streambitcoin bot.exe

UniBot stand-alone application - by MikiSoft

MikiSoft

This is a setup program which is used to install the application. The file has been seen being downloaded from www42.zippyshare.com.
Publisher:
MikiSoft

Product:
UniBot stand-alone application - by MikiSoft

Version:
1.01

MD5:
b9748f7678ecf904797d00006035664b

SHA-1:
8ccf73ca57f0fe3cc564d5f6faf5ee38eeedb76d

SHA-256:
c00081d36ae2ba8d59e2e8fea4d83580c6e47069555bd778a96d9ba520dccdd2

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/15/2024 11:41:23 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.W.VBNA
2.1.4+

Comodo Security
TrojWare.Win32.VB.MU
24200

McAfee
W32/Autorun.worm.aaeh!heur
5600.6340

Zillya! Antivirus
Downloader.Iframe.Win32.36
2.0.0.2665

File size:
440 KB (450,560 bytes)

Product version:
1.01

Original file name:
prjUB.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\streambitcoin bot.exe

File PE Metadata
Compilation timestamp:
1/7/2016 6:44:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:zSfzJps28YWmg5O2zx8hQwjOKZmN1VxQZTJu2LuOhOumkFQ3qSfLiTbGqo3iJtFD:wV0aCxE7MTF3pTEcbk5d1xAyMHCwW

Entry address:
0x4244

Entry point:
68, A0, 4A, 40, 00, E8, EE, FF, FF, FF, 00, 00, 40, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 56, 16, 26, CC, F0, 44, 9A, 4F, 9B, 8C, 10, 27, 1D, 62, 21, 14, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 20, 3E, 20, 49, 6E, 53, 70, 72, 6A, 55, 42, 00, 73, 28, 00, 29, 2C, 20, 22, 5C, 22, 29, 00, 00, 00, 00, 88, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 00, 00, 00, 00, F0, AC, 24, B7, D3, 8F, 09, 4C, 87, C7, D7, A0, D9, 93, D9, FC, 01, 00, 00, 00, 98, 00, 00, 00, A8, 00, 00, 00, 01, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
396 KB (405,504 bytes)

The file streambitcoin bot.exe has been seen being distributed by the following URL.

Scan streambitcoin bot.exe - Powered by Reason Core Security