lly_omiga-plus.exe

1871_tugs_omiga-plus

Xiaoqing Liu

The application lly_omiga-plus.exe by Xiaoqing Liu has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
JWTab  (signed by Xiaoqing Liu)

Product:
1871_tugs_omiga-plus

Description:
Tab Syn

Version:
6.3.7601.1275

MD5:
94ca2e1241ba3966ae7d7a555ee58a16

SHA-1:
4c31b5b360f48566330b8a43ed69a9637c94aa54

SHA-256:
aea70c46e9ac6787532b5e727c9edb6da18bafee4111699b0e616e564bae74d0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 10:35:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX (M)
16.11.12.22

File size:
283.9 KB (290,696 bytes)

Product version:
6.3.7601.1275

Copyright:
JWTab

Original file name:
Tab.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lly_omiga-plus.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
8/12/2014 9:00:00 PM

Valid to:
8/17/2015 9:00:00 AM

Subject:
CN=Xiaoqing Liu, O=Xiaoqing Liu, L=Zaozhuang, S=Shandong, C=CN

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
04EED95FE18B1B4413D68A12F53663C0

File PE Metadata
Compilation timestamp:
11/12/2014 11:51:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:8DnS1028HEugTB7v3JDALPpMlkt2l7dTzPJA+R:8XKR3YswuJTzW+R

Entry address:
0x11DB6

Entry point:
4C, F0, B2, DF, A0, 8A, DC, 6F, 80, 33, A1, B5, 1B, 99, 9B, 05, 34, AB, 1C, 26, E4, B3, BC, 00, 0D, 85, C3, 04, 2F, CB, 0B, AA, C8, F1, 74, 98, 09, DF, 76, 76, 2B, 73, DB, 8C, 66, 95, C3, 84, 7C, 66, CF, D1, 50, 38, 4C, F0, 32, 7B, 5E, BD, 6F, F6, 1C, 60, 42, B0, 5B, 9D, EF, 0E, 1E, 06, D2, D1, 43, A6, CC, 04, 0F, 03, E9, 78, AB, B1, 98, F0, BE, 81, 74, 60, F8, 60, 63, 73, 99, 9F, 90, 41, B3, CA, 61, 42, 3E, 53, E9, 68, 28, 1C, 26, 78, 99, 4A, AF, 86, 9A, 4A, DF, 9E, 6C, 26, B3, B1, 1D, CD, 2A, 87, 09, F9...
 
[+]

Code size:
167.5 KB (171,520 bytes)

Remove lly_omiga-plus.exe - Powered by Reason Core Security