baidutype_setup_light.exe

Baidu IME

Baidu Japan

Publisher:
Baidu Inc.  (signed by Baidu Japan)

Product:
Baidu IME

Description:
BaiduJP IME Updater

Version:
3.0.1.4

MD5:
602cfbd197ab6d73a8c303daec4c73be

SHA-1:
5c726415aaf5508e221bd03231bd5612ccc1894e

SHA-256:
fc586dc722bc24c72b268bdfb4dd44eeebacb609b360c06616b37b1c43238867

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:33:45 AM UTC  (today)

File size:
706.7 KB (723,648 bytes)

Product version:
3.0.1.4

Copyright:
Copyright (C) 2011

Original file name:
BaiduJPUpdater

File type:
Executable application (Win32 EXE)

Language:
Japanese (Japan)

Common path:
C:\users\{user}\downloads\baidutype_setup_light.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/7/2011 10:44:18 AM

Valid to:
12/5/2014 6:41:15 PM

Subject:
E=info_jp@baidu.com, CN=Baidu Japan, OU=Business Development, O=Baidu Japan, L="Roppogi Hills Mori tower 20F, 6-10-1,Roppogi,Minato-ku", S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FBE8004EAD7CC599B089A51556C81840

File PE Metadata
Compilation timestamp:
10/18/2012 9:10:09 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:pkNr6N+zk8qHY3vwQVOHr9hU4zg6VWPUx6Sju0F95rZotJgc5lFz2SDzoD:8eww4Il+5PUx6QrrZotTgSXoD

Entry address:
0x6634C

Entry point:
E8, 4E, 7F, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 20, 3F, 4A, 00, E8, BE, 48, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, 64, 35, 4B, 00, 03, 75, 43, 6A, 04, E8, 38, 81, 00, 00, 59, 83, 65, FC, 00, 56, E8, 60, 81, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 81, 81, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 24, 80, 00, 00, 59, C3, 56, 6A, 00, FF, 35, AC, 08, 4B, 00, FF, 15, 7C, A2, 48, 00, 85, C0, 75, 16, E8, 44, 49, 00...
 
[+]

Entropy:
6.4394

Code size:
544.5 KB (557,568 bytes)

The file baidutype_setup_light.exe has been seen being distributed by the following 2 URLs.

Scan baidutype_setup_light.exe - Powered by Reason Core Security