um.exe

Cloud Software

The application um.exe by Cloud Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘UM’.
Publisher:
Cloud Software  (signed and verified)

MD5:
3898890ca965a3fcdee05b293570777b

SHA-1:
2e5da28fb39fa2af7def70f9a27e11c31eff57a9

SHA-256:
7a715224dd62e19c6f809fb84797a99360f9847fa16940b7071e61ca14993bd3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/13/2024 12:29:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Spigot (M)
17.3.8.0

File size:
1.6 MB (1,683,248 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\update manager\um.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/8/2016 2:00:00 AM

Valid to:
3/7/2017 2:00:00 PM

Subject:
CN=Cloud Software, O=Cloud Software, L=Incline Village, S=Nevada, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09C8D9FCE70C8F921CB55912E7F1B2DE

File PE Metadata
Compilation timestamp:
2/24/2012 9:19:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x3883

Entry point:
00, 88, 9C, 24, 8C, 00, 00, 00, 3B, F3, 74, 06, 6A, 01, 53, 57, FF, D6, 8B, 54, 24, 18, 52, FF, 15, 68, 02, 4E, 00, 8B, 44, 24, 1C, 50, FF, 15, 3C, 02, 4E, 00, 8B, 74, 24, 20, 8D, 8C, 24, A4, 00, 00, 00, 51, 56, E8, 9F, 05, 0B, 00, 83, F8, 01, 0F, 84, D2, FC, FF, FF, 56, FF, 15, 3C, 02, 4E, 00, 8B, 44, 24, 14, 8B, 8C, 24, E0, 02, 00, 00, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5E, 5B, 8B, 8C, 24, C8, 02, 00, 00, 33, CC, E8, D4, 2A, 0B, 00, 8B, E5, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 6A, FF, 68...
 
[+]

Entropy:
7.0785

Code size:
27.5 KB (28,160 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
UM

Command:
C:\users\{user}\appdata\roaming\update manager\um.exe


Remove um.exe - Powered by Reason Core Security