strawpoll bot.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from s27.workupload.com and multiple other hosts.
Version:
4.0.0.0

MD5:
bb251e5530c58fff3ed77f23c3d94073

SHA-1:
f1aba00d9b1069029df3a895813f63b3f4fd0605

SHA-256:
d710379d3eb3378a2565e388a687419b4d8eb6d8cdb8e33080b50f011b66f948

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/16/2024 6:01:22 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Hacktool.MSIL.Ubot
4.0.3.1619

ESET NOD32
MSIL/Ubot.D potentially unsafe (variant)
10.12824

File size:
12.1 MB (12,664,926 bytes)

Product version:
4.0.0.0

Copyright:
Copyright © 2012

Original file name:
Bot.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\strawpoll bot.exe

File PE Metadata
Compilation timestamp:
6/6/2015 11:29:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
196608:ynrpX1CXm2paUmqBTVLaR0nDV0zlnt9P0ND3tlXgFTaZ0odTXW2Dj:4rpXXcaUbTVLamB0tI1tlXgF+TXh/

Entry address:
0x82B126

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8891

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8.2 MB (8,557,056 bytes)

The file strawpoll bot.exe has been seen being distributed by the following 3 URLs.

https://s27.workupload.com/.../rG61oqvp

https://s15.workupload.com/.../rG61oqvp

Scan strawpoll bot.exe - Powered by Reason Core Security