cupblueupdate.exe

Cupblue

Shan Feng

The application cupblueupdate.exe by Shan Feng has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named CupblueUpdateTaskMachineCore triggered by a time event.
Publisher:
Shan Feng  (signed and verified)

Product:
Cupblue

Version:
1.0.0.1

MD5:
ae03bad3100c982d0c65a882823c5356

SHA-1:
cced637434acd9e2efad511ced2ef9e2ddac130b

SHA-256:
754aa65c65e9a7230efe324dc85a60258a4418c9c9236910a8e75326dcf0d09e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 3:55:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.ShanFeng (M)
16.7.9.0

File size:
560.9 KB (574,336 bytes)

Product version:
51.5.2704.63

Copyright:
Copyright (C) 2016 Cupblue Authors

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cupblue\update\cupblueupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/1/2016 7:00:00 AM

Valid to:
2/4/2017 6:59:59 AM

Subject:
CN=Shan Feng, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1BE68A2F1793C12BE67FDE60C6531903

File PE Metadata
Compilation timestamp:
6/7/2016 11:54:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:e6IbTMqgR3nyxbsrEG6TD5ZAsBE8owK3jZKDqsZd0nPV1o+SNH:KR43SsrMFisy/3lgn+DSNH

Entry address:
0x4AE3B

Entry point:
8A, 2C, 65, 00, 00, AB, E2, AA, 9F, AA, C2, 67, 82, B7, 26, 00, B6, 0F, 96, 30, E9, 58, 00, 00, 00, 00, 39, 0A, 62, 1C, 39, DF, 85, 08, 6C, B0, A1, 04, 04, AA, 08, 00, 00, 00, 00, D8, 79, 66, 6E, 7F, 04, 71, 31, 11, 34, 03, E9, 7D, B6, AA, C3, E8, 11, 1D, 00, 71, A7, 04, 9F, 20, C1, 85, 27, A8, 9F, AA, C2, BD, EF, 11, 94, 31, 9E, 00, 00, 00, 00, A7, FE, 12, 06, AB, 55, 00, 00, 00, 00, D9, 24, 71, 31, 69, 06, 70, 6C, 06, 6B, 15, EB, 7C, EB, BD, 9C, FE, 13, 1C, 00, 66, F8, 12, EB, 31, 90, AA, 48, BE, A5, 11...
 
[+]

Entropy:
7.0129

Code size:
433 KB (443,392 bytes)

Scheduled Task
Task name:
CupblueUpdateTaskMachineCore

Trigger:
Time


Remove cupblueupdate.exe - Powered by Reason Core Security