docineupdate.exe

Docine

Sivi Technology Limited

The application docineupdate.exe by Sivi Technology Limited has been detected as a potentially unwanted program by 2 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named DocineUpdateTaskMachineCore triggered by a time event.
Publisher:
Sivi Technology Limited  (signed and verified)

Product:
Docine

Version:
1.0.0.1

MD5:
cedd180615686ae606ee0e8a6bfdb44f

SHA-1:
f860c3ebcdeeda7eb02378093d80ef9abee22ddd

SHA-256:
0eb3b3e2fe38b685040060b32354f4412d3c9a042f291881a858ac5d0e95f1eb

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 9:44:39 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/ELEX.IL potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.Elex.SiviTech (M)
16.7.14.15

File size:
565.9 KB (579,472 bytes)

Product version:
51.12.2704.63

Copyright:
Copyright (C) 2016 Docine Authors

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\docine\update\docineupdate.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/1/2016 5:50:00 AM

Valid to:
3/1/2017 9:56:03 AM

Subject:
CN=Sivi Technology Limited, O=Sivi Technology Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
4A9C4CFE4035D55C1ED0529A

File PE Metadata
Compilation timestamp:
6/14/2016 9:16:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:Mi0tAYTPE8sfR13GcOgxQoqQ5alp681wInryMOn7z5F:MjDsfjMgxQgd8WGWBn7z5F

Entry address:
0x4BC1E

Entry point:
8B, 94, 46, 00, 00, 98, E3, BF, BC, B8, B9, 54, 83, B2, 05, 00, CD, 3C, 97, 25, CA, 4A, 00, 00, 00, 00, 1A, 18, 19, 2F, 38, CA, A6, 1A, 17, 83, A0, 11, 27, B8, 73, 00, 00, 00, 00, CA, 02, 55, 6F, 6A, 27, 63, 4A, 22, 35, 16, CA, 6F, CD, 99, C2, FD, C2, 0F, 00, 42, A6, 11, BC, 32, BA, B6, 26, BD, BC, B8, B9, 8E, EE, 04, B7, 23, E5, 00, 00, 00, 00, B5, 85, 21, 07, BE, 76, 00, 00, 00, 00, CC, 07, 63, 4A, 5A, 07, 65, 4F, 14, 10, 26, EA, 69, C8, AF, E7, CD, E2, 09, 00, 74, 83, 21, EA, 24, B3, B8, 33, 8D, A4, 04...
 
[+]

Entropy:
6.9621

Code size:
437 KB (447,488 bytes)

Scheduled Task
Task name:
DocineUpdateTaskMachineCore

Trigger:
Time


Remove docineupdate.exe - Powered by Reason Core Security