunch Setup_.tmp (PID: 6236)
      • identity_helper.exe (PID: 3712)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 720)
      • chromium.exe (PID: 6844)
      • chromium.exe (PID: 6312)
      • chromium.exe (PID: 6724)
      • chromium.exe (PID: 6700)
      • onelaunchtray.exe (PID: 6072)
      • chromium.exe (PID: 1392)
      • chromium.exe (PID: 5304)
      • chromium.exe (PID: 5340)
      • chromium.exe (PID: 4720)
      • chromium.exe (PID: 2008)
      • chromium.exe (PID: 3728)
      • chromium.exe (PID: 5996)
      • chromium.exe (PID: 6304)
      • chromium.exe (PID: 4032)
      • chromium.exe (PID: 6888)
      • chromium.exe (PID: 6780)
      • chromium.exe (PID: 6304)
      • chromium.exe (PID: 2544)
      • chromium.exe (PID: 3936)
    • Checks proxy server information

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • chromium.exe (PID: 6844)
      • OneLaunch.exe (PID: 608)
    • Process checks computer location settings

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • OneLaunch Setup_.tmp (PID: 6236)
      • chromium.exe (PID: 6844)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 5340)
      • chromium.exe (PID: 4720)
      • chromium.exe (PID: 6304)
      • chromium.exe (PID: 3936)
    • Reads the computer name

      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 4740)
      • fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp (PID: 6404)
      • OneLaunch Setup_.tmp (PID: 6236)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 6844)
      • identity_helper.exe (PID: 3712)
      • chromium.exe (PID: 6312)
      • chromium.exe (PID: 6724)
      • onelaunchtray.exe (PID: 6072)
      • chromium.exe (PID: 1392)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6484)
      • OneLaunch Setup_.tmp (PID: 6236)
    • Application launched itself

      • msedge.exe (PID: 6484)
    • Creates files or folders in the user directory

      • OneLaunch Setup_.tmp (PID: 6236)
      • OneLaunch.exe (PID: 608)
      • chromium.exe (PID: 6844)
      • chromium.exe (PID: 6724)
      • chromium.exe (PID: 1392)
      • onelaunchtray.exe (PID: 6072)
    • Creates a software uninstall entry

      • OneLaunch Setup_.tmp (PID: 6236)
    • Creates files in the program directory

      • OneLaunch.exe (PID: 608)
      • onelaunchtray.exe (PID: 6072)
    • Disables trace logs

      • OneLaunch.exe (PID: 608)
    • Reads Environment values

      • OneLaunch.exe (PID: 608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 09:48:30+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 5.31.4.0
ProductVersionNumber: 5.31.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OneLaunch
FileDescription: OneLaunch Setup
FileVersion: 5.31.4
LegalCopyright: Copyright OneLaunch. All rights reserved.
OriginalFileName:
ProductName: OneLaunch
ProductVersion: 5.31.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
215
Monitored processes
81
Malicious processes
26
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp sppextcomobj.exe no specs slui.exe fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.exe fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp onelaunch setup_.exe onelaunch setup_.tmp msedge.exe taskkill.exe no specs conhost.exe no specs msedge.exe no specs taskkill.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs taskkill.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs onelaunch.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe onelaunchtray.exe chromium.exe cmd.exe no specs conhost.exe no specs chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe chromium.exe werfault.exe no specs chromium.exe chromium.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3772 --field-trial-handle=2376,i,6622316804216094622,9452020139899265722,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
440"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6452 --field-trial-handle=2376,i,6622316804216094622,9452020139899265722,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
608"C:\Users\admin\AppData\Local\OneLaunch\5.31.4\onelaunch.exe" /l /startedFrom=installerC:\Users\admin\AppData\Local\OneLaunch\5.31.4\OneLaunch.exe
OneLaunch Setup_.tmp
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Version:
5.31.4.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.31.4\onelaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
720C:\Users\admin\AppData\Local\OneLaunch\5.31.4\chromium\chromium.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\OneLaunch\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad" --annotation=plat=Win32 --annotation=prod=OneLaunch --annotation=ver=121.4.0.0 --initial-client-data=0x29c,0x2a0,0x2a4,0xc0,0x2a8,0x6edcabf8,0x6edcac04,0x6edcac10C:\Users\admin\AppData\Local\OneLaunch\5.31.4\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
1
Version:
121.4.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.31.4\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
892"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3452 --field-trial-handle=2376,i,6622316804216094622,9452020139899265722,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1052\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1180"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4980 --field-trial-handle=2376,i,6622316804216094622,9452020139899265722,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1324"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6300 --field-trial-handle=2376,i,6622316804216094622,9452020139899265722,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1392"C:\Users\admin\AppData\Local\OneLaunch\5.31.4\chromium\chromium.exe" --type=utility --utility-sub-type=chrome.mojom.ProfileImport --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --mojo-platform-channel-handle=3248 --field-trial-handle=2216,i,15336095742387940065,595628795703351517,262144 --variations-seed-version /prefetch:8C:\Users\admin\AppData\Local\OneLaunch\5.31.4\chromium\chromium.exe
chromium.exe
User:
admin
Company:
OneLaunch
Integrity Level:
MEDIUM
Description:
OneLaunch
Exit code:
0
Version:
121.4.0.0
Modules
Images
c:\users\admin\appdata\local\onelaunch\5.31.4\chromium\chromium.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1604"C:\Windows\System32\taskkill.exe" /f /im onelaunch.exeC:\Windows\SysWOW64\taskkill.exeOneLaunch Setup_.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
37 369
Read events
37 085
Write events
279
Delete events
5

Modification events

(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
04190000AC25D82531B2DA01
(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
834F471092D241C3E067E3320A3919371A1AF37956FDFEF9AFABF09919A397E5
(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6404) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4740) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Owner
Value:
841200004E62634C31B2DA01
(PID) Process:(4740) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:SessionHash
Value:
B9333B9F24B3DD840AE4E434AB745D344CCCD0535FA7504D4E23F21D75123300
(PID) Process:(4740) fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001
Operation:writeName:Sequence
Value:
1
Executable files
258
Suspicious files
342
Text files
304
Unknown types
37

Dropped files

PID
Process
Filename
Type
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\is-LIA7S.tmp
MD5:
SHA256:
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\OneLaunch Setup.exe
MD5:
SHA256:
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup.exe
MD5:
SHA256:
4740fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\OneLaunch Setup_.exe
MD5:
SHA256:
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\onelaunch.pngimage
MD5:D3110FB775EE7FD24426503D67840C25
SHA256:F8392390DC81756E79EC5F359DBDCAC3B4BD219B5188A429B814FC51AABB6E36
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\Win32Library.dllexecutable
MD5:564F2DFB6BEF1F47798DFB5D182232F0
SHA256:671FB4649DDD8428C7F6FD1E14B30FD4735EFBBB8C142E2662E157D87F96C9C0
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\min-10-light.pngimage
MD5:2257B1D0D33A41F509E7C3E117819F8B
SHA256:D43E4B285B5B54313B53E87D2A56CA9BA0C85F8F55C9C5FDCDB4FAC815FF4D02
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\min-pressed.bmpimage
MD5:4B549427F8B753A01272BEC3A658E7BA
SHA256:FE03E30C13229D50685E3387F4F271BEFE57DFA74BE890D09C089FB3688469A1
6404fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmpC:\Users\admin\AppData\Local\Temp\is-P12MF.tmp\onelaunch.bmpimage
MD5:00DE2DFF1787F6D7904189476B307BFB
SHA256:CC24488A078D3E92DD7DFB96C22CEBD4004EE7FCB297A438E2D3848B633A9F71
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
111
DNS requests
132
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5632
svchost.exe
GET
200
23.37.9.217:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
5632
svchost.exe
GET
200
104.103.72.96:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
1412
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
6588
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
5420
SIHClient.exe
GET
200
23.37.9.217:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
5420
SIHClient.exe
GET
200
23.37.9.217:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
6724
chromium.exe
GET
200
142.250.186.174:80
http://clients2.google.com/time/1/current?cup2key=7:aru-yuBPRNL3NNX2KQHBagU4HP4PWXgCnp0KFv1UHLE&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
608
OneLaunch.exe
GET
200
2.23.154.112:80
http://api.accuweather.com/locations/v1/cities/ipaddress?&apikey=7f64ed3093d8436e994f9dc7e382a06a
unknown
6724
chromium.exe
GET
200
142.250.186.174:80
http://clients2.google.com/time/1/current?cup2key=7:JeR7B5kSQyVMlTLb31OMxIMwcUnZgM72JeQmPwuDwuE&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
6724
chromium.exe
GET
200
142.250.186.174:80
http://clients2.google.com/time/1/current?cup2key=7:_4JEBiL8uoJ-8mR1VsFEahKkyU7ZVS9YeJc1z00Da3o&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4364
svchost.exe
239.255.255.250:1900
unknown
6404
fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp
104.26.12.224:443
update.onelaunch.com
CLOUDFLARENET
US
unknown
5632
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
636
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5140
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6404
fbb5302b06f7e6824ecdaf59162f3a08557cac0efe6b40b4502eab60ecd04d82.tmp
52.88.99.215:443
api.keen.io
AMAZON-02
US
unknown
5632
svchost.exe
104.103.72.96:80
crl.microsoft.com
Akamai International B.V.
AT
unknown
5632
svchost.exe
23.37.9.217:80
www.microsoft.com
AKAMAI-AS
PH
unknown
1412
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
update.onelaunch.com
  • 104.26.12.224
  • 172.67.68.170
  • 104.26.13.224
unknown
api.keen.io
  • 52.88.99.215
  • 34.210.169.102
  • 54.148.82.190
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
unknown
crl.microsoft.com
  • 104.103.72.96
  • 2.23.154.57
unknown
release-cdn.onelaunch.com
  • 104.26.12.224
  • 172.67.68.170
  • 104.26.13.224
unknown
www.microsoft.com
  • 23.37.9.217
unknown
login.live.com
  • 20.190.159.4
  • 20.190.159.2
  • 20.190.159.68
  • 40.126.31.73
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.64
  • 20.190.159.73
unknown
go.microsoft.com
  • 23.61.142.72
unknown
client.wns.windows.com
  • 40.115.3.253
unknown
arc.msn.com
  • 20.223.35.26
unknown

Threats

No threats detected
Process
Message
chromium.exe
[0530/013342.316:ERROR:crash_report_database_win.cc(613)] CreateDirectory C:\Users\admin\AppData\Local\OneLaunch\User Data\Crashpad: The system cannot find the path specified. (0x3)
OneLaunch.exe
2024-05-30 01:33:43,332 DEBUG [ 1] (Com.WebBar.App: 0) - Previous Version (Major.Minor)= Current Version = 5.31.4.0
OneLaunch.exe
2024-05-30 01:33:43,770 DEBUG [ 1] (Com.WebBar.Popups.PopupScheduler+PopupSchedule: 0) - scheduled popup slot app_wizard with ViewModel type AppWizardPopupViewModel to be shown at 05/30/2024 02:03:43 +00:00
onelaunchtray.exe
log4net:ERROR Appender named [Analytics] not found.
onelaunchtray.exe
log4net:ERROR XmlHierarchyConfigurator: No appender named [Analytics] could be found.
onelaunchtray.exe
Rebase.OneLaunch.Tray.TrayApp: 2024-05-30 01:33:44,410 [1] INFO - starting up
OneLaunch.exe
2024-05-30 01:33:45,315 DEBUG [ 1] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
OneLaunch.exe
2024-05-30 01:33:46,609 DEBUG [ 6] (Com.WebBar.Dock.DisplayUtilities: 0) - update size and location
OneLaunch.exe
2024-05-30 01:33:46,642 DEBUG [ 6] (Com.WebBar.Util.UserActivityDetector: 0) - first run or minimum interval expired
OneLaunch.exe
2024-05-30 01:33:46,643 DEBUG [ 6] (Com.WebBar.Util.UserActivityDetector: 0) - idle for 0:00:01.86