uibia.exe

ZhongXiang ZhiXing Network Service Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Uibia’.
Publisher:

MD5:
ddfb8bbf4a6c5e0d122329efa618aa8e

SHA-1:
906a1d834e31de9a2d53f51f5611916383bb9f82

SHA-256:
425164cc14e615cd679136e13a0af34df0672285217609bb43791d0237195415

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:48:19 PM UTC  (today)

File size:
2.5 MB (2,639,336 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\uibia\uibia.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/31/2012 8:00:00 AM

Valid to:
8/31/2013 7:59:59 AM

Subject:
CN="ZhongXiang ZhiXing Network Service Co., Ltd.", OU=Software Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ZhongXiang ZhiXing Network Service Co., Ltd.", L=ZhongXiang, S=HuBei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
51F9220230FFAD7ECF5F6730207A8C85

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:3dlm7YFw8cDpULULT67zUYNSkadvOxrvpXdDAIlX2AeaEr49hBN7ajoE33K7KKk:3KsRYLMzUYNSkadvUXma/eLYhv7sY5k

Entry address:
0x16D3A0

Entry point:
55, 8B, EC, 83, C4, F0, B8, E8, CC, 56, 00, E8, 5C, 94, E9, FF, 68, 24, D4, 56, 00, 68, 30, D4, 56, 00, E8, 9D, 9E, E9, FF, 85, C0, 76, 11, 6A, 00, 6A, 00, 68, 00, 14, 00, 00, 50, E8, 6A, A1, E9, FF, EB, 48, A1, 10, 4F, 57, 00, 8B, 00, E8, D8, 8F, F1, FF, 8B, 0D, 50, 4B, 57, 00, A1, 10, 4F, 57, 00, 8B, 00, 8B, 15, E0, 9D, 56, 00, E8, D8, 8F, F1, FF, 8B, 0D, 00, 4E, 57, 00, A1, 10, 4F, 57, 00, 8B, 00, 8B, 15, FC, 5A, 51, 00, E8, C0, 8F, F1, FF, A1, 10, 4F, 57, 00, 8B, 00, E8, 34, 90, F1, FF, E8, CB, 6D, E9...
 
[+]

Entropy:
6.9089

Developed / compiled with:
Microsoft Visual C++

Code size:
1.4 MB (1,492,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Uibia

Command:
"C:\Program Files\uibia\uibia.exe" \start


Scan uibia.exe - Powered by Reason Core Security