suptab.exe

Thinknice Co. Limited

The application suptab.exe by Thinknice Co. Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Thinknice Co. Limited  (signed and verified)

MD5:
955b5c69dc8d8ab65dd5cfae21e65599

SHA-1:
6b47534fc4a5206c0ab4937c19197096c3899fa0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:02:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Thinknice (M)
16.11.17.10

File size:
1.2 MB (1,251,796 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\tmp\suptab.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/26/2013 12:04:13 PM

Valid to:
11/27/2014 12:04:13 PM

Subject:
CN=Thinknice Co. Limited, O=Thinknice Co. Limited, L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218A5EF69A65044FE28125681D829B5EFE

File PE Metadata
Compilation timestamp:
3/22/2010 6:29:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:DI4RjstGBh+7DydmxEOJcAxpdnJZtB1qg4a9tccIwVELEQe3Zp:3jstyh+XydmtDpdnplkSVkJe3Zp

Entry address:
0x1A1000

Entry point:
BB, 98, B8, 75, 00, 68, 1A, 10, 5A, 00, 5A, 68, 98, 05, 00, 00, 5E, 31, 1C, 32, 90, 83, EE, 04, 90, 75, F6, 90, 90, 90, 70, C5, 74, 00, 98, B8, 75, 00, 98, B8, 35, 00, D2, A9, 75, 00, D8, DA, 65, 00, 4C, D1, 65, 00, 98, 08, 77, 00, 67, 47, 8A, FF, 8C, AE, 3F, 00, CE, A3, 3F, 00, FC, A3, 3F, 00, 0C, EF, 74, 00, CC, A3, 7F, 00, FA, A3, 7F, 00, 8C, E4, 74, 00, CC, A3, 7F, 00, FA, A3, 7F, 00, 98, B8, 75, 00, 98, B8, 75, 00, 98, B8, 75, 00, 98, B8, 75, 00, 98, B8, 75, 00, 98, B8, 75, 00, 98, B8, 75, 00, 98, B8...
 
[+]

Entropy:
7.9371  (probably packed)

Code size:
62 KB (63,488 bytes)

Remove suptab.exe - Powered by Reason Core Security