faucet bot.exe

UniBot stand-alone application - by MikiSoft

MikiSoft

This is a setup program which is used to install the application. The file has been seen being downloaded from www57.zippyshare.com.
Publisher:
MikiSoft

Product:
UniBot stand-alone application - by MikiSoft

Version:
1.00

MD5:
94313bed61c4a7b2ba6894a3bcf2997f

SHA-1:
073c287e351ffd19718d18146a006e7689b42598

SHA-256:
5abaae5e78c43b04bc3c14eac29bfacfb5e8ffd74c7e0f03fa8f9a375184b22e

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 1:13:17 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
QVM41.1.Malware.Gen
1.0.0.1077

Zillya! Antivirus
Trojan.Agent.Win32.595796
2.0.0.2548

File size:
452 KB (462,848 bytes)

Product version:
1.00

Original file name:
prjUB.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\faucet bot.exe

File PE Metadata
Compilation timestamp:
10/7/2015 2:19:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:dAFWaHyts2cXYNfHAqRSktGsl9KCvRG45yX:dAFWaHyts2FE

Entry address:
0x34F0

Entry point:
68, 7C, 3C, 40, 00, E8, EE, FF, FF, FF, 00, 00, 40, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 3B, 30, 82, 8E, F4, 04, 6D, 4D, 95, AF, 73, CC, 63, CB, FD, 21, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 70, 72, 6A, 55, 42, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 88, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 00, 00, 00, 00, D6, 74, AB, 44, 6F, 9E, 64, 47, 86, CE, 67, 76, 11, 54, 0B, E3, 01, 00, 00, 00, 98, 00, 00, 00, A8, 00, 00, 00, 01, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
336 KB (344,064 bytes)

The file faucet bot.exe has been seen being distributed by the following URL.

Scan faucet bot.exe - Powered by Reason Core Security