docineupdate.exe

Docine

Sivi Technology Limited

The application docineupdate.exe by Sivi Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named DocineUpdateTaskMachineCore triggered by a time event.
Publisher:
Sivi Technology Limited  (signed and verified)

Product:
Docine

Version:
1.0.0.1

MD5:
cd38b0afef3aa9aa04dd731f42b0efad

SHA-1:
6114b8800343c205d253027336eeee1a96ef0412

SHA-256:
d8a833a95440b6b8736dbd50988152e27787e1cd96fc36da337ee1d32033e564

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 5:27:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.7.25.11

File size:
565.9 KB (579,472 bytes)

Product version:
51.12.2704.63

Copyright:
Copyright (C) 2016 Docine Authors

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\docine\update\docineupdate.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/1/2016 8:20:00 AM

Valid to:
3/1/2017 1:26:03 PM

Subject:
CN=Sivi Technology Limited, O=Sivi Technology Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
4A9C4CFE4035D55C1ED0529A

File PE Metadata
Compilation timestamp:
6/14/2016 11:46:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:6i0tAYTPE8sfR13GcOgxQoqQ5alp681wAnryMOn7z5F:6jDsfjMgxQgd8WuWBn7z5F

Entry address:
0x4BC1E

Entry point:
8B, 94, 46, 00, 00, 98, E3, BF, BC, B8, B9, 54, 83, B2, 05, 00, CD, 3C, 97, 25, CA, 4A, 00, 00, 00, 00, 1A, 18, 19, 2F, 38, CA, A6, 1A, 17, 83, A0, 11, 27, B8, 73, 00, 00, 00, 00, CA, 02, 55, 6F, 6A, 27, 63, 4A, 22, 35, 16, CA, 6F, CD, 99, C2, FD, C2, 0F, 00, 42, A6, 11, BC, 32, BA, B6, 26, BD, BC, B8, B9, 8E, EE, 04, B7, 23, E5, 00, 00, 00, 00, B5, 85, 21, 07, BE, 76, 00, 00, 00, 00, CC, 07, 63, 4A, 5A, 07, 65, 4F, 14, 10, 26, EA, 69, C8, AF, E7, CD, E2, 09, 00, 74, 83, 21, EA, 24, B3, B8, 33, 8D, A4, 04...
 
[+]

Entropy:
6.9621

Code size:
437 KB (447,488 bytes)

Scheduled Task
Task name:
DocineUpdateTaskMachineCore

Trigger:
Time


Remove docineupdate.exe - Powered by Reason Core Security