Riyue Tongxing Information Technology (Beijing) Co.,Ltd.

Publisher Information

Riyue Tongxing Information Technology (Beijing) Co.,Ltd. is a software publisher located in Beijing, China*. A majority of the programs developed by the company can be classified as adware or other potentially unwanted programs. There is one additional code signing certificate issued to this publisher.
Authority:
WoSign CA Limited

Valid from:
11/2/2015 4:43:59 PM

Valid to:
11/2/2016 4:43:59 PM

Subject:
CN="Riyue Tongxing Information Technology (Beijing) Co.,Ltd.", O="Riyue Tongxing Information Technology (Beijing) Co.,Ltd.", STREET="B801A,8F,Block B,S&T Fortune Center,No.8,Xueqing Road,Haidian District", PostalCode=100083, L=Beijing, S=Beijing, C=CN, SERIALNUMBER=110108011321704, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.1=Beijing, OID.1.3.6.1.4.1.311.60.2.1.2=Beijing, OID.1.3.6.1.4.1.311.60.2.1.3=CN

Issuer:
CN=WoSign EV Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
52dc4c31f7609af339ef3228bd510b83

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Gaofenquming (M)
59.09%

IKARUS anti.virus
PUA.Gaofenquming
31.82%

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F], PE:Malware.Generic/QRS!1.9E2D [F], Malware.Generic!fOQQk4IwuzE@4 (thunder)
27.27%

ESET NOD32
Win32/Gaofenquming.B potentially unwanted (variant)
27.27%

Emsisoft Anti-Malware
Gen:Variant.Symmi.60792
27.27%

G Data
Gen:Variant.Symmi.60792, Win32.Application.RiyueDowner
27.27%

avast!
Win32:Malware-gen, Win32:Evo-gen [Susp]
27.27%

MicroWorld eScan
Gen:Variant.Symmi.60792
22.73%

K7 AntiVirus
Adware
22.73%

Bitdefender
Gen:Variant.Symmi.60792
22.73%

1 / 68      (PUP)

Downloads URLs for files signed by Riyue Tongxing Information Technology (Beijing) Co.,Ltd..

1 / 68      (PUP)
http://dl.dhfszh.com/.../Adobe Flash Player_18@2116.exe  (460e2f60ab7c1666516d1413becb957b)

15 / 68    (PUP)
http://c5.97you.net/.../???30???_36@7216.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

15 / 68    (PUP)

1 / 68      (PUP)
http://c1.9377wan.cn/.../SanteDICOMEditor_1@570383.exe  (460e2f60ab7c1666516d1413becb957b)

15 / 68    (PUP)
http://c2.9377wan.cn/.../???????_31@168519.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

1 / 68      (PUP)
http://dl.wylbdml.com/.../????_31@3106.exe  (460e2f60ab7c1666516d1413becb957b)

15 / 68    (PUP)

15 / 68    (PUP)
http://c4.97you.net/.../D3DWindower_3@39421.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

15 / 68    (PUP)

15 / 68    (PUP)
http://c5.97you.net/.../office_11@48963.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

15 / 68    (PUP)

15 / 68    (PUP)

15 / 68    (PUP)
http://c2.9377wan.cn/.../setup_33@76436.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

1 / 68      (PUP)
http://cl2.cjsdxz.com/.../X-Scan_1@1498.exe  (460e2f60ab7c1666516d1413becb957b)

1 / 68      (PUP)
http://cl2.qnxzq.com/.../OBS_61@91057.exe  (460e2f60ab7c1666516d1413becb957b)

15 / 68    (PUP)
http://c5.97you.net/.../??4?????_58@867.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

15 / 68    (PUP)

15 / 68    (PUP)

15 / 68    (PUP)
http://c5.97you.net/.../???????1.30???_36@80743.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

15 / 68    (PUP)

1 / 68      (PUP)
https://dl.cjsdxz.com/.../?????????W2kXpCJK_1@29126.exe  (460e2f60ab7c1666516d1413becb957b)

15 / 68    (PUP)
http://c1.97you.net/.../DirectX_1@5288.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

1 / 68      (PUP)

15 / 68    (PUP)
http://c2.9377wan.cn/.../Dreamweaver_51@72633.exe  (e382b1767fbe7c77d680af7bd6dddd0e)

1 / 68      (PUP)
https://dl.cjsdxz.com/.../????????_1@519794.exe  (460e2f60ab7c1666516d1413becb957b)

 
Latest 30 of 347 download URLs

The following websites host and distribute files published by Riyue Tongxing Information Technology (Beijing) Co.,Ltd..

The following certificate is also signed by Riyue Tongxing Information Technology (Beijing) Co.,Ltd..

55950E596B6D1EB045BBED7DEE696932  (Nov 02, 2015 to Nov 02, 2016)

The following publishers (by Authenticode signature organization name) are related.

30 of 46 publishers

* Note, the details and description above are based on the code signing digital signature issued to Riyue Tongxing Information Technology (Beijing) Co.,Ltd. by WoSign CA Limited on November 02, 2015 with the serial number '52dc4c31f7609af339ef3228bd510b83'.