b5tmini.exe

B5TPopup Module

Shanghai Zaihe Network Technology Co., Ltd

The application b5tmini.exe by Shanghai Zaihe Network Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:

Product:
B5TPopup Module

Version:
6.0.5.8

MD5:
35a68f9aa1918f8749ee40a6a5d066f8

SHA-1:
0f8e5a744f8a1d393b6a62ba6b490371a844ef0d

SHA-256:
968a6bb972e5600584ff5587a78671f8a8d4743422972404d4d88eb1df7e6948

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 2:30:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BM5Soft (M)
17.2.14.13

File size:
778.3 KB (796,992 bytes)

Product version:
6.0.5.8

Copyright:
Copyright (C) 2013 B5MSoft

Original file name:
B5TPopup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\b5tmini.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/24/2015 7:00:00 AM

Valid to:
7/24/2017 6:59:59 AM

Subject:
CN="Shanghai Zaihe Network Technology Co., Ltd", OU=IT, O="Shanghai Zaihe Network Technology Co., Ltd", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0DA317B1925F45E7006492C4A1917415

File PE Metadata
Compilation timestamp:
11/18/2015 5:39:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x4B2B1

Entry point:
E8, 96, B2, 00, 00, E9, 89, FE, FF, FF, E8, 92, 59, 00, 00, 8B, 48, 6C, 3B, 0D, F0, FD, 4A, 00, 74, 10, 8B, 0D, A8, FB, 4A, 00, 85, 48, 70, 75, 05, E8, 71, 82, 00, 00, A1, 30, F4, 4A, 00, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 56, 33, C0, 50, 50, 50, 50, 50, 50, 50, 50, 8B, 55, 0C, 8D, 49, 00, 8A, 02, 0A, C0, 74, 09, 83, C2, 01, 0F, AB, 04, 24, EB, F1, 8B, 75, 08, 83, C9, FF, 8D, 49, 00, 83, C1, 01, 8A, 06, 0A, C0, 74, 09, 83, C6, 01, 0F, A3, 04, 24, 73, EE, 8B, C1, 83...
 
[+]

Entropy:
6.6282

Code size:
461 KB (472,064 bytes)

Remove b5tmini.exe - Powered by Reason Core Security