baidutype_setup_light.exe

Baidu IME

Baidu Japan

Publisher:
Baidu Inc.  (signed by Baidu Japan)

Product:
Baidu IME

Description:
BaiduJP IME Updater

Version:
2.4.2.1

MD5:
98eaee186a2402e38e6630d43d84783f

SHA-1:
8a037914a9904a326bcabcc64d38f15f4d4d5a4a

SHA-256:
e45227a4577461fa063cebd35788bcadc02cba86f00862951922a9ae32825beb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:40:48 PM UTC  (today)

File size:
590.2 KB (604,352 bytes)

Product version:
2.4.2.1

Copyright:
Copyright (C) 2011

Original file name:
BaiduJPUpdater

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\baidutype_setup_light.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/7/2011 10:44:18 AM

Valid to:
12/5/2014 6:41:15 PM

Subject:
E=info_jp@baidu.com, CN=Baidu Japan, OU=Business Development, O=Baidu Japan, L="Roppogi Hills Mori tower 20F, 6-10-1,Roppogi,Minato-ku", S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FBE8004EAD7CC599B089A51556C81840

File PE Metadata
Compilation timestamp:
2/16/2012 8:46:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:FwWlO8LqyCRX9rDog9M5GzvhhSu61eCC8O:FwKO8LqrXZog9ThSu6E8O

Entry address:
0x5BDE2

Entry point:
E8, A6, 63, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 28, 5B, 48, 00, E8, 28, 42, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, A4, 09, 49, 00, 03, 75, 43, 6A, 04, E8, 90, 65, 00, 00, 59, 83, 65, FC, 00, 56, E8, B8, 65, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, D9, 65, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 7C, 64, 00, 00, 59, C3, 56, 6A, 00, FF, 35, F4, F2, 48, 00, FF, 15, 60, 42, 47, 00, 85, C0, 75, 16, E8, A1, 42, 00...
 
[+]

Entropy:
6.3104

Code size:
458.5 KB (469,504 bytes)

The file baidutype_setup_light.exe has been seen being distributed by the following URL.

Scan baidutype_setup_light.exe - Powered by Reason Core Security