ucbrowser_v6.0.1471.914_4722_(build1702221720)_channelu_02241016.exe

ChannelU.exe

TAOBAO (CHINA) SOFTWARE CO.,LTD.

The application ucbrowser_v6.0.1471.914_4722_(build1702221720)_channelu_02241016.exe by TAOBAO (CHINA) SOFTWARE CO.,LTD has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address 137.186.204.221.adsl-pool.sx.cn on port 80 using the HTTP protocol.
Publisher:
UCWeb Inc.  (signed by TAOBAO (CHINA) SOFTWARE CO.,LTD.)

Product:
ChannelU.exe

Description:
ChannelU Module

Version:
1.0.11.0

MD5:
de316abdc0308953047d36caf234bb94

SHA-1:
2ddc37cff387a2f3f35603c453f7f9963c6ad445

SHA-256:
068b2e75a06c93c2641c6315b541c010830136c29a34904adab3f560ac4418d8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 7:31:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Taobao (L)
17.2.24.9

File size:
395.4 KB (404,880 bytes)

Product version:
1.0.11.0

Copyright:
Copyright 2008-2016 UCWeb Inc. All rights reserved.

Original file name:
ChannelU.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ucbrowser_v6.0.1471.914_4722_(build1702221720)_channelu_02241016.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/16/2016 7:00:00 AM

Valid to:
7/15/2018 6:59:59 AM

Subject:
CN="TAOBAO (CHINA) SOFTWARE CO.,LTD.", OU=RDC, O="TAOBAO (CHINA) SOFTWARE CO.,LTD.", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
780A0032A6CE7D0B5D5452F5CDE520DC

File PE Metadata
Compilation timestamp:
2/23/2017 4:53:06 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0xBDF2

Entry point:
E8, 26, 06, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 08, 85, 45, 00, E8, 68, 05, 00, 00, 6A, 01, E8, D0, F9, FF, FF, 59, 84, C0, 75, 07, 6A, 07, E8, 01, 02, 00, 00, 32, DB, 88, 5D, E7, 83, 65, FC, 00, E8, B9, F8, FF, FF, 88, 45, DC, A1, D0, C2, 45, 00, 33, C9, 41, 3B, C1, 74, DC, 85, C0, 75, 49, 89, 0D, D0, C2, 45, 00, 68, 2C, A4, 44, 00, 68, 10, A4, 44, 00, E8, C2, 78, 01, 00, 59, 59, 85, C0, 74, 11, C7, 45, FC, FE, FF, FF, FF, B8, FF, 00, 00, 00, E9, F6, 00, 00, 00, 68, 0C, A4, 44, 00, 68, 8C, A3, 44, 00...
 
[+]

Entropy:
6.6295

Code size:
288.5 KB (295,424 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):
Connects to 138.186.204.221.adsl-pool.sx.cn  (221.204.186.138:80)

TCP (HTTP):
Connects to 137.186.204.221.adsl-pool.sx.cn  (221.204.186.137:80)