alucinados point blank.exe

Weapon Hack v2 Cracker Bad

This is a setup program which is used to install the application. The file has been seen being downloaded from fs04n3.sendspace.com and multiple other hosts.
Product:
Weapon Hack v2 Cracker Bad

Version:
1.0.0.0

MD5:
ef6503dfd99fcf9254f7ac5212e722b0

SHA-1:
3d13066fdf02df5a6e2f677fc5cdee1eecb812d9

SHA-256:
6f6715113ecd28d647311cb45e191b0e931073efe3c0beb5c75af574f853d8ca

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 3:59:46 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/ATRAPS.Gen
7.11.114.222

Comodo Security
UnclassifiedMalware
17307

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

Trend Micro House Call
TROJ_GEN.R0C1H0AHL13
7.2.8

File size:
101.5 KB (103,936 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
WeaponSpace.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\alucinados point blank.exe

File PE Metadata
Compilation timestamp:
7/23/2013 11:29:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:iwBgWezAILBX2Ar1/jK2sU/yeXhs1iaIxLLaZePDFv9Fvp:7ezdBX2Ar1/2AXsihUej

Entry address:
0x197AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, 0C, 44, 39, 71, 98, E1, 4C, C4, 79, 6A, CE, 92, 4A, 9D, B1, 62, 6B, 90, A5, 14, F3, 90, 3A, 38, E6, 8C, 9A, 90, 2A, F9, 53, 6C, E9, 2E, 6B, BF, 9C, 25, 58, B7, 5F, 07, 3E, F5, 6E...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
94 KB (96,256 bytes)

The file alucinados point blank.exe has been seen being distributed by the following 4 URLs.

Scan alucinados point blank.exe - Powered by Reason Core Security