baidutype_setup_light.exe

Baidu IME

Baidu Japan

Publisher:
Baidu Inc.  (signed by Baidu Japan)

Product:
Baidu IME

Description:
BaiduJP IME Updater

Version:
3.3.2.16

MD5:
1837f6b91bec31e7a62225f3861dac90

SHA-1:
ee756065ae7b63389e82037206cf84afb67714e9

SHA-256:
ce16a5238ef72e7ea3ec8660b6392517d966e04173437000ef894ec2b242f55f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 3:35:49 AM UTC  (today)

File size:
629.7 KB (644,784 bytes)

Product version:
3.3.2.16

Copyright:
Copyright (C) 2011

Original file name:
BaiduJPUpdater

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/7/2011 10:44:18 AM

Valid to:
12/5/2014 6:41:15 PM

Subject:
E=info_jp@baidu.com, CN=Baidu Japan, OU=Business Development, O=Baidu Japan, L="Roppogi Hills Mori tower 20F, 6-10-1,Roppogi,Minato-ku", S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FBE8004EAD7CC599B089A51556C81840

File PE Metadata
Compilation timestamp:
6/19/2013 2:58:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:8GtfpMy+G+cr5t4zpZDzoze7E97xfJkkBxhgvghGSOoTao4G:JxP+G+cr5mzpBU97BxhgvfaTaJG

Entry address:
0x554FF

Entry point:
E8, 69, 83, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 90, 0E, 49, 00, E8, DB, 4D, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, 84, F7, 49, 00, 03, 75, 43, 6A, 04, E8, 53, 85, 00, 00, 59, 83, 65, FC, 00, 56, E8, 7B, 85, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 9C, 85, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 3F, 84, 00, 00, 59, C3, 56, 6A, 00, FF, 35, A4, C8, 49, 00, FF, 15, 8C, 72, 47, 00, 85, C0, 75, 16, E8, 42, 4E, 00...
 
[+]

Entropy:
6.4491

Code size:
471.5 KB (482,816 bytes)

The file baidutype_setup_light.exe has been seen being distributed by the following 2 URLs.

http://download.ime.baidu.jp/BaiduType_Setup_Light.exe

Scan baidutype_setup_light.exe - Powered by Reason Core Security