cloud.exe

云端

Shanghai Holdfast Online Information Technology Co. Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Product:
云端

Version:
34.12.5.14

MD5:
995ec76fcd3ebe5c743f66336143ab39

SHA-1:
43b0208df7cd47732f7f0222ab3b8263d04a832f

SHA-256:
b01cbfc574db4a078a9662f3f63f556769e707cbf2cfebd775d91f7eed19ea72

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:27:46 PM UTC  (today)

File size:
4 MB (4,237,808 bytes)

Product version:
34.12.5.14

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\cloud\cloud.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/9/2010 8:00:00 AM

Valid to:
9/7/2013 7:59:59 AM

Subject:
CN=Shanghai Holdfast Online Information Technology Co. Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Shanghai Holdfast Online Information Technology Co. Ltd., L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32DFBEB9914DE39E73A0E7B35976D09E

File PE Metadata
Compilation timestamp:
5/14/2012 1:15:13 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:gyDtwPhYutflKAQ8370iG7vZFn9+Y3XAphyo1mrq7tTkL8pnLCD2hN1H/5iVUe0:DDtw5YutflKLq70iG7vZFn9+Y3XApUSP

Entry address:
0x2F19EA

Entry point:
E8, 1B, 04, 00, 00, E9, 1C, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, E0, EE, 7C, 00, 89, 0D, DC, EE, 7C, 00, 89, 15, D8, EE, 7C, 00, 89, 1D, D4, EE, 7C, 00, 89, 35, D0, EE, 7C, 00, 89, 3D, CC, EE, 7C, 00, 66, 8C, 15, F8, EE, 7C, 00, 66, 8C, 0D, EC, EE, 7C, 00, 66, 8C, 1D, C8, EE, 7C, 00, 66, 8C, 05, C4, EE, 7C, 00, 66, 8C, 25, C0, EE, 7C, 00, 66, 8C, 2D, BC, EE, 7C, 00, 9C, 8F, 05, F0, EE, 7C, 00, 8B, 45, 00, A3, E4, EE, 7C, 00, 8B, 45, 04, A3, E8, EE, 7C, 00, 8D, 45, 08, A3, F4, EE, 7C...
 
[+]

Entropy:
6.2200

Code size:
3.2 MB (3,359,232 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\Program Files\cloud\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security