SkySaga Infinite Isles Setup.exe

SkySaga Infinite Isles

Radiant Worlds Ltd.

This is a setup and installation application. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. The file has been seen being downloaded from skysaga.us9.list-manage2.com and multiple other hosts.
Publisher:
Radiant Worlds  (signed by Radiant Worlds Ltd.)

Product:
SkySaga Infinite Isles

Description:
This installer database contains the logic and data required to install SkySaga Infinite Isles.

Version:
1.0.3499.0

MD5:
293dd2b159bc156951a9f2599b3be6e6

SHA-1:
5590946ddfdfddf3ee6e6ff751f114eaa7844592

SHA-256:
23ea6741517c2124acd4f4a9ae5d018e30e51b45a78870be3b680f7c79657576

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/1/2024 12:20:35 AM UTC  (today)

File size:
10.1 MB (10,571,104 bytes)

Product version:
1.0.3499.0

Copyright:
Copyright (C) 2015 Radiant Worlds

Original file name:
SkySaga Infinite Isles Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\ProgramData\skysaga infinite isles\installer-updates\update #1\skysaga infinite isles setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/4/2015 1:05:38 AM

Valid to:
11/6/2016 5:06:29 AM

Subject:
CN=Radiant Worlds Ltd., O=Radiant Worlds Ltd., L=Warwick, S=Warwickshire, C=GB

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
67F0F30744C361E4

File PE Metadata
Compilation timestamp:
7/16/2015 2:46:01 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:ahGdRqkVbOIsdubS0y/TMryRZ4c37JgMrPcQXDtuoOF1LodgYeTq:qyRqMa50yLMGRuU7hrPcowF1LpFe

Entry address:
0xC967C

Entry point:
E8, 40, CC, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, F0, 33, DB, 3B, F3, 75, 1E, E8, 5D, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, C5, D5, FF, FF, 83, C4, 14, 8B, C6, E9, C2, 00, 00, 00, 57, 39, 5D, 0C, 77, 1E, E8, 39, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, A1, D5, FF, FF, 83, C4, 14, 8B, C6, E9, 9D, 00, 00, 00, 33, C0, 39, 5D, 14, 66, 89, 06, 0F, 95, C0, 40, 39, 45, 0C, 77, 09, E8, 0A, 4D, 00, 00, 6A, 22, EB, CF, 8B, 45, 10, 83, C0, FE, 83, F8, 22, 77...
 
[+]

Entropy:
7.8960  (probably packed)

Code size:
1 MB (1,051,136 bytes)

Scheduled Task
Task name:
{B785218D-ADEA-47FA-9281-CF4DA8092DE0}

Trigger:
Logon (Runs on logon)


The file SkySaga Infinite Isles Setup.exe has been seen being distributed by the following 28 URLs.

http://skysaga.us9.list-manage2.com/.../click?u=e3657ec6368c1a3d62a7de97f&id=4e3d028d55&e=9a0d1b72c1

http://skysaga.us9.list-manage1.com/.../click?u=e3657ec6368c1a3d62a7de97f&id=3a2c32c85a&e=c711a68745

http://skysaga.us9.list-manage.com/.../click?u=e3657ec6368c1a3d62a7de97f&id=4e3d028d55&e=42b12e3052

http://skysaga.us9.list-manage1.com/.../click?u=e3657ec6368c1a3d62a7de97f&id=999f3e6cc4&e=ced8700720

http://skysaga.us9.list-manage1.com/.../click?u=e3657ec6368c1a3d62a7de97f&id=999f3e6cc4&e=b98e8017a4

http://skysaga.us9.list-manage.com/.../click?u=e3657ec6368c1a3d62a7de97f&id=999f3e6cc4&e=16dd6b9373

Scan SkySaga Infinite Isles Setup.exe - Powered by Reason Core Security