File name:

Horizon Launcher V2.exe

Full analysis: https://app.any.run/tasks/129f36b9-da48-411b-a484-a8c3308a264f
Verdict: Malicious activity
Analysis date: November 03, 2023, 03:34:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

4EFF20EB9CFA69DEB33BD85153903A1B

SHA1:

78864E5D14C87D666FB4EDD1F8E07CBF2B7C4BEA

SHA256:

FE8D5C845D066061BC1FA638D7F40E99418F471375EE5DCFD73A047BB742C274

SSDEEP:

98304:bmg4QfHEGKDPH7bOs2oNstoDRE3/Fev44WIhndiFUtUyOQkxZXU3gnB6YFRyG6tD:yJBJww

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • Horizon Launcher V2.exe (PID: 3464)
    • Reads settings of System Certificates

      • Horizon Launcher V2.exe (PID: 3464)
  • INFO

    • Checks supported languages

      • Horizon Launcher V2.exe (PID: 3464)
    • Reads the computer name

      • Horizon Launcher V2.exe (PID: 3464)
    • Reads Environment values

      • Horizon Launcher V2.exe (PID: 3464)
    • Reads the machine GUID from the registry

      • Horizon Launcher V2.exe (PID: 3464)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2067:03:29 12:12:06+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 5795328
InitializedDataSize: 9728
UninitializedDataSize: -
EntryPoint: 0x588d6e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: https://fraud.lol/drug
CompanyName: https://fraud.lol/drug
FileDescription: Horizon Launcher V2
FileVersion: 1.0.0.0
InternalName: Horizon Launcher V2.exe
LegalCopyright: https://fraud.lol/drug
LegalTrademarks: https://fraud.lol/drug
OriginalFileName: Horizon Launcher V2.exe
ProductName: Horizon Launcher V2
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start horizon launcher v2.exe horizon launcher v2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3220"C:\Users\admin\AppData\Local\Temp\Horizon Launcher V2.exe" C:\Users\admin\AppData\Local\Temp\Horizon Launcher V2.exeexplorer.exe
User:
admin
Company:
https://fraud.lol/drug
Integrity Level:
MEDIUM
Description:
Horizon Launcher V2
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\horizon launcher v2.exe
c:\windows\system32\ntdll.dll
3464"C:\Users\admin\AppData\Local\Temp\Horizon Launcher V2.exe" C:\Users\admin\AppData\Local\Temp\Horizon Launcher V2.exe
explorer.exe
User:
admin
Company:
https://fraud.lol/drug
Integrity Level:
HIGH
Description:
Horizon Launcher V2
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\horizon launcher v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
3 089
Read events
3 077
Write events
12
Delete events
0

Modification events

(PID) Process:(3464) Horizon Launcher V2.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
3464
Horizon Launcher V2.exe
104.20.67.143:443
pastebin.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.20.67.143
  • 104.20.68.143
  • 172.67.34.170
shared

Threats

No threats detected
No debug info