skysagalauncher.exe

SkySaga Infinite Isles

Radiant Worlds Ltd.

This is a self-extracting archive and installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘{4167BE95-C102-47DD-9939-10A7FB91E2CB}’. The file has been seen being downloaded from skysaga.us9.list-manage.com and multiple other hosts.
Publisher:
Radiant Worlds  (signed by Radiant Worlds Ltd.)

Product:
SkySaga Infinite Isles

Description:
This installer database contains the logic and data required to install SkySaga Infinite Isles.

Version:
1.0.2650.0

MD5:
b7e475ec4e7802c748aaac41e9422581

SHA-1:
5532201d88308ad737ec5f9f2adafc9e8fbd0263

SHA-256:
359b3cf85db4efa11d5a7df0b7080a147a28b9d7f6c976b200b7a20b83bd131a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 3:49:14 AM UTC  (today)

File size:
9.6 MB (10,053,448 bytes)

Product version:
1.0.2650.0

Copyright:
Copyright (C) 2015 Radiant Worlds

Original file name:
SkySaga Infinite Isles Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/6/2014 9:18:18 PM

Valid to:
11/6/2015 1:06:29 PM

Subject:
CN=Radiant Worlds Ltd., O=Radiant Worlds Ltd., L=Warwick, S=Warwickshire, C=GB

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B91E0CF2E8DD4

File PE Metadata
Compilation timestamp:
10/7/2014 4:05:58 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:huQt5K66wwjJtHJVKFwyPZps/75suKdKMDpj+ifOkcwEeEbYeT+:75j0JtHJVKFdPZpsT5WKOpj+ifzcwNcA

Entry address:
0xC87EC

Entry point:
E8, 4A, CC, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, F0, 33, DB, 3B, F3, 75, 1E, E8, 5D, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, C5, D5, FF, FF, 83, C4, 14, 8B, C6, E9, C2, 00, 00, 00, 57, 39, 5D, 0C, 77, 1E, E8, 39, 4D, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, A1, D5, FF, FF, 83, C4, 14, 8B, C6, E9, 9D, 00, 00, 00, 33, C0, 39, 5D, 14, 66, 89, 06, 0F, 95, C0, 40, 39, 45, 0C, 77, 09, E8, 0A, 4D, 00, 00, 6A, 22, EB, CF, 8B, 45, 10, 83, C0, FE, 83, F8, 22, 77...
 
[+]

Entropy:
7.8872  (probably packed)

Code size:
1021.5 KB (1,046,016 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
{4167BE95-C102-47DD-9939-10A7FB91E2CB}

Command:
"C:\users\{user}\documents\skysaga\skysagalauncher.exe" \cmdloc "hkcu\software\radiant worlds aitemp\{4167be95-c102-47dd-9939-10a7fb91e2cb}"


The file skysagalauncher.exe has been seen being distributed by the following 2 URLs.

Scan skysagalauncher.exe - Powered by Reason Core Security