× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 64f5ef24378b978d8ac86e92535d45b40d6868708625bc73350c3f20e4cc03f1
File name: UCoin-qt.exe
Detection ratio: 1 / 56
Analysis date: 2016-04-06 20:17:12 UTC ( 1 year, 6 months ago )
Antivirus Result Update
Ikarus Trojan.BitCoinMiner 20160406
Ad-Aware 20160406
AegisLab 20160406
AhnLab-V3 20160406
Alibaba 20160406
ALYac 20160406
Antiy-AVL 20160406
Arcabit 20160406
Avast 20160406
AVG 20160406
Avira (no cloud) 20160406
AVware 20160406
Baidu 20160405
Baidu-International 20160406
BitDefender 20160406
Bkav 20160406
CAT-QuickHeal 20160406
ClamAV 20160405
CMC 20160404
Comodo 20160406
Cyren 20160406
DrWeb 20160406
Emsisoft 20160406
ESET-NOD32 20160406
F-Prot 20160406
F-Secure 20160406
Fortinet 20160404
GData 20160406
Jiangmin 20160406
K7AntiVirus 20160406
K7GW 20160404
Kaspersky 20160406
Kingsoft 20160406
Malwarebytes 20160406
McAfee 20160406
McAfee-GW-Edition 20160406
Microsoft 20160406
eScan 20160406
NANO-Antivirus 20160406
nProtect 20160406
Panda 20160406
Qihoo-360 20160406
Rising 20160406
Sophos AV 20160406
SUPERAntiSpyware 20160406
Symantec 20160331
Tencent 20160406
TheHacker 20160405
TrendMicro 20160406
TrendMicro-HouseCall 20160406
VBA32 20160406
VIPRE 20160406
ViRobot 20160406
Yandex 20160406
Zillya 20160405
Zoner 20160406
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
2009-2012 The Bitcoin developers, 2012-2013 The UCoin & PPCoin developers

Product UCoin-Qt
Original name UCoin-qt.exe
Internal name UCoin-qt
File version 1.0.0.0
Description UCoin-Qt (OSS GUI client for UCoin)
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2023-11-27 10:24:41
Entry Point 0x000014C0
Number of sections 9
PE sections
PE imports
RegCreateKeyExW
RegCloseKey
CopySid
RegQueryValueExA
OpenEventLogA
RegDeleteKeyW
RegQueryValueExW
SetSecurityDescriptorDacl
RegFlushKey
OpenProcessToken
DeregisterEventSource
RegOpenKeyExW
RegisterEventSourceA
RegOpenKeyExA
GetTokenInformation
CloseEventLog
RegQueryInfoKeyW
RegDeleteValueW
RegEnumKeyExW
GetLengthSid
ReadEventLogA
RegSetValueExW
FreeSid
RegEnumValueW
InitializeSecurityDescriptor
ReportEventA
GetSaveFileNameW
GetOpenFileNameW
SetGraphicsMode
GetCharABCWidthsW
GetCharABCWidthsFloatW
CreateFontIndirectW
SetBkMode
GetGlyphOutlineW
CreatePen
GetBkMode
SaveDC
SetTextAlign
GetPaletteEntries
EndPath
CombineRgn
GetTextMetricsW
GetBitmapBits
StretchBlt
GetDeviceCaps
CreateDCA
LineTo
OffsetRgn
DeleteDC
SetWorldTransform
RestoreDC
PolyBezierTo
SetPolyFillMode
EndDoc
PtInRegion
StartPage
GetRegionData
FillPath
CreateDCW
CreateDIBSection
RealizePalette
SetTextColor
GetObjectA
MoveToEx
ExtTextOutW
GetObjectW
CreateEllipticRgn
CreateBitmap
BitBlt
CreatePalette
EnumFontFamiliesExW
GetStockObject
SelectPalette
GetOutlineTextMetricsW
GetDIBits
GdiFlush
SelectClipRgn
CreateCompatibleDC
GetTextExtentPoint32W
StartDocW
StrokePath
EndPage
CreateRectRgn
CloseFigure
AbortDoc
GetNearestPaletteIndex
CreateSolidBrush
GetTextFaceW
ExtCreatePen
SelectObject
GetFontData
ResetDCW
BeginPath
DeleteObject
CreateCompatibleBitmap
SelectClipPath
ImmSetCompositionFontW
ImmSetCompositionWindow
ImmGetDefaultIMEWnd
ImmNotifyIME
ImmGetContext
ImmSetCandidateWindow
ImmReleaseContext
ImmGetCompositionStringW
ImmAssociateContext
GetStdHandle
GetDriveTypeW
ReleaseMutex
FileTimeToSystemTime
CreateFileMappingA
GetFileAttributesA
WaitForSingleObject
FindFirstFileW
GetHandleInformation
GetFileAttributesW
lstrcmpW
GetLocalTime
DeleteCriticalSection
GetCurrentProcess
MoveFileW
MapViewOfFileEx
UnhandledExceptionFilter
IsValidLanguageGroup
OpenFileMappingA
SetErrorMode
GetLogicalDrives
GetFileInformationByHandle
GetThreadContext
GetLocaleInfoW
GetFileTime
IsDBCSLeadByteEx
GetTempPathA
WideCharToMultiByte
GetTempPathW
GetTimeZoneInformation
GetSystemTimeAsFileTime
GetDiskFreeSpaceA
ResumeThread
SetEvent
LocalFree
FormatMessageW
GetThreadPriority
SetWaitableTimer
GetEnvironmentVariableA
OutputDebugStringW
FindClose
TlsGetValue
FormatMessageA
GetFullPathNameW
QueueUserWorkItem
OutputDebugStringA
VirtualQuery
SetLastError
GetUserDefaultUILanguage
GetSystemTime
DeviceIoControl
InitializeCriticalSection
CopyFileW
GetUserDefaultLangID
GetModuleFileNameW
TryEnterCriticalSection
ExitProcess
GetVersionExA
GetModuleFileNameA
FlushViewOfFile
QueueUserAPC
VerSetConditionMask
SetThreadPriority
CreateDirectoryExW
GetVolumeInformationW
LoadLibraryExW
MultiByteToWideChar
SystemTimeToTzSpecificLocalTime
SetFilePointerEx
SetProcessAffinityMask
FindNextChangeNotification
CreateMutexA
SetFilePointer
SetFileAttributesW
LockFileEx
CreateSemaphoreA
CreateThread
VirtualLock
MoveFileExW
GetSystemDirectoryW
CreateSemaphoreW
CreateMutexW
ExitThread
MoveFileExA
SetThreadContext
MoveFileA
GlobalMemoryStatus
FindCloseChangeNotification
SetUnhandledExceptionFilter
GetVersion
SetCurrentDirectoryW
GlobalAlloc
GetDiskFreeSpaceExW
SetEndOfFile
GetCurrentThreadId
SleepEx
CloseHandle
AreFileApisANSI
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
TerminateThread
LoadLibraryW
GetVersionExW
FreeLibrary
QueryPerformanceCounter
GetTickCount
TlsAlloc
VirtualProtect
FlushFileBuffers
LoadLibraryA
GlobalSize
GetStartupInfoA
UnlockFile
OpenProcess
CreateDirectoryA
DeleteFileA
GetDateFormatW
GetStartupInfoW
ReadProcessMemory
CreateDirectoryW
DeleteFileW
GetProcAddress
GetProcessHeap
CreateFileMappingW
GetProfileStringW
CompareStringW
SetCriticalSectionSpinCount
GetFileSizeEx
RemoveDirectoryW
ExpandEnvironmentStringsW
FindNextFileW
ResetEvent
CreateWaitableTimerA
FindNextFileA
IsValidLocale
DuplicateHandle
FindFirstFileExW
GetUserDefaultLCID
GetProcessAffinityMask
CreateEventW
CreateFileW
CreateEventA
GetFileType
TlsSetValue
CreateFileA
HeapAlloc
GetCurrencyFormatW
LeaveCriticalSection
GetLastError
SystemTimeToFileTime
CreateWaitableTimerW
VirtualAllocEx
GetSystemInfo
lstrlenA
GlobalFree
GetTimeFormatW
GetProcessTimes
GlobalUnlock
LockFile
RemoveDirectoryA
FindFirstChangeNotificationW
GetQueuedCompletionStatus
WaitForSingleObjectEx
SwitchToThread
GetCurrentDirectoryW
VirtualFreeEx
GetCurrentProcessId
CreateIoCompletionPort
SetFileTime
GetCommandLineW
GetCurrentThread
SuspendThread
QueryPerformanceFrequency
ReleaseSemaphore
MapViewOfFile
TlsFree
GetModuleHandleA
VirtualUnlock
ReadFile
PulseEvent
FindFirstFileA
VerifyVersionInfoW
GlobalLock
GetModuleHandleW
GetFileAttributesExW
GetLongPathNameW
UnmapViewOfFile
WriteFile
PostQueuedCompletionStatus
CreateProcessW
WaitForMultipleObjects
Sleep
TerminateProcess
OpenEventA
GetAcceptExSockaddrs
AcceptEx
VariantInit
SysAllocStringLen
Shell_NotifyIconW
ShellExecuteW
SHGetSpecialFolderPathA
SHGetFileInfoW
PathFileExistsW
PathRemoveFileSpecW
SetFocus
SetWindowRgn
SetWindowPos
EndPaint
ScrollWindowEx
WindowFromPoint
SetCaretBlinkTime
SetMenuItemInfoW
GetDC
DestroyCursor
GetCursorPos
ReleaseDC
GetMenu
TranslateMessage
UnregisterClassW
GetClassInfoW
ToAscii
SetCaretPos
CallNextHookEx
GetSysColor
LoadImageW
ClientToScreen
GetActiveWindow
InvalidateRgn
DestroyWindow
GetUserObjectInformationW
GetParent
UpdateWindow
CreateCaret
GetMessageW
ShowWindow
FlashWindowEx
ValidateRgn
PeekMessageW
SetWindowPlacement
GetClipboardFormatNameW
GetSystemMenu
SetParent
DestroyCaret
CreateCursor
CharNextExA
GetIconInfo
GetQueueStatus
RegisterClassW
IsZoomed
GetWindowPlacement
SetWindowLongW
GetKeyboardLayoutList
IsIconic
TrackPopupMenuEx
SetTimer
GetKeyboardLayout
GetSysColorBrush
CreateWindowExW
GetWindowLongW
GetUpdateRect
IsChild
MapWindowPoints
RegisterWindowMessageW
BeginPaint
DefWindowProcW
KillTimer
MapVirtualKeyW
ClipCursor
SetClipboardViewer
GetSystemMetrics
EnableMenuItem
GetWindowRect
SetCapture
ReleaseCapture
GetProcessWindowStation
DrawIconEx
SetWindowTextW
CreateIconIndirect
ScreenToClient
PostMessageW
GetKeyboardState
GetDesktopWindow
SetWindowsHookExW
LoadIconW
FindWindowExW
DispatchMessageW
SetForegroundWindow
GetAsyncKeyState
GetCaretBlinkTime
HideCaret
FindWindowW
MessageBeep
GetWindowThreadProcessId
MessageBoxW
SendMessageW
RegisterClassExW
UnhookWindowsHookEx
MoveWindow
MessageBoxA
ChangeClipboardChain
AdjustWindowRectEx
MsgWaitForMultipleObjectsEx
RegisterClipboardFormatW
GetKeyState
GetWindowRgn
GetDoubleClickTime
DestroyIcon
IsWindowVisible
SetDoubleClickTime
SetCursorPos
SystemParametersInfoW
InvalidateRect
GetClientRect
ToUnicode
GetFocus
SetCursor
PlaySoundW
DeviceCapabilitiesW
GetPrinterW
EnumFormsW
EnumPrintersW
ClosePrinter
OpenPrinterW
getaddrinfo
htonl
WSARecv
accept
ioctlsocket
WSAStartup
freeaddrinfo
WSASocketW
shutdown
WSAAddressToStringA
htons
getnameinfo
WSAGetLastError
gethostname
getsockopt
recv
send
ntohl
WSASend
ntohs
select
listen
__WSAFDIsSet
WSACleanup
WSASetLastError
WSAAsyncSelect
closesocket
setsockopt
socket
bind
connect
__lconv_init
wcsftime
fseek
fclose
_snwprintf
strtoul
fflush
isxdigit
_fmode
strtol
fputc
system
_wgetenv
fwrite
frexp
fputs
_fstat64
exit
isspace
_close
puts
iswctype
wcscoll
_exit
__dllonexit
_wfopen
_write
_clearfp
memcpy
strstr
ctime
memmove
localtime
signal
freopen
_initterm
strcmp
memchr
strncmp
fgetc
memset
strcat
_stricmp
_setmode
fgets
__pioinfo
strchr
asin
fopen
_beginthread
fgetpos
fsetpos
strftime
ftell
__initenv
_strlwr
sprintf
strrchr
_acmdln
ferror
gmtime
free
ungetc
_getdrive
__getmainargs
ungetwc
_stat
_lseeki64
_vsnprintf
putchar
_flushall
_read
wcsxfrm
strcpy
__mb_cur_max
islower
acos
isupper
_ftime
_iob
rand
_putenv
setlocale
realloc
_getcwd
strxfrm
__doserrno
_open_osfhandle
fwprintf
isprint
_setjmp3
toupper
printf
_commit
strncpy
_cexit
raise
isalnum
mktime
qsort
_tzset
_open
_onexit
wcslen
isalpha
_snprintf
putc
memcmp
__setusermatherr
log10
srand
_fdopen
getenv
atoi
vfprintf
atol
atof
strcoll
localeconv
strerror
wcscpy
_beginthreadex
strspn
_strnicmp
putwc
_tzname
malloc
sscanf
fread
_waccess
abort
fprintf
getwc
tan
ispunct
feof
_endthreadex
_amsg_exit
_control87
strlen
_lock
_get_osfhandle
towlower
_fileno
wcsrchr
longjmp
tolower
atan
_unlock
calloc
setbuf
_getch
towupper
iswprint
_errno
atan2
_filelengthi64
setvbuf
time
wcsstr
_wgetdcwd
getc
_wchmod
__set_app_type
OleUninitialize
CoUninitialize
CoInitialize
OleFlushClipboard
CoLockObjectExternal
ReleaseStgMedium
CoCreateGuid
RegisterDragDrop
CoCreateInstance
DoDragDrop
RevokeDragDrop
OleSetClipboard
CoGetMalloc
OleGetClipboard
OleIsCurrentClipboard
CoTaskMemFree
StringFromGUID2
OleInitialize
Number of PE resources by type
RT_ICON 6
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 8
PE resources
ExifTool file metadata
SubsystemVersion
4.0

InitializedDataSize
20602368

ImageVersion
1.0

ProductName
UCoin-Qt

FileVersionNumber
1.0.0.0

UninitializedDataSize
37888

LanguageCode
English (U.S.)

FileFlagsMask
0x0000

CharacterSet
Windows, Latin1

LinkerVersion
2.24

FileTypeExtension
exe

OriginalFileName
UCoin-qt.exe

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
1.0.0.0

LegalTrademarks1
Distributed under the MIT/X11 software license, see the accompanying file COPYING or http://www.opensource.org/licenses/mit-license.php.

TimeStamp
2023:11:27 11:24:41+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
UCoin-qt

ProductVersion
1.0.0.0

FileDescription
UCoin-Qt (OSS GUI client for UCoin)

OSVersion
4.0

FileOS
Windows NT 32-bit

LegalCopyright
2009-2012 The Bitcoin developers, 2012-2013 The UCoin & PPCoin developers

MachineType
Intel 386 or later, and compatibles

CompanyName
UCoin

CodeSize
13856768

FileSubtype
0

ProductVersionNumber
1.0.0.0

EntryPoint
0x14c0

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 122af502b802684fd022dcb1ea8b3d07
SHA1 150b1eabe68466514d16816aa7d763a769fbacc2
SHA256 64f5ef24378b978d8ac86e92535d45b40d6868708625bc73350c3f20e4cc03f1
ssdeep
393216:bMSSM41wR6G7pbAdlKolaOp36jWp9Cga83VVGdaivjaeBZ6fD0OzgYTlBRztL2DM:WWRPkKC36jo7gORB

authentihash f0daf18dd98a424e9a83ab7e73818a73736ed7e487f23e457c0d3a36491cc277
imphash 34cb9d90d49465dffeeb0d3d5892c296
File size 19.6 MB ( 20603392 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID InstallShield setup (46.2%)
Win32 EXE PECompact compressed (generic) (44.6%)
Win32 Executable (generic) (4.8%)
Generic Win/DOS Executable (2.1%)
DOS Executable Generic (2.1%)
Tags
peexe

VirusTotal metadata
First submission 2015-01-31 19:25:23 UTC ( 2 years, 8 months ago )
Last submission 2016-04-06 20:17:12 UTC ( 1 year, 6 months ago )
File names UCoin-qt
UCoin-qt.exe
UCoin-qt.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Moved files
Deleted files
Code injections in the following processes
Created mutexes
Opened mutexes
Searched windows
Opened service managers
Opened services
Hooking activity
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.
The file installs an application-defined hook procedure into a hook chain. You would install a hook procedure to monitor the system for certain types of events. These events are associated either with a specific thread or with all threads in the same desktop as the calling thread. This is done making use of the SetWindowsHook Windows API function.
HTTP requests
DNS requests
TCP connections