upob94a.tmp.hlh

Shanghai Yuntong Technology Co., Ltd.

The file upob94a.tmp.hlh by Shanghai Yuntong Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from img.rafomedia.com.
Publisher:
Shanghai Yuntong Technology Co., Ltd.  (signed and verified)

MD5:
4dae6ab3c9d4d18c5447c6082e9d8176

SHA-1:
c5137e4a6945b94ddf98c1a3e829feaa3c1e6269

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 6:23:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.9.8.15

File size:
394.4 KB (403,848 bytes)

Common path:
C:\users\{user}\appdata\local\temp\upob94a.tmp.hlh

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/6/2016 7:00:00 AM

Valid to:
2/25/2017 6:59:59 AM

Subject:
CN="Shanghai Yuntong Technology Co., Ltd.", O="Shanghai Yuntong Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1A3EAC6C38C71B1E4CE1FA41CFA093E5

The file upob94a.tmp.hlh has been seen being distributed by the following URL.

Remove upob94a.tmp.hlh - Powered by Reason Core Security