cloud.exe

云端

ChengDu YunDuan Network Tech Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Publisher:

Product:
云端

Version:
10, 10, 9, 30

MD5:
f78d8fdc5787b35cc2dddf3e42f250c4

SHA-1:
1c2130b6d538485662a0b659c46b7f9bc231101a

SHA-256:
852ed5920b9d8f555e8d500c4383b47d1b57e668f7828a7669990dc47ad9d375

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 11:11:26 PM UTC  (a few moments ago)

File size:
7.8 MB (8,168,328 bytes)

Product version:
10, 10, 9, 30

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cloud\cloud.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/20/2011 8:00:00 AM

Valid to:
10/11/2012 7:59:59 AM

Subject:
CN="ChengDu YunDuan Network Tech Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ChengDu YunDuan Network Tech Co., Ltd.", L=chengdu, S=sichuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F629BF7C969CB41DFBCE8782796C87E

File PE Metadata
Compilation timestamp:
3/14/2012 3:50:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:VmU8Pq5u79tnsvCMQOUiIiWYXwvK7aOdwVaKcne:QU897bsvqOUiIiWYXwvKNK7

Entry address:
0x1D3154

Entry point:
55, 8B, EC, 6A, FF, 68, B8, A1, 61, 00, 68, BE, 32, 5D, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 9C, 6D, 60, 00, 59, 83, 0D, 80, F6, 66, 00, FF, 83, 0D, 84, F6, 66, 00, FF, FF, 15, 98, 6D, 60, 00, 8B, 0D, 60, F6, 66, 00, 89, 08, FF, 15, 94, 6D, 60, 00, 8B, 0D, 5C, F6, 66, 00, 89, 08, A1, 90, 6D, 60, 00, 8B, 00, A3, 7C, F6, 66, 00, E8, 40, 01, 00, 00, 39, 1D, 20, 0E, 66, 00, 75, 0C, 68, 00, 33, 5D, 00, FF, 15, 8C, 6D...
 
[+]

Entropy:
6.8454

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2 MB (2,117,632 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\Program Files\cloud\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security