Xin Zhou

Publisher Information

Xin Zhou is a software publisher located in Beijing, China*. Thre are 128 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
9/18/2016 3:00:00 AM

Valid to:
3/23/2017 12:59:59 AM

Subject:
CN=Xin Zhou, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3a949ef03d9dd2d150b24b274ff6d7b4

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP (M)
100.00%

1 / 68      (Malware)
3gs_lj.exe  (8dfab2a757a94b1dc6dd621b05319767)

1 / 68      (Malware)
damu_ay.exe  (abf797f93ec34482a65e29f1edfb47c8)

1 / 68      (Malware)
trmz.exe  (8c4fe43f326379f5f8d0bd0578eec5d7)

1 / 68      (Malware)
64f2.tmp  (e8a9096db86386ba4559e465fc37df3b)

1 / 68      (Malware)
pro_lj.exe  (2d609421cd8390b15dc35b8291024973)

1 / 68      (Malware)
trotux.exe  (7e5c06b44e376702b891f418807bd1fa)

1 / 68      (Malware)
qpft56rvh.exe  (4a714110636e0f49378b9fcb52479b8a)

1 / 68      (Malware)
isr_lj.exe  (0d78a7fd8afb5c15c77918711bf8c2f1)

1 / 68      (Malware)
qca_zt.exe  (3e1dc7f6217dc458567c5a32412b56d1)

1 / 68      (Malware)
phq4r7quv.exe  (af526b0cbb8e35760c33eec78162e81c)

1 / 68      (Malware)
dam_ay.exe  (827f9db95aeaa565b118b576d749061f)

1 / 68      (Malware)
0y1i8kppk.exe  (9423c050a1761f753ed2ff575e0964de)

1 / 68      (Malware)
web_zt.exe  (197b78cf0e3d5ad6790f74fa61c6b5e4)

1 / 68      (Malware)
rnw8qqdqm.exe  (e82c8b9b61e133294811a2eb24ac5236)

1 / 68      (Malware)
dq4j38oio.exe  (768eb79ab6992e172b69af49933dc746)

1 / 68      (Malware)
isr_lm.exe  (352534ed7a54700e4a311debdfa87aa9)

1 / 68      (Malware)
trotux.exe  (087792376e758bd55c14cc7176e54d09)

1 / 68      (Malware)
8d81.tmp  (24e932abc1734fb325fb2460607ec697)

1 / 68      (Malware)

1 / 68      (Malware)
3gs_lj.exe  (f0ce094f91d23f6a52dc8ea1f77e98a7)

1 / 68      (Malware)
tnyc5sh1q1h4.exe  (51466a56b94f46fc470af0125b35cf62)

1 / 68      (Malware)
adv_288.exe  (b4d7f31078beaac016eba8ddc27805c9)

1 / 68      (Malware)
yomz.exe  (4f663f9a7975798b9ca7b56eed88e3ea)

1 / 68      (Malware)
trotux.exe  (f2e93a17daef84df3982ef57964763da)

1 / 68      (Malware)
isr_lm.exe  (b9010ecafee8eaa9edd29be3387bcda3)

1 / 68      (Malware)
ic-0.13037f2f786948.exe  (c038687a59b41476d7bb5a10b17e000c)

1 / 68      (Malware)
d2fb.tmp  (608020603c920d3678b76fbe39e5f566)

1 / 68      (Malware)
ic-0.b73ec737273f78.exe  (576a55149d461f9df920c530729ec373)

1 / 68      (Malware)
isr_lj.exe  (84652a1c74b5b6a9f89f0dc39bdc6829)

1 / 68      (Malware)
v08pb0tw2kym.exe  (5881bf9095b7370543fbff10e094b3df)

 
Latest 30 of 37 files

Downloads URLs for files signed by Xin Zhou.

1 / 68      (Malware)
http://d3g1g0k0wwnjag.cloudfront.net/.../dam_ay.exe  (4cd9fa849aa3172f2a43ab9e5f40d696)

1 / 68      (Malware)
http://d3g1g0k0wwnjag.cloudfront.net/.../3gs_lj.exe  (f0ce094f91d23f6a52dc8ea1f77e98a7)

1 / 68      (Malware)
http://d3g1g0k0wwnjag.cloudfront.net/.../dam_ay.exe  (827f9db95aeaa565b118b576d749061f)

The certificates below are also signed by Xin Zhou.

34EC9565805F34204C6966FB81E36BA1  (Oct 20, 2016 to Mar 23, 2017)

4CEAF4F1B7C2E1B181B9A1ED937F62A8  (Apr 19, 2016 to Mar 23, 2017)

6B69B926445760937BFECE1A309DB4C3  (Nov 02, 2016 to Mar 23, 2017)

1DB458BF0A340397741D916531FF4BF9  (May 16, 2016 to Mar 23, 2017)

367B2279015EA17AAEF655811E3FA5B5  (Aug 24, 2016 to Mar 23, 2017)

35D1EE4E830E9AD6F6434327DEEF72FB  (Dec 16, 2016 to Mar 23, 2017)

6FCED1F00CF94B4441BCEC9673DC734C  (Nov 17, 2016 to Mar 23, 2017)

696F62AA5E54725E0D70304080E0E296  (Nov 21, 2016 to Mar 23, 2017)

65A50AC1DC609167928FF03D2E9DB9B7  (Jan 17, 2017 to Mar 23, 2017)

3975CA38C58455C8411CAB1D133B35BD  (Dec 14, 2016 to Mar 23, 2017)

10 of 128 code signing certificates issued

* Note, the details and description above are based on the code signing digital signature issued to Xin Zhou by thawte, Inc. on September 18, 2016 with the serial number '3a949ef03d9dd2d150b24b274ff6d7b4'.