upservice.exe

UPSecurityInputService

China UnionPay Co.,Ltd.

It runs as a separate (within the context of its own process) windows Service named “UPSecurityInputService”.
Publisher:
中国银联股份有限公司  (signed by China UnionPay Co.,Ltd.)

Product:
UPSecurityInputService

Version:
1.0.0.1

MD5:
b082c6b7a13ba376f06b9c10031d6b25

SHA-1:
2a46248308500953ac3508ba076bd567c9563458

SHA-256:
99df6418ff0782eb4f9eb95d9ab62034ae45f7f87ba151d3487f39909cd765bc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/12/2025 9:35:14 PM UTC  (today)

File size:
352.8 KB (361,240 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2015

Original file name:
UPSecurityInputService

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\upeditnew\upservice.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/8/2015 8:00:00 AM

Valid to:
7/8/2018 7:59:59 AM

Subject:
CN="China UnionPay Co.,Ltd.", OU=product innovation, O="China UnionPay Co.,Ltd.", L=shanghai, S=shanghai, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1F5E46E3B8C0B8C33918E7CB4BE3A31D

File PE Metadata
Compilation timestamp:
3/16/2016 4:39:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:h/8Ol1+yixs+jMBSgY4mQMlq9d1gt3HlKLaI+MxZrAzxTZ6JFdWAoO5hZgkw:h/prTi9YG4mQN9dOt3lKLsMnAdZ6JiAy

Entry address:
0xA80D8

Entry point:
E8, 97, 8A, FB, FF, 29, 8F, A4, 84, EB, 2E, F4, 66, 4D, AB, 70, 28, 5B, CD, 43, 1A, 01, 57, D5, FE, B0, 97, 31, 16, 97, 0E, 7D, EE, 16, FD, CB, BB, 9D, 33, 11, 1F, 75, 4D, 68, 4F, C9, F5, DC, 0C, CA, 2E, ED, EB, 08, 70, 0B, DD, 5B, B0, 42, 06, 59, 6F, 50, 38, 57, E1, 07, 31, A2, A1, D1, EB, 0A, 30, 88, 3A, F0, 78, 02, C6, BA, BE, D0, 28, 06, 05, 00, D8, B3, 95, 8B, 5D, AC, 7C, BD, CB, D7, 91, D8, 20, C3, 96, 22, 06, E6, EA, 2E, F4, 28, DE, 8A, DD, 8B, AB, 2D, C6, 82, AC, FC, 6A, 7E, 89, 82, 70, B8, 7F, 19...
 
[+]

Entropy:
7.9069  (probably packed)

Code size:
113.5 KB (116,224 bytes)

Service
Display name:
UPSecurityInputService

Type:
Win32OwnProcess


Scan upservice.exe - Powered by Reason Core Security