upoa0a2.tmp.hlh

Sice Xing

The file upoa0a2.tmp.hlh by Sice Xing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Sice Xing  (signed and verified)

MD5:
6bee5b1c57afb24b87f930f72eb25b65

SHA-1:
110890d1ca048abb4ff88f2c70a2907a94e2f983

SHA-256:
9534779f25266df2d7d129a47df6549a422bfbe08792085fbc06987b99839a16

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 12:38:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.8.6.21

File size:
464.4 KB (475,520 bytes)

Common path:
C:\windows\temp\upoa0a2.tmp.hlh

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/6/2016 2:00:00 AM

Valid to:
4/2/2017 1:59:59 AM

Subject:
CN=Sice Xing, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
358C4C30C91718ECFB0999261DB321AC

File PE Metadata
Compilation timestamp:
5/20/2016 11:39:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:libYb9iYFnlzBzBK/Ntreg8IN9siqpAqpTqpQNfyYpsiqpF:GYRiYFnTzBK/fSgDRGAGTGayYpRGF

Entry address:
0x25D30

Entry point:
C4, 04, 85, C0, 74, 22, 8B, 8D, 08, FF, FF, FF, 8B, 11, 83, CA, 01, 8B, 85, 08, FF, FF, FF, 89, 10, 8B, 8D, 08, FF, FF, FF, 8B, 95, 00, FF, FF, FF, 89, 51, 08, 8B, 85, 08, FF, FF, FF, 8B, 08, 81, E1, 00, 03, 00, 00, 81, F9, 00, 03, 00, 00, 0F, 84, FF, 01, 00, 00, 8B, 95, 04, FF, FF, FF, 83, 7A, 10, 00, 74, 0C, C7, 85, F4, FE, FF, FF, 03, 00, 00, 00, EB, 0A, C7, 85, F4, FE, FF, FF, 01, 10, 00, 00, 68, F0, 00, 00, 00, 8D, 85, 0C, FF, FF, FF, 50, 8B, 8D, F4, FE, FF, FF, 51, 8B, 95, 00, FF, FF, FF, 52, FF, 15...
 
[+]

Code size:
331.5 KB (339,456 bytes)

Remove upoa0a2.tmp.hlh - Powered by Reason Core Security