Shulan Hou

Publisher Information

Shulan Hou is a software publisher located in Dingzhou, Hebei in China*. The company is a primary distributor of unwanted software. Thre are 45 additional code signing certificates issued to this publisher.
Authority:
DigiCert Inc

Valid from:
12/24/2014 1:00:00 AM

Valid to:
1/6/2016 1:00:00 PM

Subject:
CN=Shulan Hou, O=Shulan Hou, L=Dingzhou, S=Hebei, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0f2577198bbf58ac5f13ac0b95180508

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Ma Lin.ShulanHou, PUP.Ma Lin.ShulanHou, PUP.Ma Lin.ShulanHou (M), PUP.ELEX.ShulanHou (M), PUP.ELEX.ShulanHo (M), PUP.ELEX (M)
100.00%

Bkav FE
W32.HfsAdware
60.87%

Agnitum Outpost
Riskware.Agent, PUA.Downloader
60.87%

Baidu Antivirus
Adware.Win32.ELEX, PUA.Win32.LiMo
60.87%

herdProtect (fuzzy)
a variant of 4cf8de9d25e0b7e8905dcc15d143994af8c8a64d, a variant of 772dce34c5d243721268e666d082016fed6cb13b, a variant of 757d4a8389c3216a31b644d52b7345eedde7c329
56.52%

Dr.Web
Adware.Mutabaha.306, Adware.Mutabaha.325, Adware.Mutabaha.361
47.83%

Malwarebytes
PUP.Optional.IStartSurf.A, PUP.Optional.IStartsurf.A, PUP.Optional.MyStartSearch.A
47.83%

NANO AntiVirus
Riskware.Win32.Mutabaha.dqesbj
47.83%

Zillya! Antivirus
Downloader.Adload.Win32.19234
47.83%

Sophos
PUA 'Elex' (of type Adware)
47.83%

1 / 68      (Adware)
smt_istartsurf.exe (3428_smt_istartsurf by HTabp.com)  (a74df74ea6ab0c1a0e2f104300dd615d)

1 / 68      (Adware)
smt_istartsurf.exe  (021972f85d3e4152f41d9af0ab369c18)

1 / 68      (Adware)
smt_oursurfing.exe (3428_smt_istartsurf by HTabp.com)  (22bc590d69acc22c85caf5a85b2d0268)

1 / 68      (Adware)
smt_oursurfing.exe  (4d1f9300a06fd067f5bf8998ee7bcf3b)

1 / 68      (Adware)
amt_omniboxes.exe (3455_amt_omniboxes by BaiSix)  (10ecbc5820c45b91b7bf8023fbe5d568)

1 / 68      (Adware)
adv_46.exe (3421_ima_istartsurf by HTabp.com)  (37897410826f278d3f2900b98554c1ac)

1 / 68      (Adware)
untde62.tmp.exe (3489_epom_omniboxes by BaiSix)  (e47b2b2fb71f6fc50d4dbc9f39b40a40)

1 / 68      (Adware)
untabba.tmp.exe (3492_epom3_omniboxes by BaiSix)  (c1477d27309dc73d5e6a122d727ef106)

1 / 68      (Adware)
lly1_istartsurf.exe (3486_tug1_istartsurf by BaiSix)  (5f1d25bc3c31b2323dcdcf044c89ca5f)

10 / 68    (Adware)
lly_istartsurf.exe (3460_tugs_istartsurf by BaiSix)  (30b18988ae3294de4633b49394a12bc3)

17 / 68    (Adware)
lly_mystartsearch.exe (3459_tugs_mystartsearch by BaiSix)  (64251d999b9d0389f052da01e4c5dd1a)

14 / 68    (Adware)
unt5f55.tmp.exe (3491_epom2_omniboxes by BaiSix)  (95c1de1cdca6987995e1e09d77bbdc7f)

14 / 68    (Adware)
unt5ea6.tmp.exe (3490_epom1_omniboxes by BaiSix)  (35e45f56a23c1142f603f46861114ba6)

16 / 68    (Adware)
lly_istartsurf.exe (3460_tugs_istartsurf by BaiSix)  (b579d6bd5c5f8ebc2a509ad9e8103f60)

15 / 68    (Adware)
lly_istartsurf.exe (3468_tugs_istartsurf by BaiSix)  (6bc8935faa7fc77516f3205625f3e0d8)

14 / 68    (Adware)
lly_mystartsearch.exe (3469_tugs_mystartsearch by BaiSix)  (5dbb67f3ba64ceba411fba80b691d3ed)

8 / 68      (Adware)
smt_oursurfing.exe (3584_smt_oursurfing by HTabp.com)  (38a1d65ad3f187be873f087983fcbe89)

17 / 68    (Adware)
cvs_mystartsearch.exe (3493_cvs_mystartsearch by BaiSix)  (1ccfb04a87a5d4a5b00c34c49c1e9e09)

12 / 68    (Adware)
adv_76.exe (3419_ima_mystartsearch by HTabp.com)  (b830170a533c0e3745bade092c16c2e6)

14 / 68    (Adware)
lly_mystartsearch.exe (3459_tugs_mystartsearch by BaiSix)  (8f143e0ef16104b912d0845507a52c64)

13 / 68    (Adware)
0plhblkxusg==2.exe (3585_2sq_oursurfing by BaiSix)  (1c6c3702c8f1c5eec9d799347ccc169b)

21 / 68    (Adware)
amt_oursurfing.exe (3583_amt_oursurfing by BaiSix)  (fd69c6eee04f0db722ca1091c6796169)

8 / 68      (Adware)
smt_istartsurf.exe (3428_smt_istartsurf by HTabp.com)  (5e242fda5059ff7746c404cdd3a15966)

Downloads URLs for files signed by Shulan Hou.

17 / 68    (Adware)

8 / 68      (Adware)
http://www.girlliuxiaowei.com/.../smt_istartsurf.exe  (5e242fda5059ff7746c404cdd3a15966)

10 / 68    (Adware)

1 / 68      (Adware)

14 / 68    (Adware)

13 / 68    (Adware)

14 / 68    (Adware)

15 / 68    (Adware)

16 / 68    (Adware)

The following websites host and distribute files published by Shulan Hou.

The certificates below are also signed by Shulan Hou.

18DB51E9C16B714FFCB04CB5C35983FA  (Oct 08, 2016 to Jun 14, 2017)

2A5B578B2DA9A441D2C1AECD265EEFBF  (Jul 25, 2016 to Jun 14, 2017)

77C4983B630ECB2C08FBC858271E3D45  (Jul 20, 2016 to Jun 14, 2017)

03254EAC08CFABB19414DAE3BD08D149  (Jul 18, 2016 to Jun 14, 2017)

2F1AD76761251F239B649AF9F2D2627C  (Aug 11, 2016 to Jun 14, 2017)

74702DFF5D4056B847D009A2265FB1B3  (Jul 28, 2016 to Jun 14, 2017)

21E3000980B30029C251639A0B0AF0FD  (Aug 25, 2016 to Jun 14, 2017)

3261BAE34D602AACC22105B22CB5F2E9  (Sep 12, 2016 to Jun 14, 2017)

58D977998990941725A12A8E95E680E8  (Aug 22, 2016 to Jun 14, 2017)

1B471CD0973DAEB038ECC7D56538602F  (Aug 04, 2016 to Jun 14, 2017)

10 of 45 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Shulan Hou by DigiCert Inc on December 24, 2014 with the serial number '0f2577198bbf58ac5f13ac0b95180508'.