| File name: | FishTycoonSetup.exe |
| Full analysis: | https://app.any.run/tasks/1de4887d-6bfd-48c3-b751-c2cb07bce9a3 |
| Verdict: | Malicious activity |
| Analysis date: | February 16, 2024, 21:35:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 667A2513DB4A5DD63A8CA3722613A608 |
| SHA1: | 30C18408DF5D6D1B593D0166DBE5C522BBC50072 |
| SHA256: | 16273D010DF007D1816919AE88FFBD0A90B638CBE996501DAD5A9CED7A2916A4 |
| SSDEEP: | 98304:7jFQMPY9i34wJY3mwdeaPrrplc8W0MwSiQYYqGQum8R0G7pZGQlLm/XJ4bEm4Zy+:rqiHFZHgmnuGil |
| .exe | | | InstallShield setup (27.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (26.2) |
| .exe | | | Win32 Executable MS Visual C++ (generic) (19.6) |
| .exe | | | Win64 Executable (generic) (17.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2005:02:04 00:24:30+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 146432 |
| InitializedDataSize: | 49152 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1b5f5 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1072 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3692 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1232 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1192 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1380 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1516 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1596 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1488 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1652 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3580 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1696 | "C:\Program Files\Fish Tycoon\FishTycoon.exe" | C:\Program Files\Fish Tycoon\FishTycoon.exe | — | is-1AGRG.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1888 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://arcade.reflexive.com/redirect.aspx?rra&pid=A71433960877207350592369943 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | FishTycoon.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1936 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2324 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2120 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3844 --field-trial-handle=1308,i,15628616317034090419,3757088917485674933,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\Desktop\FishTycoonSetup.exe" | C:\Users\admin\Desktop\FishTycoonSetup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (2840) FishTycoonSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ReflexiveArcade\459 |
| Operation: | write | Name: | DownloadID |
Value: 1ED4380300000000 | |||
| (PID) Process: | (2840) FishTycoonSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ReflexiveArcade\459 |
| Operation: | write | Name: | ChannelID |
Value: 21555 | |||
| (PID) Process: | (2840) FishTycoonSetup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ReflexiveArcade\459 |
| Operation: | write | Name: | ChannelName |
Value: PCGamer2006May | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\FishTycoon |
| Operation: | write | Name: | ExePath |
Value: C:\Program Files\Fish Tycoon\FishTycoon.exe | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\FishTycoon |
| Operation: | write | Name: | SavePath |
Value: C:\Program Files\Fish Tycoon\ | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fish Tycoon_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.0.7 | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fish Tycoon_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\Fish Tycoon | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fish Tycoon_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Fish Tycoon\ | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fish Tycoon_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: Fish Tycoon | |||
| (PID) Process: | (3304) is-1AGRG.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fish Tycoon_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3932 | FishTycoonSetup3442.exe | C:\Users\admin\AppData\Local\Temp\is-G3COL.tmp\is-1AGRG.tmp | executable | |
MD5:667555FC8D80C030ED5DE256404DF5C5 | SHA256:74EF33E3B3298D8CA7166C2B07A490A74C5A9A26B08B9478A524096208D5600A | |||
| 3304 | is-1AGRG.tmp | C:\Program Files\Fish Tycoon\FishTycoon.exe | executable | |
MD5:D2FE41077D0BAC6D8F0B4D2E704E98C3 | SHA256:8A1E9D9C69963871170EEA6C8781C308EEA29369B77F1A0E53F52EC53E7CC7FB | |||
| 2840 | FishTycoonSetup.exe | C:\Users\admin\AppData\Local\Temp\FishTycoonSetup3442.exe | executable | |
MD5:24739028142C55354190CDC1C950E3B4 | SHA256:E34E0FF8DF903463295E7E14CB4AFE59B51B046A9CD9B4B0D1A9DAC101B61754 | |||
| 3304 | is-1AGRG.tmp | C:\Users\admin\AppData\Local\Temp\is-CSD7T.tmp\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 3304 | is-1AGRG.tmp | C:\Program Files\Fish Tycoon\is-NHOTN.tmp | executable | |
MD5:D2FE41077D0BAC6D8F0B4D2E704E98C3 | SHA256:8A1E9D9C69963871170EEA6C8781C308EEA29369B77F1A0E53F52EC53E7CC7FB | |||
| 3304 | is-1AGRG.tmp | C:\Program Files\Fish Tycoon\FishTycoon.RWG | executable | |
MD5:049B8E745762B706CF2F352100008FF4 | SHA256:E9240378DF9F5FE7979EB3FAE49B6DD7AABA74101F1E843E87A1EFDEE0F8E843 | |||
| 2840 | FishTycoonSetup.exe | C:\Program Files\ReflexiveArcade\Channels\21555\Channel.dat | compressed | |
MD5:53F7A71807AE470C4FA828D1FFC4ACF3 | SHA256:7824962D765855EBEFA1833B62B6074BEDBDCD5EA35C636D71B4D420C28AE789 | |||
| 3304 | is-1AGRG.tmp | C:\Program Files\Fish Tycoon\Readme.txt | text | |
MD5:A2C631EEB7CB42A718E38F7F525617FD | SHA256:AA3122564AAF814619ABB873D9A13517636E95C70801FA5FBF79C4A82F5B4268 | |||
| 3304 | is-1AGRG.tmp | C:\Program Files\Fish Tycoon\is-4GUR4.tmp | xm | |
MD5:0D912BCBF8F5251374FEAE29B4734531 | SHA256:50A4E6B502ED1205922B714A65DB7E83EFF68CE8F4267EAE5A753D86DE4CB2C9 | |||
| 3304 | is-1AGRG.tmp | C:\Program Files\Fish Tycoon\is-T56AM.tmp | text | |
MD5:A2C631EEB7CB42A718E38F7F525617FD | SHA256:AA3122564AAF814619ABB873D9A13517636E95C70801FA5FBF79C4A82F5B4268 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2888 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
1596 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1596 | msedge.exe | 184.72.55.36:80 | arcade.reflexive.com | AMAZON-02 | US | unknown |
1596 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1596 | msedge.exe | 104.126.37.136:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2888 | msedge.exe | 224.0.0.251:5353 | — | — | — | unknown |
1596 | msedge.exe | 2.19.198.56:443 | msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
arcade.reflexive.com |
| unknown |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
aefd.nelreports.net |
| whitelisted |
r.bing.com |
| whitelisted |
th.bing.com |
| whitelisted |
login.microsoftonline.com |
| whitelisted |
services.bingapis.com |
| unknown |