cloud.exe

云端

ChengDu YunDuan Network Tech Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Publisher:

Product:
云端

Version:
34.0.12.50

MD5:
bd7707cd9df2e0334061c5f3acef72d8

SHA-1:
2dccfb76ae6b6058099593549937cc6bd7d143e5

SHA-256:
c5818c6d6930a4126bfc5cdd1ac85d28c0a3ec774076e81a3a580f1b0852e14a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:28:57 PM UTC  (today)

File size:
5.1 MB (5,358,984 bytes)

Product version:
34.0.12.50

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cloud\cloud.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/20/2011 8:00:00 AM

Valid to:
10/11/2012 7:59:59 AM

Subject:
CN="ChengDu YunDuan Network Tech Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ChengDu YunDuan Network Tech Co., Ltd.", L=chengdu, S=sichuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F629BF7C969CB41DFBCE8782796C87E

File PE Metadata
Compilation timestamp:
3/28/2012 9:25:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:9sX6FzCVq0/1VXtVR/PHj1aullQAwDQX3T3DBn7htf+BacZIIEHpKVxe:9sX6FzCVn/1V9VR/PHj1aullQAwDQnTD

Entry address:
0x3C317A

Entry point:
E8, 1B, 04, 00, 00, E9, 1C, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, D2, 8C, 00, 89, 0D, AC, D2, 8C, 00, 89, 15, A8, D2, 8C, 00, 89, 1D, A4, D2, 8C, 00, 89, 35, A0, D2, 8C, 00, 89, 3D, 9C, D2, 8C, 00, 66, 8C, 15, C8, D2, 8C, 00, 66, 8C, 0D, BC, D2, 8C, 00, 66, 8C, 1D, 98, D2, 8C, 00, 66, 8C, 05, 94, D2, 8C, 00, 66, 8C, 25, 90, D2, 8C, 00, 66, 8C, 2D, 8C, D2, 8C, 00, 9C, 8F, 05, C0, D2, 8C, 00, 8B, 45, 00, A3, B4, D2, 8C, 00, 8B, 45, 04, A3, B8, D2, 8C, 00, 8D, 45, 08, A3, C4, D2, 8C...
 
[+]

Entropy:
5.6353

Code size:
4.1 MB (4,292,608 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\Program Files\cloud\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security