locker blue (war commander) 15-06-26.exe

The executable locker blue (war commander) 15-06-26.exe has been detected as malware by 4 anti-virus scanners. The file has been seen being downloaded from download1013.mediafire.com and multiple other hosts.
MD5:
f5c4fe5aa52e6e739288009b56108799

SHA-1:
d99ade588955ae16d41024c95c040fc00b918447

SHA-256:
5e9e5222d2d880bbfc046c2bb22ef26a4ed9ae141770365f07e8b8a9dac57e06

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
12/26/2024 12:28:19 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
8.3.1.6

avast!
Win32:Malware-gen
2014.9-160204

AVG
Win32/DH
2017.0.2844

F-Prot
W32/Heuristic-KPP
v6.4.7.1.166

File size:
1.3 MB (1,396,102 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\locker blue (war commander) 15-06-26.exe

File PE Metadata
Compilation timestamp:
6/26/2015 1:59:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.23

CTPH (ssdeep):
24576:Q0Y8P9mZHZZVZYlakfON/8MIHnwmMvCYs3h3QvrnhB:Q0uHZZVZYlRfe/8MIHw

Entry address:
0x1570

Entry point:
83, EC, 1C, C7, 04, 24, 01, 00, 00, 00, FF, 15, 64, 93, 49, 00, E8, FB, FB, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, 83, EC, 1C, C7, 04, 24, 02, 00, 00, 00, FF, 15, 64, 93, 49, 00, E8, DB, FB, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, A1, A0, 93, 49, 00, FF, E0, 89, F6, 8D, BC, 27, 00, 00, 00, 00, A1, 90, 93, 49, 00, FF, E0, 90, 90, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, A0, 46, 00, E8, 0E, 71, 01, 00, BA, 60, 1D, 41, 00, 83, EC, 04, 85, C0, 74, 15, C7, 44...
 
[+]

Entropy:
5.8593

Code size:
390 KB (399,360 bytes)

The file locker blue (war commander) 15-06-26.exe has been seen being distributed by the following 3 URLs.

Remove locker blue (war commander) 15-06-26.exe - Powered by Reason Core Security