| File name: | Fishstrap.exe | 
| Full analysis: | https://app.any.run/tasks/5f6f80a1-4b90-4083-b93c-9d1c9f3ddfaf | 
| Verdict: | Malicious activity | 
| Analysis date: | December 20, 2024, 21:07:07 | 
| OS: | Windows 10 Professional (build: 19045, 64 bit) | 
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable | 
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections | 
| MD5: | E13A344F19BAAD756F9429BBF1A71978 | 
| SHA1: | 5BEAA188293018CE2B4FFDB56B9AE539845860AD | 
| SHA256: | B9076E8314DB07D38EA9D7F3AF51AA86C8F184EFB4395A2A6F6BBC383F9AD7F8 | 
| SSDEEP: | 98304:5PwZJknj40Pm0000x+p6Ke0RWNTR5wU4q1+FennnnnnnnnnnnnnnO1w5UMHoyyyi:BvNvNr | 
| .exe | | | Win32 Executable MS Visual C++ (generic) (46.3) | 
|---|---|---|
| .exe | | | Win64 Executable (generic) (41) | 
| .exe | | | Win32 Executable (generic) (6.6) | 
| .exe | | | Generic Win/DOS Executable (2.9) | 
| .exe | | | DOS Executable Generic (2.9) | 
| MachineType: | AMD AMD64 | 
|---|---|
| TimeStamp: | 2024:10:14 11:26:56+00:00 | 
| ImageFileCharacteristics: | Executable, Large address aware | 
| PEType: | PE32+ | 
| LinkerVersion: | 14.29 | 
| CodeSize: | 99840 | 
| InitializedDataSize: | 259584 | 
| UninitializedDataSize: | - | 
| EntryPoint: | 0x14050 | 
| OSVersion: | 6 | 
| ImageVersion: | - | 
| SubsystemVersion: | 6 | 
| Subsystem: | Windows GUI | 
| FileVersionNumber: | 2.8.1.5 | 
| ProductVersionNumber: | 2.8.1.5 | 
| FileFlagsMask: | 0x003f | 
| FileFlags: | (none) | 
| FileOS: | Win32 | 
| ObjectFileType: | Executable application | 
| FileSubtype: | - | 
| LanguageCode: | Neutral | 
| CharacterSet: | Unicode | 
| CompanyName: | Bloxstrap | 
| FileDescription: | Bloxstrap | 
| FileVersion: | 2.8.1.5 | 
| InternalName: | Bloxstrap.dll | 
| LegalCopyright: | |
| OriginalFileName: | Bloxstrap.dll | 
| ProductName: | Bloxstrap | 
| ProductVersion: | 2.8.1.5 | 
| AssemblyVersion: | 2.8.1.5 | 
| PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 732 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3600 --field-trial-handle=2304,i,10638724215519395932,15345441690292832375,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 3221226029 Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 936 | "C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=3600 --field-trial-handle=2304,i,10638724215519395932,15345441690292832375,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: PWA Identity Proxy Host Exit code: 0 Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 1356 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3772 --field-trial-handle=2460,i,14963087846047901961,3153674716058255133,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 1448 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2300 --field-trial-handle=2304,i,10638724215519395932,15345441690292832375,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 1520 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3376 --field-trial-handle=2304,i,10638724215519395932,15345441690292832375,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 1540 | C:\Windows\syswow64\MsiExec.exe -Embedding 4896EBA4995B0E6ED285BE5167FB2CA7 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
 | |||||||||||||||
| 1540 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2480 --field-trial-handle=2304,i,10638724215519395932,15345441690292832375,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 1688 | C:\Windows\syswow64\MsiExec.exe -Embedding 8AC65871925748DDE8851A12F9EB3CD3 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
 | |||||||||||||||
| 2324 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3588 --field-trial-handle=2460,i,14963087846047901961,3153674716058255133,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
 | |||||||||||||||
| 2452 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3824 --field-trial-handle=2304,i,10638724215519395932,15345441690292832375,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
| User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
 | |||||||||||||||
| (PID) Process: | (4824) Fishstrap.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content | 
| Operation: | write | Name: | CachePrefix | 
| Value: | |||
| (PID) Process: | (4824) Fishstrap.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies | 
| Operation: | write | Name: | CachePrefix | 
| Value: Cookie: | |||
| (PID) Process: | (4824) Fishstrap.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History | 
| Operation: | write | Name: | CachePrefix | 
| Value: Visited: | |||
| (PID) Process: | (3736) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon | 
| Operation: | write | Name: | failed_count | 
| Value: 0 | |||
| (PID) Process: | (3736) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon | 
| Operation: | write | Name: | state | 
| Value: 2 | |||
| (PID) Process: | (3736) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon | 
| Operation: | write | Name: | state | 
| Value: 1 | |||
| (PID) Process: | (4824) Fishstrap.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer | 
| Operation: | write | Name: | SlowContextMenuEntries | 
| Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (3736) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics | 
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly | 
| Value: 0 | |||
| (PID) Process: | (3736) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault | 
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 | 
| Value: FC81D85050882F00 | |||
| (PID) Process: | (3736) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault | 
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 | 
| Value: 7A20E35050882F00 | |||
| PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF137d32.TMP | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF137d32.TMP | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF137d32.TMP | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF137d32.TMP | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF137d32.TMP | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
| MD5:— | SHA256:— | |||
| 3736 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
| MD5:— | SHA256:— | |||
| PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation | 
|---|---|---|---|---|---|---|---|---|---|
| — | — | GET | 200 | 2.20.245.137:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown |  —  | — | whitelisted | 
| — | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown |  —  | — | whitelisted | 
| 5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown |  —  | — | whitelisted | 
| 1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown |  —  | — | whitelisted | 
| 7872 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown |  —  | — | whitelisted | 
| 7872 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown |  —  | — | whitelisted | 
| 6828 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown |  —  | — | whitelisted | 
| 3736 | msedge.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl | unknown |  —  | — | whitelisted | 
| 3700 | svchost.exe | HEAD | 200 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c269ced-c74b-4e70-9b58-6e7999b292c0?P1=1734859100&P2=404&P3=2&P4=ETSiVulB0HpAU4G8uG2UlVWzETwaaGuD7sxZNmHQfyI6LFoSnB2CifSSmwpkqHjsCZ4ZmJ%2fgNYBw9cBX5wv%2fTg%3d%3d | unknown |  —  | — | whitelisted | 
| 3736 | msedge.exe | GET | 200 | 2.20.245.137:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown |  —  | — | whitelisted | 
| PID | Process | IP | Domain | ASN | CN | Reputation | 
|---|---|---|---|---|---|---|
| 904 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted | 
| 4 | System | 192.168.100.255:138 | — | — | — | whitelisted | 
| 4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted | 
| — | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted | 
| — | — | 2.20.245.137:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted | 
| — | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown | 
| 3820 | msedge.exe | 184.30.22.2:443 | aka.ms | AKAMAI-AS | DE | whitelisted | 
| 3736 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted | 
| 3820 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted | 
| 3820 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted | 
| Domain | IP | Reputation | 
|---|---|---|
| settings-win.data.microsoft.com | 
 | whitelisted | 
| google.com | 
 | whitelisted | 
| crl.microsoft.com | 
 | whitelisted | 
| www.microsoft.com | 
 | whitelisted | 
| config.edge.skype.com | 
 | whitelisted | 
| aka.ms | 
 | whitelisted | 
| edge.microsoft.com | 
 | whitelisted | 
| business.bing.com | 
 | whitelisted | 
| edge-mobile-static.azureedge.net | 
 | whitelisted | 
| bzib.nelreports.net | 
 | whitelisted | 
| Process | Message | 
|---|---|
| Fishstrap.exe | You must install .NET to run this application.
App: C:\Users\admin\AppData\Local\Temp\Fishstrap.exe
Architecture: x64
App host version: 6.0.36
.NET location: Not found
Learn about runtime installation:
https://aka.ms/dotnet/app-launch-failed
Download the .NET runtime:
https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win10-x64&apphost_version=6.0.36 | 
| Fishstrap.exe | Profiler was prevented from loading notification profiler due to app settings.
  Process ID (decimal): 6672.  Message ID: [0x2509].
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | SystemAccentColorPrimary: #FF0071CA
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | SystemAccentColorSecondary: #FF006ABE
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | SystemAccentColor: #FF0078D7
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | SystemAccentColorTertiary: #FF0063B1
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | Text on accent is LIGHT
 | 
| Fishstrap.exe | Wpf.Ui.Theme: INFO | Wpf.Ui.Appearance.Theme tries to update theme to Light (Light): True
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | SystemAccentColorTertiary: #FF0063B1
 | 
| Fishstrap.exe | Wpf.Ui.Accent: INFO | SystemAccentColorPrimary: #FF0071CA
 |