bossfaceupdate.exe

Luhong Han

The application bossfaceupdate.exe by Luhong Han has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Luhong Han  (signed and verified)

MD5:
3f77465deaee21eb81880b82dae918c3

SHA-1:
a17f4c5b0ac79402bf92aed84e33b65a7d2c0c0e

SHA-256:
111f57055ad19cff1af8a88ca0102c59af7c468ee5be34ac2ad2b094544a40fb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
6/26/2025 8:41:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.10.14.3

File size:
277.4 KB (284,032 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\bossface\update\bossfaceupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/12/2016 7:00:00 AM

Valid to:
4/2/2017 6:59:59 AM

Subject:
CN=Luhong Han, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6F1A02A25EBF95FC2471099A880E9D0C

File PE Metadata
Compilation timestamp:
10/13/2016 9:49:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
3072:I43r4lBUAg0FujosHKG0p5JRFMViBE+jTOr3bwyFqA4L+7sI8R/DqPyAVfLPD5HX:pAOlqG0zJVEkOrL48sI8BsLDdbmY

Entry address:
0x217F7

Entry point:
E8, B9, 05, 00, 00, E9, 8E, FE, FF, FF, FF, 25, 70, 22, 44, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, E0, 43, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, E0, 43, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45...
 
[+]

Entropy:
6.4127

Code size:
244 KB (249,856 bytes)

Remove bossfaceupdate.exe - Powered by Reason Core Security