BS.exe

BLOOD STRIKE

This is a setup program which is used to install the application. The file has been seen being downloaded from www8.zippyshare.com and multiple other hosts.
Product:
BLOOD STRIKE

Version:
1.0.0.0

MD5:
f3dfa9e12fd3a3b39699f40944ec0136

SHA-1:
f90dd02c67196297c2cbf01ef944dd4b1a7be230

SHA-256:
85c80d0b1204ce32ad2a216ec8bc0b7df0762c328a640c0102dd37571437a3b2

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/16/2024 2:50:53 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan.MSIL3
t3scan.2.0.9.0

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
490.5 KB (502,272 bytes)

Product version:
1.0.0.0

Original file name:
BS.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bs.exe

File PE Metadata
Compilation timestamp:
5/15/2016 12:26:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:wP16ShK97WJ3b/nqFuESkjnILc+d3zlxYJaMEECa49ZcXP16ShK97WJ:C6tSznqFh4/SSECa36t

Entry address:
0x5C7AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 62, EC, 37, 57, 00, 00, 00, 00, 02, 00, 00, 00, 5C, 00, 00, 00, 1C, E0, 05, 00, 1C, AC, 05, 00, 52, 53, 44, 53, DE, 3F, 65, 65, 96, 4A, A8, 4E, A7, 5C, 0F, FE, 7C, B2...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
362 KB (370,688 bytes)

The file BS.exe has been seen being distributed by the following 8 URLs.

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

https://fs09n5.sendspace.com/dl/5cab239cf24396de37c6c6a1e1136c55/579292a27bb68ca4/.../BS.exe

https://fs09n5.sendspace.com/dl/86d0c55639414559ab74e06fb7aa8564/574082ee5e98cce1/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

https://fs09n3.sendspace.com/dl/f37cbe45676bc66f3496d6f558ce7aaf/57953a4b13b064c9/.../BS.exe

https://fs09n1.sendspace.com/dl/186b63e9d776d9ef03015f645c15c44b/5748c2dd682364b4/.../BS.exe

temp:BS.exe

Scan BS.exe - Powered by Reason Core Security