Apocalypse.exe

Apocalypse

Evil Team Beast

The executable Apocalypse.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from fs06n3.sendspace.com and multiple other hosts.
Publisher:
Evil Team Beast

Product:
Apocalypse

Version:
1.2.0.0

MD5:
287fb91177c933d2f3181bd42ecdb4b4

SHA-1:
37041f1eaddc6022afffaf1b6519c605dea44fd9

SHA-256:
730051779650c10a3bc2903317848189c395627f6b47bd14dfeff34a09a7e6a1

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/26/2024 4:52:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.98678
392

Arcabit
Trojan.Strictor.D18176
1.0.0.637

Bitdefender
Gen:Variant.Strictor.98678
1.0.20.40

Emsisoft Anti-Malware
Gen:Variant.Strictor.98678
8.16.01.08.08

F-Secure
Gen:Variant.Strictor.98678
11.2016-08-01_6

G Data
Gen:Variant.Strictor.98678
16.1.25

McAfee
Artemis!287FB91177C9
5600.6526

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
46088

File size:
125.5 KB (128,512 bytes)

Product version:
1.2.0.0

Copyright:
Copyright © Microsoft 2015

Original file name:
Apocalypse.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\apocalypse.exe

File PE Metadata
Compilation timestamp:
7/15/2015 5:55:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:CPEsirwES/OaIf6GVqpBhDvvYT0CutgIG5:CHcw/IyRbhDnYT0CutgIe

Entry address:
0x76AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
22 KB (22,528 bytes)

The file Apocalypse.exe has been seen being distributed by the following 6 URLs.

https://fs06n3.sendspace.com/dl/7da8f62eb0eb86c4ca91ba35760e1bb3/58ac3b1a272e192a/.../Apocalypse.exe

https://fs06n2.sendspace.com/dl/5f0f5f0517f0a6f1350bdd36c6e7ea0c/584f40c1785fb5ad/.../Apocalypse.exe

https://fs06n5.sendspace.com/dl/320b350d33b3b279757745cc16df6956/580012bb431f9e43/.../Apocalypse.exe

https://fs06n5.sendspace.com/dl/1ca53dd8caf082deaa46dc30236297eb/577978e27e1cec54/.../Apocalypse.exe

Remove Apocalypse.exe - Powered by Reason Core Security