update_task.exe

Update Task

TAOBAO (CHINA) SOFTWARE CO.,LTD.

The executable update_task.exe, “UCBrowser update task” has been detected as malware by 3 anti-virus scanners.
Publisher:
UCWeb Inc  (signed by TAOBAO (CHINA) SOFTWARE CO.,LTD.)

Product:
Update Task

Description:
UCBrowser update task

Version:
1.0.0.8

MD5:
81f1a62197013698844c902fd168f1e4

SHA-1:
423e90f7e49c96d8b88aacb75a498ae5c35b6c21

SHA-256:
f1fdc6a042e16702e0552dadf1bdd4fc865a300c62635b9bede66b6eff9f2f3d

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/26/2024 7:45:14 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
589.3 KB (603,479 bytes)

Product version:
1.0.0.8

Copyright:
UCWeb Inc. All rights reserved.

Original file name:
update_task.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\ucbrowser\application\update_task.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/16/2016 6:00:00 AM

Valid to:
7/15/2018 5:59:59 AM

Subject:
CN="TAOBAO (CHINA) SOFTWARE CO.,LTD.", OU=RDC, O="TAOBAO (CHINA) SOFTWARE CO.,LTD.", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
780A0032A6CE7D0B5D5452F5CDE520DC

File PE Metadata
Compilation timestamp:
2/21/2017 1:26:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x47B6C

Entry point:
E9, CB, AB, FE, FF, E9, 80, FE, FF, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, 48, 3C, 03, C8, 0F, B7, 41, 14, 8D, 51, 18, 03, D0, 0F, B7, 41, 06, 6B, F0, 28, 03, F2, 3B, D6, 74, 19, 8B, 4D, 0C, 3B, 4A, 0C, 72, 0A, 8B, 42, 08, 03, 42, 0C, 3B, C8, 72, 0C, 83, C2, 28, 3B, D6, 75, EA, 33, C0, 5E, 5D, C3, 8B, C2, EB, F9, E8, DD, 0B, 00, 00, 85, C0, 75, 03, 32, C0, C3, 64, A1, 18, 00, 00, 00, 56, BE, 4C, 9E, 47, 00, 8B, 50, 04, EB, 04, 3B, D0, 74, 10, 33, C0, 8B, CA, F0, 0F, B1, 0E, 85, C0, 75, F0, 32, C0, 5E, C3, B0...
 
[+]

Entropy:
6.9588

Packer / compiler:
Xtreme-Protector v1.05

Code size:
412 KB (421,888 bytes)

Remove update_task.exe - Powered by Reason Core Security