Sample details: 00eff06b0b6791dc22c4a3a5bb4054fe --

Hashes
MD5: 00eff06b0b6791dc22c4a3a5bb4054fe
SHA1: f8394391ae9cecbdcee14099fe6bd78d1eee93b2
SHA256: 6bd3c470a8ab0465e966734209933e42b80a064824265e674fb28b0c2d7253e0
SSDEEP: 6144:TwyMmniQtRkLOsXin5YZtNK9PEnv3ksupARYJWxwRxkw4VdxVcKDtQz5W8kC1L8n:shciQtiPS5YZtyc3qpAGCrcVkW4JgL5u
Details
File Type: MS-DOS
Yara Hits
YRP/MPRESS_V200_V20X_MATCODE_Software_20090423 | YRP/yodas_Protector_v1033_dllocx_Ashkbiz_Danehkar_h | YRP/mpress_2_xx_x86 | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/IsPacked | YRP/HasModified_DOS_Message | YRP/maldoc_getEIP_method_1 | YRP/domain | YRP/IP | YRP/contentis_base64 | YRP/win_registry | YRP/suspicious_packer_section |
Source
http://elizvanroos.info/ug/ucg.exe
Strings
		!Win32 .EXE.
.MPRESS1
.MPRESS2
*.gj)Fk
e-@ogJf
9X4,=Ih
4<*i[0
;&J&g].w
,=8`Ui
\Yzt_(
V<ni6-
RLd^OL
3@x,_T~_
j!Zhr/
>!oJ]B
;;CT'c}
w(ErBV
QAY^SaQ
dqE:j 
:{gX:#BDM
B184e<
/gw&	EK
&]oFtb
4[H:k=c
vqcscdP
TAWu^#Z
@`	O9C
%[KbQey
\n\zSK
$4^|BS
v{zcWTe
!E<.43$
GS1$q{Kg
\;<Uu_z?\
+x7#34
ytu{rx
Y&&:JX
Vcqk=2
a!-xxBB
Z@SI/F
&RuyS8
KW8UBI
wwZJ-F
Iv".GY~
&!-6k6-
V:Ph=Ar
Ks<JL,p
/|bJgH
j=T?5R
=>@>xY
!jw/G5DLg
.PN*Dv-a/
*C#qtuy
e*/>{;X
"}^GQp
ux+}dU
Y[:~o{
`-ZE*k
X<({-`
E>NVnz
),Qf[\
KnuLxJ
#{G^sp
ht?=~iM
pa+_S84=
a$0}1m
c,629`
$V4fDK=
.^DLGF>t7
dKSu'J
EOjss#
IfEVwA&
`x[`'|>
1lJeEt
=HzV.G
R(7&}[
af[Tm&
aM#k.	L;Hi
goMe<e
#zQLK?jt&
~hA?2-_C
6w7~WSZ
 bXwZ}y
b,ZUo,
R8F/*8Hx
rmiWt$
#,R/9@
rLmcILa,o
J+cP[l
piY\5OSu
adqWCq0
7|ko%\
uMA4@6Y
MXMPhwe&
h?Xw\[LcPM
1>_[{p
-^hXWT_%72
vmQ/"`
hA@*7&Q]cb
<U.qJm
dXM`rn$td`
$(:@+s
;MY9to
=B_j[9|
Ikt\0.
m)byG`hlRa
z.N%TW
ta!C%C
d-.^'c
B;mSG2dm-
K;GPxJ
x ,7rd5)
v<S]W2
@Y|Q89
|X~".m
TSj>^F
B:vODv
.JFB^0
K[Ej6X
OIJ5hp\[X
w>;<bXvr
:)"0+s
.58ZMv
o_9Z_@s$u
mqbM-5
zrP+Jbf
L@Vc@z
@:4ij.X
?5}Y$V
ge74@M8
l*ERT'
L-lwU(
x<nc4Z
|)k[Z;B+
#z'#'<
%gDC`P
a"$Ze;
;|n^2%
xhq[=oH
}NcMZ(
46``U 
N6sJqD
ky|G= 
WELPXp1
w;PR*J
i;Tt.1
O$x>%U
p~-4>#
mUUS[l"
Tu$$cT,|u
irXq4pZ
~{xS-W
]^\s>j|i
m49PMF
v1&uxB~49
u 3'\n"g
Y1-@Mh
Wi,[H/
TatGZC
4+n v3!
ViBo]e
xf7nAA
Trn`F_
o~o]w*M
mm:JR)
^^Z|P=
Tw8TJO
aPfR\5
yl8'c-
|f<jmK
B=+^DQ
/	ine 
?q>3f]
x];&9E
b,>2i#
 s6ZLq
y=lt5,b
T["?ro
VOB:0@
HDd6+?j;
8i:D5V
zc/VC`
4Ycajb
soO*C_
*zV&g+
Z$Vq2O
oNet7F
SN1MJe
]_]Mp-
G2,Hi|
jV77qifn
W*B@i)
'70h"_Hh
fXiLsx
Xz@i)S
73+jE(
Z"N3r^
.B`*c8
nxcNWw
tMIe#m%
Re1/qD;
bJf>G3.
txjtnRKt
Ma1Wp{
@>~s;"
{yP=}Y
iX!6_hg
n%QoNd#
dW6&Dt}X
|)i81.
ke#@NY
{z!D ^
Tr.>1P
'F)ayU
K&.^U;Z;3
^<gCVw
?h/X$g
ji,gc^RnG
~5B7|ex*%
yL*+@E
g,oeML
(t4.KsJ_
da0V<T F8j
Tq)MJdp
?e6+=}
ut65GU
.TXhh5C1
V8SOU)	rti
1h3G#H
~IQv^7?]S
t0HHm3
hhj*f(AW
0)h9wu
v`:L~)7]$6"1v
D<8.Du~
w7c?YpF
dz&Z4dOO"
`TdXA*
BCp\=go
F(He0Z
xl9\lJ}
2x D(O
z79RK\1Z~
"1gX?v
zV<J^y
Jl{N^IH
;_*TfO
@K)[s@
x@Oep]V
j)2T@@
'zynXh
S*>mx_
J38h}5`
pE49W!B
U4^D (2
h\d4B'
L"))5s}
ON\!A"*~T
q|5sFpX
2ys1D2
*^Vmk9
mk;:`W
Hv|5uJ
M2%.a4
9k2/W9L*
;[(x/I
ZyoO`:
m{32XOzg
PY+<>M
C'iiFV
3N8jcB
@%q1NX
~J@$YQ
@8oRy9D
^u_	r+
YPk CJ
F-0_vL'
"O0s!T
<\&#OJ{
Pfdb"z@
g	5J9v
b#bVkk
Wio^B _
YX<5g]j
o|f1*'
X'k	iFs
LBFHd6C
HC?.aC
(}qS81
g_>|1HO
L|Sz v
,iE1JT
`/|'j f
JJt!Ax3;
,}^Y6l
m@i"Ct
af*vIZ
n4IF@6f
v	[v,E 
4X"4"]
8y\Zba
zMfVH`
h.>l4@^["s
]JG$-LD
h+}Xcx
6&p1nzL
:'uFXN
J];,+[
V|i%[Rn
o)jEzk
5RmA"F
MHbLc{
HMlK%;
$1M^FH
sN&^nW
w*!Eo8
zzJ32u[
8k(]|@'#
Jr0ol++
i]c^EhU
	LFRNg~
0$qvEO
cbKHE*
yV3j	?
V mi:4eM3
')B=T)
tI)cv85X
|I#S|:g9
	krdR7&
5;%!3K
pPmmPu(]
rhM`[!<
nFAr%z
*1)QF?$l
zmsH`w
8(j<j99
9ONPiy<y
IvN2YU
~?d\tHF
F].k?iI
4XF6DB
oTs6`IB
wBQ	i|
tb!{7	(
t.u-DJ
`fU'	h6R
Jeg![(
wQ|-~Xh
wJEM)g,
9bzd.6
V/N/lbjf
cC?O/0
.v/l	g
.5%i-"
L|l gg*
:09lQ~
+z6z%#
/PdI(a
)V~Ivn
#mV-I:
J3E\ [d
~=QTg&
cfop=0
+v".zshM
mb|y}~
bmBl$'
W?DQYC
yuvWaS
+V?B{|
P,u?"D
s	/}ou
,&>mU:
9N]Ys;
2&nvI5
7$ a_g|56Q
Ql9P*M
OYl4;$
kD2)d^
(i]/OiL
e_Wc1V]
ThvBE\9
+!2xCV
sOr))j>
zw%j`]
a,|y7ycE
*n]jW}
6EyifRv{TRr~
T_%$ua
:*+gcg
.J&G#	
`XP()g
H%+>\	N
i`fpa4
b=:S|I
N[[Fti
:6=hwhX
1	;^'FXj
Z&o\o#D
|I)4gY
RU`L/6
Ttf\sk{
jy4l|j
Amo*jp
6P%~=tj
X5!9s8/*
]0?4W^
^tjhKx~
.7jZjZ
Nnp2X>A$
lB-u],j
y.m*	E
dm-%M2
Q.'EZ	J
Rc$Ds2?
g4vx`|W
ePinDY
&_xuz~
crvtbF
&km)h"9
6)y	z6
P><$dL
 :h-$\+R
[8sCfs
il;z+x
x(4<fDPeg	
QkM[}Q-
8Oj{xg{
j:|{zG).
1_))K:
(Cc/:%b
}CcP)6
]C'~<a
?^nSF"
hdFNi#
8d{IOt
33/(Ux
%UvS?/V6E=a
=)Otj>fS
8;K=w>
1D%"cu
>73Pyr{
>hL)n?
GNbd3[#,7{
Ryc@&Q
HeZa'f
MxjsB%
l]R<">.D
M$SPU:
_'f|\3
I-DRPes~Tg
R!<ISf'b
kP(}+,JM_`s`h
!]?-45
TC;I-n
L2FUH"
l>_Bw\D
<`R36[
Dz(;wn
]D86j@f
5A{|*_8p
_d")9;
Zw7v2;
c(_aGIB
EW)5^z
 (BKI-
|	-a(5
gR?LiN
F"2|y\1
%M= qQ<,^&
4._qm%P
6a.@=z
I k_8+
13<|\_
_vy?b@E
e=e`bf#ug
7j^k<ooW
VI| CU
Ap`zk0IN
-\J=Ys
w::xE{-
8Tiql,O#;
#HGdX9o
jD\!I1
p8Z}S=
TDl0fe
,mh@[z
F;*&EvT#
&0.)re
>\`Gt:$
!`yjWD
i}xe<CXo
JjeBg:
*$dlT(
NZ5p|tr
%L6A&:
 LE.K5X
DG2.vN^
|snI4Z
N<T3y+#{!
#X$2h`m
3O	svH
PHEmLk
s5SAa'
TfSn	W\
xN]	XoG
&y,{HO
x/]AeSkPY
%+_Upq
L?@V}7.@G
H5N)I:J}
C:I$Z1
XeP!NE
FJ!N!fe
D$TFp*
77=P]s
li hg6
Af[MV/
MOX$1@
xOfxD<b
6io;#Ew
,#<@7[i5
-	8G+:
"Go;@P
"11LU'89
e<k`0n
j|](qj;o,
MwZ	}a+
R44xn	
8z}%E:g
CR1pbs
SnRRht-
GnR;5%]
Gj"sDCC7W
M48~Fi
q||0e IW
[N\KMs
):>fYfA_
r#bDuk
K?c*<@O
?I8*/G1+
? IpT+
t?a9~)}
!OlS!-
!o2M3QT
(B7wfG
{9h!-}
R$ekku
Lr>L&B
+O(4:1z
L?C*f!
|ku"J-
|JErlR
g{"q?o
D;"qIf]f
IA/_YP
}%~#A>
&OvF(g
Vm>@"?l
wk\2w'?.
A<8(>/8]WI(Xs
YX@=`d
a~tO!Y
8jR]y[
qZA%9}
m>/!(L
OZ	c*?J
FX%uLe
yCi]MS
$GDWt@
P~3_0+*
~3U3{S
?n\{G^
us/_'.F$
R[L0#y
<*[~,4
j,j-WO
'Vb29/
O	Q|^a
,xJ=|i
Y:(O`^6
eXo4Ol
wa4o,=
g9GZG^
q=34ntn
4.y<C9
.KrNv{	
JE}wJW
#`dAv}
yGub=81!
`xp6&I
:DY##r
|R?^u}
?Vm-$9
S%(^~H
C_/`#2fk
Y!f:o8
!cW8B7_<J
C0[f#<
{'0	-#
?YW58"
`xyGYx
BI]VW[
Z#)]9c
5J&(nE
0sdwu/
;efhs{w
MAnSa-
?m@AU;
|_]a:W
91 B HB
=bDQQ:`S
!'8zEM
F7kO&}m
Z	,:=,
.BIcolHY+
rE%m9z
@7qZ,fQ
bx~N{Y
;%^.h^|
Ojs4eZ
2fA][b
WQ$W0Z
Z~`s	'
v:@x"j
~,QZev6
cBj0K{
cm2+(9
@Y8TB6
_kxB$!"
Vf8v\v
Xj>c58
\sjcHx
L'$`v-Wm
jU!<q0!z4
6XTh\HMN
@v',@i
Hz=ED`
hs7("p,(
>Ibg~TR
&l$m]Z
,}CZx4B[0
mJ_dk^
E@R9NY
y-Mtq'
qb+`1x
g};0u{
mLu~Z$
6aD\miy
.Z(=VU
on%eoUM|j~
)j_|+B
N}_,5_
Wo#?bb
)C0n9aTT+
jp'AF-
%KwHtZ
tj4Ns1B
S)&ztk
IQ+_%{
gFd48~/I7
RVbn)*
s--1+#9
^4#\`^r
~-_N1	b
T6LA_d
&pRdRa
uOm{9EZ;
\*/f=N
EYw-3F
9,w(snv
t|_H#;
WVl-12
G#3=tG
Tv,a;f
FNt )O
sDdS:F
I=2,&e
GetModuleHandleA
GetProcAddress
KERNEL32.DLL
oleaut32.dll
SysFreeString
advapi32.dll
RegCloseKey
user32.dll
CharNextA
msimg32.dll
GradientFill
gdi32.dll
SaveDC
version.dll
VerQueryValueA
comctl32.dll
ImageList_Add
shell32.dll
SHGetSpecialFolderPathA
comdlg32.dll
GetSaveFileNameA
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H+
s`)L$4
D$t+D$\
9l$\w`