File name:

Pokemon.Infinite.Fusion.Launcher.Setup.exe

Full analysis: https://app.any.run/tasks/f60bcd85-bf58-471b-b1c6-249e12f187fd
Verdict: Malicious activity
Analysis date: December 15, 2023, 18:36:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

24C3E14334B616F65A6D1E4DD0472B96

SHA1:

DBE3A21A96CF424D3EFB5B28DE23D9912A0D1CDC

SHA256:

CFE01FC3013F844597ABB2DA01F16A1F854352E7C8F288B19057C51066A0FF1D

SSDEEP:

98304:r+cD4dny2W8oWG3hIP0PDmv3v9pGr0h3nFU3Gclvkm/Q+d2xf80bDefkj4p4/2vE:aTMKPp4FZ3q8W4ZHJU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Pokemon.Infinite.Fusion.Launcher.Setup.exe (PID: 1556)
      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
    • Actions looks like stealing of personal data

      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
    • Reads the Windows owner or organization settings

      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
  • INFO

    • Checks supported languages

      • Pokemon.Infinite.Fusion.Launcher.Setup.exe (PID: 1556)
      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
    • Reads the computer name

      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
    • Creates files or folders in the user directory

      • Pokemon.Infinite.Fusion.Launcher.Setup.tmp (PID: 2076)
    • Create files in a temporary directory

      • Pokemon.Infinite.Fusion.Launcher.Setup.exe (PID: 1556)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 243200
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Pokémon Infinite Fusion Team
FileDescription: Pokémon Infinite Fusion Launcher Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Pokémon Infinite Fusion Launcher
ProductVersion: 1.6.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pokemon.infinite.fusion.launcher.setup.exe no specs pokemon.infinite.fusion.launcher.setup.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1556"C:\Users\admin\AppData\Local\Temp\Pokemon.Infinite.Fusion.Launcher.Setup.exe" C:\Users\admin\AppData\Local\Temp\Pokemon.Infinite.Fusion.Launcher.Setup.exeexplorer.exe
User:
admin
Company:
Pokémon Infinite Fusion Team
Integrity Level:
MEDIUM
Description:
Pokémon Infinite Fusion Launcher Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\pokemon.infinite.fusion.launcher.setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2076"C:\Users\admin\AppData\Local\Temp\is-NB3GV.tmp\Pokemon.Infinite.Fusion.Launcher.Setup.tmp" /SL5="$1301E2,7967849,986112,C:\Users\admin\AppData\Local\Temp\Pokemon.Infinite.Fusion.Launcher.Setup.exe" C:\Users\admin\AppData\Local\Temp\is-NB3GV.tmp\Pokemon.Infinite.Fusion.Launcher.Setup.tmp
Pokemon.Infinite.Fusion.Launcher.Setup.exe
User:
admin
Company:
Pokémon Infinite Fusion Team
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nb3gv.tmp\pokemon.infinite.fusion.launcher.setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
854
Read events
848
Write events
0
Delete events
6

Modification events

(PID) Process:(2076) Pokemon.Infinite.Fusion.Launcher.Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
E6FDE091D4536C08A450231FD04489D15BB2C760703E10F4962C293206960EF6
(PID) Process:(2076) Pokemon.Infinite.Fusion.Launcher.Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\Pokémon Infinite Fusion Launcher.exe
(PID) Process:(2076) Pokemon.Infinite.Fusion.Launcher.Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2076) Pokemon.Infinite.Fusion.Launcher.Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
7C47924AEA8FD22573BA9488A05FC9D0332D68AEEE693E56ACC2BB86E1CC76E8
(PID) Process:(2076) Pokemon.Infinite.Fusion.Launcher.Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
1C0800003CE908AA852FDA01
(PID) Process:(2076) Pokemon.Infinite.Fusion.Launcher.Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
41
Suspicious files
12
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1556Pokemon.Infinite.Fusion.Launcher.Setup.exeC:\Users\admin\AppData\Local\Temp\is-NB3GV.tmp\Pokemon.Infinite.Fusion.Launcher.Setup.tmpexecutable
MD5:75B3B50616E7B9626E4202FD7EA7114E
SHA256:986F7F0CEF08B4D7656AE376A4D1E7ECD3F06DF557239640C43975034334A535
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\Pokémon Infinite Fusion Launcher.exeexecutable
MD5:9E293DF6321BCA9F14769781C6B05A7E
SHA256:563FF70584D48AA70AEE9990FA9C29AEAAD39A51449FBCB6576BF6599CE76220
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\unins000.exeexecutable
MD5:98A08EED6ADC77929984D165C76A2F44
SHA256:F1FC89201C69D569EB01D6EBED3876843701F5D3F0BA943300A8E92C071F8150
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\is-317QP.tmpexecutable
MD5:385DCD2FC1D609F60EB0F55255057DD4
SHA256:790499110F94E72033E524B16C025129994CA9813727170C6ACA9FBF24B6FB97
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\is-7M6BC.tmpbinary
MD5:E21C89AA3F88B480763D0D6CAFB49426
SHA256:CAA36723284DC425FF6F28959454133FE179A079B60C1887FF86317F77F27972
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\is-5KBPU.tmpexecutable
MD5:9E293DF6321BCA9F14769781C6B05A7E
SHA256:563FF70584D48AA70AEE9990FA9C29AEAAD39A51449FBCB6576BF6599CE76220
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\Discord.Net.Interactions.dllexecutable
MD5:385DCD2FC1D609F60EB0F55255057DD4
SHA256:790499110F94E72033E524B16C025129994CA9813727170C6ACA9FBF24B6FB97
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\is-H88QL.tmpexecutable
MD5:F04B2D88011462FEFA579CE1D1D14CAF
SHA256:E66A57D4539BD244E12BD410246D34E9611507FE0191EBE62CAD54585D9ECDA3
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\Discord.Net.Core.dllexecutable
MD5:21517C090E8C0B01014D6F8B0276BF93
SHA256:65E305F5A83DE657110D6042526BDDD7C8E1EF634854CDD5FF4D2DF024BD0655
2076Pokemon.Infinite.Fusion.Launcher.Setup.tmpC:\Users\admin\AppData\Roaming\InfiniteFusionLauncher\Discord.Net.Rest.dllexecutable
MD5:F04B2D88011462FEFA579CE1D1D14CAF
SHA256:E66A57D4539BD244E12BD410246D34E9611507FE0191EBE62CAD54585D9ECDA3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
23.211.8.250:80
armmf.adobe.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.211.8.250
whitelisted

Threats

No threats detected
No debug info