alipserver_w32.exe

pserver_ 应用程序

Alibaba Cloud Computing Ltd

Publisher:
Alibaba Cloud Computing Ltd  (signed and verified)

Product:
pserver_ 应用程序

Version:
2, 5, 4, 3340

MD5:
19e276d3984dd4a5e26b8b1b484e2cfe

SHA-1:
8b39e4abc1e26aaf32f497008a2426103f8c0e3c

SHA-256:
1b2296015f9726f053cb0cf800f0b3963a081fc1e7e6912faf120fe5e36c0d3a

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 12:14:52 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably DLOADER.Trojan
9.0.1.05190

File size:
127.4 KB (130,408 bytes)

Product version:
2, 5, 4, 3340

Copyright:
Copyright (C) 2013

Original file name:
pserver_.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\yunos\zhushou\2.5.4.3341\alipserver_w32.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/1/2013 8:00:00 AM

Valid to:
6/1/2014 7:59:59 AM

Subject:
CN=Alibaba Cloud Computing Ltd, OU=Information Security Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Alibaba Cloud Computing Ltd, L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4A89AF78347AA91378B2A95A17084B44

File PE Metadata
Compilation timestamp:
12/20/2013 12:04:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:gL8b0QeDCeYMTRfRuiJP1lB31SsLDqO69d:q8b0vCeZTFRTJhgKDqO6D

Entry address:
0x18D73

Entry point:
E8, 16, 05, 00, 00, E9, D7, FC, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, A9, 42, 00, 89, 0D, AC, A9, 42, 00, 89, 15, A8, A9, 42, 00, 89, 1D, A4, A9, 42, 00, 89, 35, A0, A9, 42, 00, 89, 3D, 9C, A9, 42, 00, 66, 8C, 15, C8, A9, 42, 00, 66, 8C, 0D, BC, A9, 42, 00, 66, 8C, 1D, 98, A9, 42, 00, 66, 8C, 05, 94, A9, 42, 00, 66, 8C, 25, 90, A9, 42, 00, 66, 8C, 2D, 8C, A9, 42, 00, 9C, 8F, 05, C0, A9, 42, 00, 8B, 45, 00, A3, B4, A9, 42, 00, 8B, 45, 04, A3, B8, A9, 42, 00, 8D, 45, 08, A3, C4, A9, 42...
 
[+]

Entropy:
6.3826

Code size:
98.5 KB (100,864 bytes)

Windows Firewall Allowed Program
Name:
alipserver_w32


Scan alipserver_w32.exe - Powered by Reason Core Security