walking-dead-1_2_3_4_5.exe

The executable walking-dead-1_2_3_4_5.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from fra-7m18-stor09.uploaded.net.
MD5:
3efd575db686ec51f3a3eb6f79adf595

SHA-1:
77244812d0d8fce4ebb8ffb476d52220cb221641

SHA-256:
cdd091a4b386963cfd0e6f9c24f4272270d9ce2be5fd872ab724dac5ab75a6b1

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
5/19/2024 6:59:10 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4591

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.06.20

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2192.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

VIPRE Antivirus
Threat.4721115
29708

File size:
3.3 MB (3,508,857 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\walking-dead-1_2_3_4_5.exe

File PE Metadata
Compilation timestamp:
12/1/2013 2:08:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:dEPjNmu0B+9A66Ixj7A0bGHzcU+cI+YikHGzu:YBmu0gy66Ixw0be+eY4zu

Entry address:
0x108AF

Entry point:
60, 69, D7, 07, 39, 61, BA, 84, D2, FF, CB, F6, C7, A6, 81, D8, 85, B1, 45, 24, 0F, AF, CF, BA, 71, D9, 2A, 24, EB, 02, 86, ED, 15, E1, B3, CF, 0C, 48, F6, C0, FC, F6, C0, FD, 25, 75, 8A, 65, 24, 49, E8, 00, 00, 00, 00, 8D, 35, 82, 1E, 34, 3F, FE, CF, 21, DE, 41, 35, 4E, EE, 00, 00, 8A, FA, 88, E2, 5A, 3B, FA, 78, 06, C7, C0, 2A, F8, 06, CE, 85, D2, F2, 0F, B6, D9, 1A, E0, 87, EB, 0F, AF, D9, 77, 0C, 8D, 0D, 3F, 5D, 86, FF, F2, 2D, 6C, B9, 25, 5B, 70, 02, 1C, 39, 45, FE, C9, 69, CE, 67, 26, 94, BD, 8B, D9...
 
[+]

Entropy:
7.9543  (probably packed)

Code size:
98 KB (100,352 bytes)

The file walking-dead-1_2_3_4_5.exe has been seen being distributed by the following URL.

Remove walking-dead-1_2_3_4_5.exe - Powered by Reason Core Security