blur.exe

MD5:
38a219c6774261bfe51ded0f07fb6b3c

SHA-1:
d2c0166df5ca9d5f8a86c9c8e311b3b5e23432d5

SHA-256:
6832d82378a6e857515d4294788dcfdae913d78e8cad5c5fe74fbbec17824594

Scanner detections:
8 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 9:05:24 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.Heur
2.1.4+

AVG
Win32/Heur
2015.0.3563

Bkav FE
W32.HfsAutoA
1.3.0.4923

IKARUS anti.virus
Virus.Win32.Heur
t3scan.2.2.29

K7 AntiVirus
Virus
13.175.11064

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14212

Sophos
Mal/Zbot-HX
4.97

VIPRE Antivirus
Trojan.Win32.Generic
26138

File size:
27.6 MB (28,898,304 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\activision\blur(tm)\blur.exe

File PE Metadata
Compilation timestamp:
10/23/2015 9:01:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:E/eSZCkpj69LbP136bItc6TV4jYA+Taq8pgxsBI9TiMR7607Djc8TPvq7/w:3SZCk2LbNf5VrGqpWIM4760Vrvq7

Entry address:
0x1BC9000

Entry point:
60, 9C, B8, 01, 00, 00, 00, 0F, A2, 83, E0, DF, BB, 00, A1, FC, 01, 8A, C8, 33, C0, 81, 2C, 18, 00, 91, FC, 01, D3, 04, 18, 83, C0, 04, 83, 3C, 18, 00, 75, ED, 64, A1, 18, 00, 00, 00, 8B, 40, 20, 35, 42, 9F, A1, 3E, A3, F8, DC, FC, 01, B8, 01, 00, 00, 00, 0F, A2, 83, E0, DF, 05, 1E, 27, 38, 00, A3, E8, DC, FC, 01, E9, 17, 00, 00, 00, 68, 00, 00, 00, 00, E8, A2, 6F, 03, FE, 83, C4, 08, A1, 00, 00, 00, 00, A3, 00, 00, 00, 00, 83, EC, 10, 64, A1, 18, 00, 00, 00, 8B, 40, 20, 35, D3, 3F, EA, 19, 50, E8, 08, 00...
 
[+]

Entropy:
6.6898

Code size:
10.3 MB (10,820,096 bytes)

The file blur.exe has been discovered within the following program.

Blur(TM)  by Activision
Blur is an arcade racing video game for Microsoft Windows published by Activision in North America and Europe. It features a racing style that incorporates real world cars and locales with arcade style handling and vehicular combat.
www.activision.com/atvihub/home.do
11% remove it
 
Powered by Should I Remove It?

The file blur.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to host-213.158.175.90.tedata.net  (213.158.175.90:80)

TCP (HTTP):
Connects to host-213.158.175.98.tedata.net  (213.158.175.98:80)

TCP (HTTP):
Connects to host-82-222-160-114.reverse.superonline.net  (82.222.160.114:80)

TCP (HTTP):
Connects to a84-53-132-240.deploy.akamaitechnologies.com  (84.53.132.240:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to a23-205-220-91.deploy.static.akamaitechnologies.com  (23.205.220.91:80)

TCP (HTTP):
Connects to a184-51-148-120.deploy.static.akamaitechnologies.com  (184.51.148.120:80)

TCP (HTTP):
Connects to a184-25-109-16.deploy.static.akamaitechnologies.com  (184.25.109.16:80)

TCP (HTTP):
Connects to a104-116-245-18.deploy.static.akamaitechnologies.com  (104.116.245.18:80)

TCP (HTTP):
Connects to a104-102-246-16.deploy.static.akamaitechnologies.com  (104.102.246.16:80)

TCP (HTTP):
Connects to 154.120.216.16.liquidtelecom.net  (154.120.216.16:80)

Scan blur.exe - Powered by Reason Core Security