baidutype_setup_light.exe

Baidu IME

Baidu Japan

Publisher:
Baidu Inc.  (signed by Baidu Japan)

Product:
Baidu IME

Description:
BaiduJP IME Updater

Version:
2.4.0.19

MD5:
8de9437dc0d87ca167385faa4719852f

SHA-1:
1cd2de9a51c469da46dfa7e35705403c5a3e60c6

SHA-256:
ff1bf739f2424094715ea5b2998525968ca54c134964d7d09c3ab084cbf77600

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:25:12 AM UTC  (today)

File size:
590.2 KB (604,352 bytes)

Product version:
2.4.0.19

Copyright:
Copyright (C) 2011

Original file name:
BaiduJPUpdater

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\baidutype_setup_light.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/7/2011 10:44:18 AM

Valid to:
12/5/2014 6:41:15 PM

Subject:
E=info_jp@baidu.com, CN=Baidu Japan, OU=Business Development, O=Baidu Japan, L="Roppogi Hills Mori tower 20F, 6-10-1,Roppogi,Minato-ku", S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FBE8004EAD7CC599B089A51556C81840

File PE Metadata
Compilation timestamp:
2/17/2012 12:37:41 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:5ufUwcqqyiRq9vJdY7LjGHDhhVjX+AaEW9:5uswcqqLq3dY7YhVjX9W9

Entry address:
0x5BDE2

Entry point:
E8, A6, 63, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 48, 5B, 48, 00, E8, 28, 42, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, A4, 09, 49, 00, 03, 75, 43, 6A, 04, E8, 90, 65, 00, 00, 59, 83, 65, FC, 00, 56, E8, B8, 65, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, D9, 65, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 7C, 64, 00, 00, 59, C3, 56, 6A, 00, FF, 35, F4, F2, 48, 00, FF, 15, 60, 42, 47, 00, 85, C0, 75, 16, E8, A1, 42, 00...
 
[+]

Entropy:
6.3098

Code size:
458.5 KB (469,504 bytes)

The file baidutype_setup_light.exe has been seen being distributed by the following URL.

Scan baidutype_setup_light.exe - Powered by Reason Core Security