build_5_21_2016_id24243.exe

The executable build_5_21_2016_id24243.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from fs09n5.sendspace.com.
MD5:
f6482595051da0e32b5936747227d1ff

SHA-1:
1e17f69ee200c5665d23cc00aa05f77ae2f64550

SHA-256:
b0bdd517fa23cbb93e9abe5b9e2889fae4b6ef3b1559db779af2b9c44e90b089

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/26/2024 4:32:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.7.6.3

File size:
197.5 KB (202,240 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\build_5_21_2016_id24243.exe

File PE Metadata
Compilation timestamp:
11/15/2015 5:51:47 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:+eQnq5WJfPtcD49wk1anUN0vxbD2WREM0wQ6leeBu5kh2dw0L:+KkJfP9KUN0vxbT0e+

Entry address:
0x15C6

Entry point:
55, 8B, EC, 51, 51, 53, 33, DB, 56, 57, 89, 5D, FC, 89, 5D, F8, 33, C0, 38, 98, 26, 30, 40, 00, 75, 08, 40, 3D, 00, 01, 00, 00, 72, F0, 64, A1, 30, 00, 00, 00, 3B, C3, 74, 0A, 80, 78, 02, 01, 0F, 84, 94, 00, 00, 00, 68, 07, 80, 00, 00, FF, 15, 58, 20, 40, 00, 68, 2F, 10, 40, 00, FF, 15, 10, 20, 40, 00, 68, 04, 01, 00, 00, 68, 28, 31, 40, 00, 53, FF, 15, 20, 20, 40, 00, 64, A1, 30, 00, 00, 00, F7, D8, 1B, C0, F7, D8, A3, 30, 33, 40, 00, E8, C8, FA, FF, FF, E8, 2E, FB, FF, FF, 83, F8, 01, 75, 11, 6A, 01, 68...
 
[+]

Entropy:
7.9213

Developed / compiled with:
Microsoft Visual C++

Code size:
4 KB (4,096 bytes)

The file build_5_21_2016_id24243.exe has been seen being distributed by the following URL.

Remove build_5_21_2016_id24243.exe - Powered by Reason Core Security