BS.exe

BLOOD STRIKE

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FreeRadioCast EPM Support’. The file has been seen being downloaded from www8.zippyshare.com and multiple other hosts.
Product:
BLOOD STRIKE

Version:
1.0.0.0

MD5:
0013bc68d1f90a040fc049b354d18410

SHA-1:
fd3e33d7a2ab48a9e122e886ac985426e6a96718

SHA-256:
6e79296342985608ed72fa0998b656d136412d8e4e341ec82f2903446a8ec9b6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 5:32:19 AM UTC  (today)

File size:
403 KB (412,672 bytes)

Product version:
1.0.0.0

Original file name:
BS.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bs.exe

File PE Metadata
Compilation timestamp:
3/22/2016 12:26:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:+nILc+d3zlxYJaMEECa499P16ShK97WJDclP16ShK97WJ:24/SSECaU6tP6t

Entry address:
0x4685E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
274.5 KB (281,088 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FreeRadioCast EPM Support

Command:
"C:\Program Files2\freera~1\bar\1.bin\eemedint.exe" t8epmsup.dll,s


The file BS.exe has been seen being distributed by the following 37 URLs.

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

http://www8.zippyshare.com/d/RG9Npwiv/.../BS.exe

Latest 30 of 37 download URLs

Scan BS.exe - Powered by Reason Core Security