alipyinshelper.exe

Alibaba Cloud Computing Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘AliPinYinPreload’.
Publisher:
Alibaba Cloud Computing Ltd  (signed and verified)

MD5:
28a2bf755e64d1eb9e88e3dfd514af68

SHA-1:
ac70a4c7c2450c904d43db2bbd2dc5205dd12965

SHA-256:
058ab23ef34f24328653553e24e098c599ecc723d1f00038cc5ff56a4d477b06

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/16/2025 4:31:37 PM UTC  (today)

File size:
241.9 KB (247,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\alipy\1.0.0.74\alipyinshelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/31/2011 8:00:00 AM

Valid to:
3/31/2012 7:59:59 AM

Subject:
CN=Alibaba Cloud Computing Ltd, OU=OPS, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Alibaba Cloud Computing Ltd, L=HangZhou, S=ZheJiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1C8CB0BE3EC0FB091D7BEB9445935205

File PE Metadata
Compilation timestamp:
7/14/2011 5:18:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:YHCHuahHlW0zmrHpNZP6qbOTkKLS/KLzMk2af7l0tjhy:YiOaljzmrJHbONS/Razchy

Entry address:
0x12734

Entry point:
E8, 57, 87, 00, 00, E9, 17, FE, FF, FF, 8B, 54, 24, 04, 53, 56, 33, F6, 3B, D6, 57, 74, 08, 8B, 5C, 24, 14, 3B, DE, 77, 1B, E8, CA, 26, 00, 00, 6A, 16, 5F, 89, 38, 56, 56, 56, 56, 56, E8, 2C, E5, FF, FF, 83, C4, 14, 8B, C7, EB, 46, 8B, 7C, 24, 18, 3B, FE, 75, 05, 66, 89, 32, EB, D8, 8B, CA, 66, 39, 31, 74, 05, 41, 41, 4B, 75, F6, 3B, DE, 74, EB, 0F, B7, 07, 66, 89, 01, 41, 41, 47, 47, 66, 3B, C6, 74, 03, 4B, 75, EE, 3B, DE, 75, 11, 66, 89, 32, E8, 79, 26, 00, 00, 6A, 22, 59, 89, 08, 8B, F9, EB, AB, 33, C0...
 
[+]

Entropy:
6.3282

Code size:
176 KB (180,224 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AliPinYinPreload

Command:
"C:\Program Files\alipy\1.0.0.74\alipyinshelper.exe" --preload


Scan alipyinshelper.exe - Powered by Reason Core Security