cloud.exe

云端

Cheng Du YunDuan Network Tech.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Publisher:
Cheng Du YunDuan Network Tech.,Ltd  (signed and verified)

Product:
云端

Version:
10, 10, 9, 21

MD5:
f11ec497e0782a976f26eaff052f132d

SHA-1:
55e55e8dda653fb0fb14aaf2580eacf85d051470

SHA-256:
600bb7989e0c4eda668cc164c3c2c0ac985682fd4992b2089c79a787c012cca5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:46:24 AM UTC  (today)

File size:
7.7 MB (8,118,384 bytes)

Product version:
10, 10, 9, 21

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cloud\cloud.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/13/2009 12:52:41 PM

Valid to:
10/13/2010 12:52:41 PM

Subject:
CN="Cheng Du YunDuan Network Tech.,Ltd", O="Cheng Du YunDuan Network Tech.,Ltd", C=CN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001244C60A585

File PE Metadata
Compilation timestamp:
9/21/2010 2:37:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:HT+B38NDf8Rs9N9GpoZCMuOUiIiWYXwvK7aOdwVaKcreZ:HTnf8Rs4poZAOUiIiWYXwvKNKXZ

Entry address:
0x1C8524

Entry point:
55, 8B, EC, 6A, FF, 68, A0, DD, 60, 00, 68, 8E, 86, 5C, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, FC, AC, 5F, 00, 59, 83, 0D, 58, 1E, 66, 00, FF, 83, 0D, 5C, 1E, 66, 00, FF, FF, 15, 00, AD, 5F, 00, 8B, 0D, 38, 1E, 66, 00, 89, 08, FF, 15, 04, AD, 5F, 00, 8B, 0D, 34, 1E, 66, 00, 89, 08, A1, 08, AD, 5F, 00, 8B, 00, A3, 54, 1E, 66, 00, E8, 40, 01, 00, 00, 39, 1D, 90, 36, 65, 00, 75, 0C, 68, D0, 86, 5C, 00, FF, 15, 0C, AD...
 
[+]

Entropy:
6.8411

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2 MB (2,068,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\Program Files\cloud\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security