uplay.exe

Internet Widgits Pty Ltd

The application uplay.exe by Internet Widgits Pty has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Internet Widgits Pty Ltd  (signed and verified)

MD5:
d72cbeb7727d5ec6c263432ab110752a

SHA-1:
829e2e05e3360da4695e30e78939030f43bb1a46

SHA-256:
f94108226992bd8fc155f9d3d54bd05d3ccd174e323840913237c33630f70bbe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 4:33:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.3.21

File size:
15.7 MB (16,477,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ubisoft\ubisoft game launcher\uplay.exe

Digital Signature
Authority:
Internet Widgits Pty Ltd

Valid from:
4/26/2012 9:07:46 PM

Valid to:
5/26/2012 9:07:46 PM

Subject:
O=Internet Widgits Pty Ltd, S=Some-State, C=AU

Issuer:
O=Internet Widgits Pty Ltd, S=Some-State, C=AU

Serial number:
009DD8BC177ABB2F73

File PE Metadata
Compilation timestamp:
11/10/2005 6:11:47 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1135B7B

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, 7F, 00, 00, 00, BA, 03, BB, F1, D7, 30, EA, 4B, 66, 4B, 75, FC, 47, 42, 48, 46, 81, F7, 4F, 51, D9, 4E, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 73, E5, B4, AD, 87, F2, 81, D9, E6, 13, 00, 00, F6, D6, 71, D7, 86, C4, 90, 40, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, B0, B7, 90, FC, 66, 81, 44, 24, FC, B0, BA, 90, 75, BB, 0F, 9D, C4, 49, 68, F8, CC, 5A, FC, E9, 3C, FC, FF, FF, 31, E6, 47, 28, 77, FE, 87, D1, 4F, 4E, 86, D6, 83, E8, F8, 3D, 97, 30, 03...
 
[+]

Entropy:
5.7800

Code size:
12.4 MB (13,037,056 bytes)

Remove uplay.exe - Powered by Reason Core Security