Xi'an TingXue Network Technology co., Ltd.

Publisher Information

Xi'an TingXue Network Technology co., Ltd. is a software publisher located in Xi'an, Shaanxi in China*. Thre are 2 additional code signing certificates issued to this publisher.
Authority:
WoSign CA Limited

Valid from:
1/21/2016 2:41:37 PM

Valid to:
5/21/2016 2:41:37 PM

Subject:
CN="Xi'an TingXue Network Technology co., Ltd.", O="Xi'an TingXue Network Technology co., Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
5451a8e67dccd396c3bef61e2ef9a151

Status:
Inconclusive detections from multiple engines

Scan engine
Details
Detections

Dr.Web
infected with Trojan.Upload.107, Detection.Undefined
55.56%

AegisLab AV Signature
Troj.NSIS.StartPage
44.44%

IKARUS anti.virus
Trojan.SuspectCRC
33.33%

Bkav FE
W32.eHeur.Downloader, W32.ExecPriD.Trojan
22.22%

Panda Antivirus
Trj/Genetic.gen
11.11%

Baidu Antivirus
Win32.Trojan.YouXun
11.11%

ESET NOD32
Win32/RiskWare.YouXun (variant)
11.11%

Microsoft Security Essentials
SoftwareBundler:Win32/Xiazai
11.11%

0 / 68
processwork.dll  (823066c452c072fec651aa1bc9d43fff)

3 / 68      (inconclusive)
setup_2482x.exe  (0508b8e8831a1cf37974072dc74702ee)

0 / 68
update.exe  (18364ddf1a16a3603554ebbcb8801447)

0 / 68
Unrar.dll (RAR decompression library by Alexander Roshal)  (a248df003b447a296b84d5156f2dbbd0)

3 / 68      (Malware)
uninst.exe  (25848a14f3d4bcc99dbefc57f87f7ff6)

0 / 68
jxsjzs.exe  (d930e6c7adb519023d500f6b5c49c071)

0 / 68
jxsj.exe  (284ad30e9ccf25bd11501a6edbf959e0)

0 / 68
jxpc.exe  (8ddcae3f64fd1b1974ea73a109067d9a)

0 / 68
jxgamebox.exe  (6f2f9bb831e7cc6d0fa50bb9f211c48f)

0 / 68
glut32.dll  (499d07bc8b8927ccc0f37edbcd7d1b6f)

0 / 68
glut.dll  (2c810cccfbde3a89187154391cc5cb4e)

0 / 68
gamestart.exe  (cff8a40414856d180f52460668a1b9e1)

0 / 68
game_6182mnc.exe  (39e2f4f9a283b56871693dcfe464a6ed)

1 / 68      (inconclusive)
setup_6182mnc.exe  (11412c76d2fcacbba2ea4e774a9cd9b6)

0 / 68
dui.dll  (e11d30899e9cb90d85c6838d57b102ca)

3 / 68      (inconclusive)
setup_6124mny_2.exe  (0f40817fd17354250a482df1d5aadb11)

0 / 68
setup_6124cd.exe  (ad4dd519876a913c15ab8ff687d21073)

0 / 68
nsdialogs.dll  (6deda89daa3aaa2a61773ce4e114da0a)

0 / 68
system.dll  (a4a05ae017940431409480a96294f9af)

2 / 68
inetc.dll  (46f8d24c9549ddcd780b4309fa17390b)

2 / 68      (inconclusive)
processwork.dll  (6cbf06b48cbdc4557302f1bb27294f3a)

1 / 68
dui.dll  (085c8eb05589ed0f2efe11a49a553868)

0 / 68
ontop.dll  (1b3647f89d45a2a8577385746bf8fc9f)

1 / 68
uninst.exe  (64ea4ffbacd67c8827c6fc85bcaa68fc)

0 / 68
commlib.dll (CommLib.dll)  (1f51f69cded01ffb46d3d6735b2b3ed4)

0 / 68
jxgamebox.exe  (04793638608893b2144a6d6fc8634c94)

2 / 68      (inconclusive)
setup_6124c.exe  (cf121f4fd2582ed649101a7d1e72dfc8)

Downloads URLs for files signed by Xi'an TingXue Network Technology co., Ltd..

2 / 68      (inconclusive)

2 / 68      (inconclusive)

3 / 68      (inconclusive)
http://dl.fly086.com/d.php?id=2295  (setup_6124mny_2.exe)

1 / 68      (inconclusive)
http://dl.fly086.com/d.php?id=6182  (setup_6182mnc.exe)

1 / 68      (inconclusive)
http://lxdl.91nzh.com/.../Setup_1513mnc.exe  (11412c76d2fcacbba2ea4e774a9cd9b6)

3 / 68      (inconclusive)
http://dl.fly086.com/d.php?id=6182  (setup_6124mny_2.exe)

0 / 68

The following websites host and distribute files published by Xi'an TingXue Network Technology co., Ltd..

The certificates below are also signed by Xi'an TingXue Network Technology co., Ltd..

6190EFA7A2B8F0695104A04BBE7112B5  (Jan 21, 2016 to May 21, 2016)

335183F94C563B4721865B606129EFBA  (May 06, 2015 to May 06, 2016)

The following publishers (by Authenticode signature organization name) are related.

30 of 58 publishers

* Note, the details and description above are based on the code signing digital signature issued to Xi'an TingXue Network Technology co., Ltd. by WoSign CA Limited on January 21, 2016 with the serial number '5451a8e67dccd396c3bef61e2ef9a151'.