ucbrowser_v6.1.2015.1007_windows_pf101_(build17022118).exe

UC Browser

TAOBAO (CHINA) SOFTWARE CO.,LTD.

The application ucbrowser_v6.1.2015.1007_windows_pf101_(build17022118).exe, “UCBrowser Online Installer” by TAOBAO (CHINA) SOFTWARE CO.,LTD has been detected as a potentially unwanted program by 2 anti-malware scanners. The file has been seen being downloaded from pdds.ucweb.com and multiple other hosts.
Publisher:
UCWeb Inc.  (signed by TAOBAO (CHINA) SOFTWARE CO.,LTD.)

Product:
UC Browser

Description:
UCBrowser Online Installer

Version:
1.0.0.0

MD5:
e95597eb63ba0299e0afff2a4fa5e041

SHA-1:
4934ff38ba54a1b9a5a146fc9d4f2203d713cf6d

SHA-256:
8dd1d8b6c83374491f1404f1ee1a858a5c86fce0e5b0f3834f02af90f287304c

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 4:59:19 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Taobao.D potentially unwanted application
6.3.12010.0

Reason Heuristics
PUP.Taobao (L)
17.2.24.4

File size:
1.2 MB (1,281,696 bytes)

Product version:
1.0.0.0

Copyright:
Copyright 2008-2014 UCWeb Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\downloads\ucbrowser_v6.1.2015.1007_windows_pf101_(build17022118).exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/16/2016 7:00:00 AM

Valid to:
7/15/2018 6:59:59 AM

Subject:
CN="TAOBAO (CHINA) SOFTWARE CO.,LTD.", OU=RDC, O="TAOBAO (CHINA) SOFTWARE CO.,LTD.", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
780A0032A6CE7D0B5D5452F5CDE520DC

File PE Metadata
Compilation timestamp:
2/21/2017 2:24:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x8AF48

Entry point:
E8, 70, 09, 00, 00, E9, 80, FE, FF, FF, 3B, 0D, 44, E4, 4C, 00, F2, 75, 02, F2, C3, F2, E9, 28, 00, 00, 00, 55, 8B, EC, 6A, 00, FF, 15, 1C, 13, 4B, 00, FF, 75, 08, FF, 15, E0, 10, 4B, 00, 68, 09, 04, 00, C0, FF, 15, 54, 11, 4B, 00, 50, FF, 15, 74, 12, 4B, 00, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 2B, 45, 02, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 90, 47, 4D, 00, 89, 0D, 8C, 47, 4D, 00, 89, 15, 88, 47, 4D, 00, 89, 1D, 84, 47, 4D, 00, 89, 35, 80, 47, 4D, 00, 89, 3D, 7C, 47, 4D, 00, 66...
 
[+]

Entropy:
6.8477

Code size:
703.5 KB (720,384 bytes)

The file ucbrowser_v6.1.2015.1007_windows_pf101_(build17022118).exe has been seen being distributed by the following 3 URLs.

http://pdds.ucweb.com/download/newest/UCBrowser/en-us/101/.../PC_banner

http://pdds.ucweb.com/download/newest/UCBrowser/en-us/101/.../pcweb

http://gjxz.ucweb.com/files/UCBrowser/en-us/.../UCBrowser_V6.1.2015.1007_windows_pf101_(Build17022118).exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to a96-17-182-48.deploy.akamaitechnologies.com  (96.17.182.48:80)

TCP (HTTP):
Connects to static.ill.117.239.122.8/24.bsnl.in  (117.239.122.8:80)

TCP (HTTP):
Connects to rlchq901.ghanatel.com.gh  (80.87.65.83:80)

TCP (HTTP):
Connects to host-213.158.175.90.tedata.net  (213.158.175.90:80)

TCP (HTTP):
Connects to a96-17-182-51.deploy.akamaitechnologies.com  (96.17.182.51:80)

TCP (HTTP):

TCP (HTTP):
Connects to a184-25-109-18.deploy.static.akamaitechnologies.com  (184.25.109.18:80)

TCP (HTTP):
Connects to static.ill.117.239.91.48/24.bsnl.in  (117.239.91.48:80)

TCP (HTTP):
Connects to fm-dyn-139-193-253-59.fast.net.id  (139.193.253.59:80)

TCP (HTTP):
Connects to etg-01-042.etg.ras.cantv.net  (200.44.26.42:80)

TCP (HTTP):
Connects to broadband.actcorp.in  (123.176.33.19:80)

TCP (HTTP):
Connects to abs-static-89.92.251.27.aircel.co.in  (27.251.92.89:80)

TCP (HTTP):
Connects to a92-122-214-232.deploy.akamaitechnologies.com  (92.122.214.232:80)

TCP (HTTP):

TCP (HTTP):
Connects to a23-215-131-168.deploy.static.akamaitechnologies.com  (23.215.131.168:80)

TCP (HTTP):

TCP (HTTP):
Connects to a204-2-179-17.deploy.akamaitechnologies.com  (204.2.179.17:80)

TCP (HTTP):
Connects to a173-222-148-11.deploy.static.akamaitechnologies.com  (173.222.148.11:80)

TCP (HTTP):
Connects to a104-95-190-33.deploy.static.akamaitechnologies.com  (104.95.190.33:80)

TCP (HTTP):