uibia6.1.exe

ZhongXiang ZhiXing Network Service Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Uibia0412164724’.
Publisher:

MD5:
7c5eeffd73723b09bd5cccfe2b185d8e

SHA-1:
3930fb44af6cf72df6b535f4064c134485e9ece0

SHA-256:
33bd766b6626013f16fb276a648b0ec7637fe8d077e8b17e0335e49a4315578f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:28:02 PM UTC  (today)

File size:
2.8 MB (2,945,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\uibia\uibia6.1.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/13/2013 8:00:00 AM

Valid to:
9/21/2015 7:59:59 AM

Subject:
CN="ZhongXiang ZhiXing Network Service Co., Ltd.", OU=Software Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ZhongXiang ZhiXing Network Service Co., Ltd.", L=ZhongXiang, S=Hubei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7E93ADFCFBCBCF60320C1B21FA69513A

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:etimLxAziBbR1tCUadwVXLm9/uJuvU/zb+dlr+eOj:QDxAzok9/uMsb+dl2j

Entry address:
0x1A9764

Entry point:
55, 8B, EC, B9, 07, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 1C, 8E, 5A, 00, E8, 4B, D1, E5, FF, 33, C0, 55, 68, 58, 99, 5A, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 84, 94, E5, FF, 8B, 45, EC, BA, 70, 99, 5A, 00, E8, 7F, B0, E5, FF, 0F, 85, 8C, 00, 00, 00, 6A, 00, 8D, 45, E8, 50, 8D, 55, DC, A1, 98, 38, 5B, 00, 8B, 00, E8, 48, E5, ED, FF, 8B, 45, DC, 8D, 55, E0, E8, 1D, 06, E6, FF, FF, 75, E0, 68, 84, 99, 5A, 00, 68, 94, 99, 5A, 00, 8D, 45, E4, BA, 03, 00, 00, 00...
 
[+]

Entropy:
6.8910

Developed / compiled with:
Microsoft Visual C++

Code size:
1.7 MB (1,739,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Uibia0412164724

Command:
"C:\Program Files\uibia\uibia6.1.exe" \start


Scan uibia6.1.exe - Powered by Reason Core Security