winguard_x64.exe

魔方守护

Qingdao Ruanmei Network Technology Co.,Ltd.

The application winguard_x64.exe by Qingdao Ruanmei Network Technology Co.,Ltd has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address pc-b.bitgravity.com on port 80 using the HTTP protocol.
Publisher:
青岛软媒网络科技有限公司  (signed by Qingdao Ruanmei Network Technology Co.,Ltd.)

Product:
魔方守护

Version:
1.6.1.0

MD5:

SHA-1:
18e879d622ae4eeaea9ada28af3f73187dbc7a20

SHA-256:
128adcf2866404b8954472bf15c675e36eeb55c751908436ff698dc6a8a32862

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 12:50:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.QingdaoR (M)
16.7.13.9

File size:
583.2 KB (597,152 bytes)

Product version:
1.6.1.0

Copyright:
青岛软媒

Original file name:
winguard.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\roaming\pcmaster\winguard\winguard_x64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/13/2016 8:00:00 AM

Valid to:
8/27/2017 7:59:59 AM

Subject:
CN="Qingdao Ruanmei Network Technology Co.,Ltd.", OU=IT, O="Qingdao Ruanmei Network Technology Co.,Ltd.", L=Qingdao, S=Shandong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
50284BE9AB1A229C8F2C9FDD7B7E4AE4

File PE Metadata
Compilation timestamp:
7/12/2016 10:31:40 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:JxhqUS1dLiZ/nQ1DqjgaZXAml9DsFsV4zJIi4vRkfE7Md5Me2ac7LwK+CVXchEOr:1jRLgmXPl9ivGSVA1uj+NfKJ

Entry address:
0x4E914

Entry point:
48, 83, EC, 28, E8, 9B, FB, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 30, 48, 8B, D9, B9, 0E, 00, 00, 00, E8, 29, DE, 00, 00, 90, 48, 8B, 43, 08, 48, 85, C0, 74, 3F, 48, 8B, 0D, 44, 26, 03, 00, 48, 8D, 15, 35, 26, 03, 00, 48, 89, 4C, 24, 20, 48, 85, C9, 74, 19, 48, 39, 01, 75, 0F, 48, 8B, 41, 08, 48, 89, 42, 08, E8, 35, C0, FF, FF, EB, 05, 48, 8B, D1, EB, DD, 48, 8B, 4B, 08, E8, 25, C0, FF, FF, 48, 83, 63, 08, 00, B9, 0E, 00, 00, 00, E8, D6, DC, 00, 00, 48, 83, C4, 30, 5B, C3...
 
[+]

Entropy:
6.3889

Code size:
406.5 KB (416,256 bytes)

Access Provider
Name:
MartaExtension


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to pc-b.bitgravity.com  (64.185.181.238:80)

Remove winguard_x64.exe - Powered by Reason Core Security