Dening Hu

Publisher Information

Dening Hu is a software developer located in Beijing, China*. A majority of the programs developed by the company can be classified as adware or other potentially unwanted programs. Thre are 20 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
6/27/2016 7:00:00 AM

Valid to:
6/9/2017 6:59:59 AM

Subject:
CN=Dening Hu, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
103042e2534359abac3b375e85a962ba

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Elex (M), PUP.Elex (M), PUP.Elex.DeningHu.Meta (M)
75.00%

ESET NOD32
Win32/Floxif.H virus
25.00%

avast!
Win32:Pioneer-C
25.00%

F-Secure
Win32.Floxif.A
20.83%

Emsisoft Anti-Malware
Win32.Floxif
16.67%

AVG
Win32/Floxif.A
16.67%

F-Prot
W32/Floxif.B
16.67%

Norman
Win32.Floxif.A
16.67%

Microsoft Security Essentials
Threat.Undefined
12.50%

Kaspersky
Virus.Win32.Pioneer
12.50%

1 / 68      (PUP)
winsaber.exe  (6f64cdb5808f696f03462107a3124d02)

1 / 68      (PUP)
saber.exe  (6d84424716bbd74aa0ec3a4c7578044b)

1 / 68      (PUP)
winsaber.exe  (72e8a4ed4009edf480fc6fe37444eb13)

1 / 68      (PUP)
saber.exe  (dfe2609933ab98e2aec0208c251f68d9)

1 / 68      (PUP)
tmp00000002c744eeec4e61e710  (cf5d6ab51a0486712c9ffbafd2757329)

1 / 68      (PUP)
tmp0000000195f5ee7df4fd8e19  (30e5f3f4aad9d472b2ccf5b2d32bb4cb)

1 / 68      (PUP)
tmp00000002a8e1087f2410f12d  (f569f7649c263951017237c4d02c3b50)

1 / 68      (PUP)
winsaber.exe  (8cb3d87cea134361aa6f735c3e20cb47)

3 / 68      (Malware)
winsaber.exe  (88bbf81f1aab861af80c5e6008c12243)

1 / 68      (PUP)
saber.exe  (0207fafd12be59af5bc2322f1549f53d)

3 / 68      (Malware)
winsaber.exe  (c52f2a0de4035d4fb9af45702a979780)

1 / 68      (PUP)
tmp000000020f027833e75ff287  (bfe218da85c56143640ee23c5e5b5488)

1 / 68      (PUP)
winsaber.exe  (a22365d468dfdc8371d13f8b177811a2)

7 / 68      (Malware)
winsaber.exe  (e4f0f19b9e022a4e282809486598e1a1)

1 / 68      (PUP)
tmp000000038404b37d265c519d  (e6589c7394e1495070ebb7deef3250ed)

1 / 68      (PUP)
tmp00000002193e94c6857ddd8f  (f2924ec6ac266184bc6ce9d02f06e089)

1 / 68      (PUP)
winsaber.exe  (a25ddc51e8ee72f5715ce89d7ce51ced)

2 / 68      (PUP)
winsaber.exe  (8cb3d87cea134361aa6f735c3e20cb47)

9 / 68      (Malware)
winsaber.exe  (d2d6d7643f3d4ec0cfffbc2ee8477822)

1 / 68      (PUP)
winsaber.exe  (0090066ff1fb8f657d1e7f0e9ddf848e)

8 / 68      (Malware)
winsaber.exe  (ae911de36de783cbc6734a2973447950)

10 / 68    (Malware)
winsaber.exe  (ec8395e7d3a3df05ffa9e52130e68220)

1 / 68      (PUP)
winsaber.exe  (223de46f3f542bb6c0a2e528709ed3c9)

1 / 68      (PUP)
saber.exe  (6f64cdb5808f696f03462107a3124d02)

The certificates below are also signed by Dening Hu.

0241B909702EF44D10F5AB5FD6C664DF  (Aug 24, 2016 to Jun 09, 2017)

11746E1CD169D4C6D69A0C53EE052AE5  (Aug 31, 2016 to Jun 09, 2017)

48F6F27B7E9E428FAC06E28A6C97FCC2  (Jul 18, 2016 to Jun 09, 2017)

57CCEF725BD375656810929BA3B993CD  (Oct 14, 2016 to Jun 09, 2017)

1526014E3F697DCED61C390661163B6C  (Jun 08, 2016 to Jun 09, 2017)

1B4C3DB975D9BC9D6ACE9646EB28502A  (Aug 26, 2016 to Jun 09, 2017)

1B5D997D61943E8FF1BDF34C65EE5719  (Jul 28, 2016 to Jun 09, 2017)

5BD08CFF51B7E7BB13C171E1D7A49B78  (Sep 06, 2016 to Jun 09, 2017)

7986DA5F93A0A631551A2F4F1B1666BF  (Sep 22, 2016 to Jun 09, 2017)

7A2DF2BB7E9010EDF9FC306983C02B4D  (Oct 10, 2016 to Jun 09, 2017)

10 of 20 code signing certificates issued

* Note, the details and description above are based on the code signing digital signature issued to Dening Hu by thawte, Inc. on June 27, 2016 with the serial number '103042e2534359abac3b375e85a962ba'.