SHService.exe

SHService

FOX INFORMATION TECHNOLOGY (TIANJIN) LIMITED

It runs as a windows Service named “SHService”.
Publisher:

Product:
SHService

Version:
1.0.0.1

MD5:
888b26c57f5f1608ea4ce749b1eb5a11

SHA-1:
836d15c17b8cc80468a9b86599d9d3083ed9d6ee

SHA-256:
1f088a7fc5bed2cf2fe97747bd25f4c5dec7c70713051e45d2c515d21874d48a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:26:01 PM UTC  (today)

File size:
158.1 KB (161,904 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2016

Original file name:
SHService.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\pushapp\shservice.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/31/2014 8:00:00 AM

Valid to:
12/31/2017 7:59:59 AM

Subject:
CN=FOX INFORMATION TECHNOLOGY (TIANJIN) LIMITED, OU=Product Technology Center, O=FOX INFORMATION TECHNOLOGY (TIANJIN) LIMITED, L=TIANJIN, S=TIANJIN, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7DE0E1DC4BA0CD6A79AB70BEB93FD937

File PE Metadata
Compilation timestamp:
3/15/2017 3:26:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x92EF

Entry point:
E8, FC, 5F, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, B0, 3C, 42, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 4C, 22, 42, 00, 33, C5, 89, 45, FC, 83, A5, D8, FC, FF, FF, 00, 53, 6A, 4C, 8D, 85, DC, FC, FF, FF, 6A, 00, 50, E8, BB, FB, FF, FF, 8D, 85, D8, FC, FF, FF, 89, 85, 28, FD, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, 2C, FD, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89...
 
[+]

Entropy:
6.4712

Code size:
96 KB (98,304 bytes)

Service
Display name:
SHService

Type:
Win32OwnProcess, InteractiveProcess

Depends on:
RPCSS


Scan SHService.exe - Powered by Reason Core Security