cloud.exe

云端

Cheng Du YunDuan Network Tech.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Publisher:
Cheng Du YunDuan Network Tech.,Ltd  (signed and verified)

Product:
云端

Version:
10, 10, 4, 30

MD5:
91358b450eab11367b7dd064688f3854

SHA-1:
250ad706831069a4de4be05de131bd547928e3ad

SHA-256:
e456d20d0f82430adbdce892334f07b0e818bb684e6c14e14800148b00016438

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:30:18 PM UTC  (today)

File size:
6.7 MB (7,004,272 bytes)

Product version:
10, 10, 4, 30

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/13/2009 12:52:41 PM

Valid to:
10/13/2010 12:52:41 PM

Subject:
CN="Cheng Du YunDuan Network Tech.,Ltd", O="Cheng Du YunDuan Network Tech.,Ltd", C=CN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001244C60A585

File PE Metadata
Compilation timestamp:
4/30/2010 1:50:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:+bvzr6jJfZYxKfUCNOUiIiWYXwvKMaOdwVpKq8:GvzrYJfoGOUiIiWYXwvKjKx

Entry address:
0x172E0E

Entry point:
55, 8B, EC, 6A, FF, 68, A8, B3, 5A, 00, 68, 6C, 2F, 57, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 48, AC, 59, 00, 59, 83, 0D, D8, 2A, 5F, 00, FF, 83, 0D, DC, 2A, 5F, 00, FF, FF, 15, 4C, AC, 59, 00, 8B, 0D, CC, 2A, 5F, 00, 89, 08, FF, 15, 50, AC, 59, 00, 8B, 0D, C8, 2A, 5F, 00, 89, 08, A1, 54, AC, 59, 00, 8B, 00, A3, D4, 2A, 5F, 00, E8, 40, 01, 00, 00, 39, 1D, 38, 48, 5E, 00, 75, 0C, 68, BA, 2F, 57, 00, FF, 15, 58, AC...
 
[+]

Entropy:
6.8520

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
1.6 MB (1,675,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\cloud1.0_beta2_0430\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security