Yuanyuan Mei

Publisher Information

Yuanyuan Mei is a software publisher located in Beijing, China*. A majority of the programs developed by the company can be classified as adware or other potentially unwanted programs. Thre are 25 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
8/10/2016 5:00:00 PM

Valid to:
4/20/2017 4:59:59 PM

Subject:
CN=Yuanyuan Mei, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
19908a5548b59ce82f392297f289696b

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Elex (M), PUP.Bundler (M)
100.00%

IKARUS anti.virus
PUA.IStartSurf
4.17%

Qihoo 360 Security
QVM10.1.Malware.Gen
4.17%

1 / 68      (PUP)
isr_lj.exe  (c6e3d61f2e40e11a494e35960799b6c7)

1 / 68      (PUP)
damu_ay.exe  (45744f57ee94f2a166f39c0b0320a387)

1 / 68      (PUP)
damu_ay.exe  (603b68726491c88dc301ff3d1b16a0f7)

3 / 68      (PUP)
awhe4d7.tmp  (c9bc1902f140141932c1edfe8fbd39ef)

1 / 68      (PUP)
dam_ay.exe  (54db25529c6ad7d5ea72bbecde9c3c47)

1 / 68      (PUP)
fxzt8u6yb.exe  (fd5140e0c765d82a1d6f28cd6b5b92bc)

1 / 68      (PUP)
damu_ay.exe  (904021fc36da2644834726525aaa8abe)

1 / 68      (PUP)
amyesz.exe  (d2770042b2fd8ac55be071c157c673b4)

1 / 68      (PUP)
naizoye9pb.exe  (7b64aeae353814e8154c803d2669cbce)

1 / 68      (PUP)
isr_lj.exe  (6a3c95d48833292a8c7e1d23041140be)

1 / 68      (PUP)
isr_lj.exe  (6042b0d7c65135c4b0f655023c99a54d)

1 / 68      (PUP)
3gs_lj.exe  (d6cbff6b5668a0c92c8c8a2f61c11823)

1 / 68      (PUP)
damu_ay.exe  (2389025dc65a22ac52809457cf91be0d)

1 / 68      (PUP)
ui6pf831d.exe  (2768e920136b4d96a28531e1d33d6ce7)

1 / 68      (PUP)
awh593d.tmp  (da7ddfe674e6f3d76dfba6c28fac18b8)

1 / 68      (PUP)
isr_lj.exe  (f284084e318c7d1f91ed02c7acde5bb1)

1 / 68      (PUP)
amyesz.exe  (0744c0aa052593a12d0f3cf7ec01ad1f)

1 / 68      (PUP)
yj6eesazaq.exe  (607fa7edad908d78eb025bf5e0ce7f8a)

1 / 68      (PUP)
awh88bf.tmp  (c2f5c792b3859377c174d1af9fc72f0f)

1 / 68      (PUP)
isr_lj.exe  (ba09bee60d695fdc64f39c49c6e89d71)

1 / 68      (PUP)
tj3vcrv2it.exe  (75725f92ff59dacfad0be1648ea76fad)

1 / 68      (PUP)
dam_ay.exe  (227ff39182052c8bfa71b12f87617a51)

1 / 68      (PUP)
nationzoom.exe  (bc6537a7704d19fdfb9516a9edc0d53a)

1 / 68      (PUP)
awhe3db.tmp  (55103c15a69a5cf614585c93de5790f9)

Downloads URLs for files signed by Yuanyuan Mei.

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../damu_ay.exe  (904021fc36da2644834726525aaa8abe)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../amyesz.exe  (bc6537a7704d19fdfb9516a9edc0d53a)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../3gs_lj.exe  (d6cbff6b5668a0c92c8c8a2f61c11823)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../damu_ay.exe  (2389025dc65a22ac52809457cf91be0d)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../dam_ay.exe  (54db25529c6ad7d5ea72bbecde9c3c47)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../amyesz.exe  (d2770042b2fd8ac55be071c157c673b4)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../dam_ay.exe  (227ff39182052c8bfa71b12f87617a51)

1 / 68      (PUP)
http://d3g1g0k0wwnjag.cloudfront.net/.../amyesz.exe  (0744c0aa052593a12d0f3cf7ec01ad1f)

The certificates below are also signed by Yuanyuan Mei.

1E8CBE561541A195413040AFD65F878D  (Jan 06, 2017 to Apr 21, 2017)

6DA39476057154CF6769846DB47C8306  (Aug 26, 2016 to Apr 21, 2017)

045D57D63E13775C8F812E1864797F5A  (Jan 22, 2017 to Apr 21, 2017)

128A1FE0064E80F84A2197C8F0D07D76  (Jan 24, 2017 to Apr 21, 2017)

648588429AF2C580751BE41E22947AC1  (Aug 24, 2016 to Apr 21, 2017)

7D92FB84FC4339F548AEAF1B0A921F9B  (Aug 18, 2016 to Apr 21, 2017)

6C5D7A45FC4FE4003F40D7B13C3AA377  (Aug 12, 2016 to Apr 21, 2017)

7D1B8EB8054873A3D1BACD4595433E06  (Jan 13, 2017 to Apr 21, 2017)

4B77E45E6EE2D3592CB495A496A5B5CA  (Jan 19, 2017 to Apr 21, 2017)

0779F2D4DF108ECA89972073E40279BD  (Jan 20, 2017 to Apr 21, 2017)

10 of 25 code signing certificates issued

* Note, the details and description above are based on the code signing digital signature issued to Yuanyuan Mei by thawte, Inc. on August 10, 2016 with the serial number '19908a5548b59ce82f392297f289696b'.