fishlose.exe

Zhiming Yuan

The application fishlose.exe by Zhiming Yuan has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(FishloseP)”. While running, it connects to the Internet address 125.235.4.59.adsl.viettel.vn on port 80 using the HTTP protocol.
Publisher:
Zhiming Yuan  (signed and verified)

MD5:
2687979f45b244a69d1e6206a8b25177

SHA-1:
d4aa0f510211e70f881d35ab3222951d46d59735

SHA-256:
069d0fb904271c20a2f57f0a5d727d02073b0ed512dfc7c4161cda33bdcc93cc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 1:26:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex (M)
16.9.21.10

File size:
448.7 KB (459,512 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\fishlose\fishlose.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/21/2016 2:00:00 AM

Valid to:
6/14/2017 1:59:59 AM

Subject:
CN=Zhiming Yuan, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0C8088A269975EEFD69FC51652E874F6

File PE Metadata
Compilation timestamp:
9/21/2016 11:51:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:zY2/xKMwcvUZIh6Nlf9vBoM5LQzz6GJXX2QB:z6MRv94xokXCXGQB

Entry address:
0x2D556

Entry point:
E8, FA, 07, 00, 00, E9, 8E, FE, FF, FF, FF, 25, 60, 03, 45, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 90, 46, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 90, 46, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45...
 
[+]

Entropy:
6.4676

Code size:
315 KB (322,560 bytes)

Service
Display name:
Protect Service(FishloseP)

Service name:
FishloseP

Description:
To ensure your Fishlose software integrity. If this service is disabled or stopped, your Fishlose software will not be kept integrity check. This service uninstalls itself when there is no Fishlose so

Type:
Win32OwnProcess

Depends on:
RpcSs


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 125.235.4.59.adsl.viettel.vn  (125.235.4.59:80)

Remove fishlose.exe - Powered by Reason Core Security