ucbrowser_v6.1.2107.201_4722_(build1703310852)_channelu_03021028.exe

ChannelU.exe

TAOBAO (CHINA) SOFTWARE CO.,LTD.

The application ucbrowser_v6.1.2107.201_4722_(build1703310852)_channelu_03021028.exe by TAOBAO (CHINA) SOFTWARE CO.,LTD has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
UCWeb Inc.  (signed by TAOBAO (CHINA) SOFTWARE CO.,LTD.)

Product:
ChannelU.exe

Description:
ChannelU Module

Version:
1.0.11.0

MD5:
43c611e90c9ab44e54ee5d119ed4b706

SHA-1:
ddc5c4b4f0d4d30d414fece74c58f2226eb1688b

SHA-256:
732bdd02874a40ee65e2085a70a865e69da702b67658bf7fcb78152f5a71b59a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 4:55:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Taobao (L)
17.3.2.8

File size:
395.4 KB (404,880 bytes)

Product version:
1.0.11.0

Copyright:
Copyright 2008-2016 UCWeb Inc. All rights reserved.

Original file name:
ChannelU.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\ucbrowser_v6.1.2107.201_4722_(build1703310852)_channelu_03021028.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/16/2016 2:00:00 AM

Valid to:
7/15/2018 1:59:59 AM

Subject:
CN="TAOBAO (CHINA) SOFTWARE CO.,LTD.", OU=RDC, O="TAOBAO (CHINA) SOFTWARE CO.,LTD.", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
780A0032A6CE7D0B5D5452F5CDE520DC

File PE Metadata
Compilation timestamp:
2/23/2017 10:53:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0xBDF2

Entry point:
E8, 26, 06, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 08, 85, 45, 00, E8, 68, 05, 00, 00, 6A, 01, E8, D0, F9, FF, FF, 59, 84, C0, 75, 07, 6A, 07, E8, 01, 02, 00, 00, 32, DB, 88, 5D, E7, 83, 65, FC, 00, E8, B9, F8, FF, FF, 88, 45, DC, A1, D0, C2, 45, 00, 33, C9, 41, 3B, C1, 74, DC, 85, C0, 75, 49, 89, 0D, D0, C2, 45, 00, 68, 2C, A4, 44, 00, 68, 10, A4, 44, 00, E8, C2, 78, 01, 00, 59, 59, 85, C0, 74, 11, C7, 45, FC, FE, FF, FF, FF, B8, FF, 00, 00, 00, E9, F6, 00, 00, 00, 68, 0C, A4, 44, 00, 68, 8C, A3, 44, 00...
 
[+]

Code size:
288.5 KB (295,424 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):