cloud.exe

云端

ChengDu YunDuan Network Tech Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Publisher:

Product:
云端

Version:
10, 10, 9, 21

MD5:
0aa32745ecc785a8177c5c0b8745a3da

SHA-1:
a91074e47697a26fc5d169e8906c5fec2598b8d4

SHA-256:
3677c732de01e51d31fa5819aa3075753a5b561e0fa41a2a73359b232b54a94d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 3:11:37 AM UTC  (today)

File size:
7.8 MB (8,158,272 bytes)

Product version:
10, 10, 9, 21

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cloud\cloud.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/20/2011 9:00:00 AM

Valid to:
10/11/2012 8:59:59 AM

Subject:
CN="ChengDu YunDuan Network Tech Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ChengDu YunDuan Network Tech Co., Ltd.", L=chengdu, S=sichuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F629BF7C969CB41DFBCE8782796C87E

File PE Metadata
Compilation timestamp:
2/23/2012 5:33:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1D08F4

Entry point:
55, 8B, EC, 6A, FF, 68, 38, 70, 61, 00, 68, 5E, 0A, 5D, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 98, 3D, 60, 00, 59, 83, 0D, 30, C5, 66, 00, FF, 83, 0D, 34, C5, 66, 00, FF, FF, 15, 94, 3D, 60, 00, 8B, 0D, 10, C5, 66, 00, 89, 08, FF, 15, 90, 3D, 60, 00, 8B, 0D, 0C, C5, 66, 00, 89, 08, A1, 8C, 3D, 60, 00, 8B, 00, A3, 2C, C5, 66, 00, E8, 40, 01, 00, 00, 39, 1D, D0, DC, 65, 00, 75, 0C, 68, A0, 0A, 5D, 00, FF, 15, 88, 3D...
 
[+]

Entropy:
6.8423

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2 MB (2,105,344 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\Program Files\cloud\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security