15bit bot.exe

UniBot stand-alone application - by MikiSoft

MikiSoft

This is a setup program which is used to install the application. The file has been seen being downloaded from www43.zippyshare.com.
Publisher:
MikiSoft

Product:
UniBot stand-alone application - by MikiSoft

Version:
1.01

MD5:
cb30937bdcb78c6f7d8991520ccf2618

SHA-1:
b94a5b192d6a68674abda0329710160085727bf1

SHA-256:
cbaed0b18154f1ab997c9f34a2b9c67ee46f62d5e604fcabc4e26ab8edc68840

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 6:31:06 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.W.VBNA
2.1.4+

Comodo Security
TrojWare.Win32.VB.MU
24202

McAfee
W32/Autorun.worm.aaeh!heur
5600.6340

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

Zillya! Antivirus
Downloader.Iframe.Win32.36
2.0.0.2665

File size:
440 KB (450,560 bytes)

Product version:
1.01

Original file name:
prjUB.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\15bit bot.exe

File PE Metadata
Compilation timestamp:
1/7/2016 6:44:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:nSfzJps28YWmg5O2zx8hQwjOKZmN1VxQZTJu2LuOhOumkFQ3qSfLiTbGqo3iJtFK:cV0aCxE7MTF3pTEcbk5d1xAyMHCB0

Entry address:
0x4244

Entry point:
68, A0, 4A, 40, 00, E8, EE, FF, FF, FF, 00, 00, 40, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 56, 16, 26, CC, F0, 44, 9A, 4F, 9B, 8C, 10, 27, 1D, 62, 21, 14, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 20, 3E, 20, 49, 6E, 53, 70, 72, 6A, 55, 42, 00, 73, 28, 00, 29, 2C, 20, 22, 5C, 22, 29, 00, 00, 00, 00, 88, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 00, 00, 00, 00, F0, AC, 24, B7, D3, 8F, 09, 4C, 87, C7, D7, A0, D9, 93, D9, FC, 01, 00, 00, 00, 98, 00, 00, 00, A8, 00, 00, 00, 01, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
396 KB (405,504 bytes)

The file 15bit bot.exe has been seen being distributed by the following URL.

Scan 15bit bot.exe - Powered by Reason Core Security