insaniquarium deluxe full by tranesebastian1.exe

The executable insaniquarium deluxe full by tranesebastian1.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from download1336.mediafire.com and multiple other hosts.
MD5:
c03c3f9ba5cc21c14b815305bc27eda1

SHA-1:
ad8faf8f6084998ec12149b7db252e63c479c9d8

SHA-256:
8112b59b15a4347f085604e48a24308da2a9b837fdf57dc29ad7b4b8af7cf621

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
12/26/2024 1:53:08 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader.Generic11
2015.0.3255

Comodo Security
UnclassifiedMalware
17608

Dr.Web
Trojan.DownLoader3.28856
9.0.1.0353

Fortinet FortiGate
W32/Malware_fam.NB
12/19/2014

IKARUS anti.virus
Trojan-Downloader.SuspectCRC
t3scan.2.2.29

McAfee
Artemis!C03C3F9BA5CC
5600.6911

NANO AntiVirus
Trojan.Win32.Murlo.jbtfi
0.28.0.57029

Norman
Troj_Generic.JHMZ
11.20141219

Quick Heal
(Suspicious) - DNAScan
12.14.12.00

Trend Micro House Call
TROJ_SPNR.29EE12
7.2.353

Trend Micro
TROJ_SPNR.29EE12
10.465.19

VIPRE Antivirus
Trojan.Win32.Generic
25418

File size:
14.6 MB (15,349,632 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\insaniquarium deluxe full by tranesebastian1.exe

File PE Metadata
Compilation timestamp:
3/15/2010 1:27:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:91LvitswMfWCv9wpkKXvXA3yjJ8Ejg22Os4vMY/y5:91LitwfDvMk022JpgfONMb5

Entry address:
0xA7B1

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, BE, 2B, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, D0, A7, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 1C, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 1C, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, AF, AC, FF, FF, C3, 55, 8B, EC, 83, EC, 1C, 56, 33, F6, 56, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 40, 22, 41, 00, 85, C0, 74, 21, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 44, 22, 41, 00, 8D, 45, E4...
 
[+]

Code size:
66 KB (67,584 bytes)

The file insaniquarium deluxe full by tranesebastian1.exe has been seen being distributed by the following 14 URLs.

http://download1336.mediafire.com/b6e5oasdz2tg/.../Insaniquarium BY DRUCK.ss.exe

http://download1336.mediafire.com/hgs7fhdbx7pg/.../Insaniquarium BY DRUCK.ss.exe

http://download1568.mediafire.com/dk7mt892dpxg/.../Insaniquarium BY DRUCK.ss.exe

http://download1568.mediafire.com/x8jhn4d9cjqg/.../Insaniquarium BY DRUCK.ss.exe

http://download1635.mediafire.com/mflx4s4yedbg/.../Insaniquarium BY DRUCK.ss.exe

http://download1847.mediafire.com/u0dtx964nckg/.../Insaniquarium BY DRUCK.ss.exe