cloud.exe

云端

Cheng Du YunDuan Network Tech.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cloud.exe’.
Publisher:
Cheng Du YunDuan Network Tech.,Ltd  (signed and verified)

Product:
云端

Version:
10, 10, 5, 31

MD5:
6169a0bc8dbb0136d3d0f63a1e27a69f

SHA-1:
c80dfa1d06ccc6b5b95141dee8f011310d619a2d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:18:15 PM UTC  (today)

File size:
6.8 MB (7,168,112 bytes)

Product version:
10, 10, 5, 31

Copyright:
版权所有 (C) 成都云端网络技术有限公司

Original file name:
cloud

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/13/2009 12:52:41 PM

Valid to:
10/13/2010 12:52:41 PM

Subject:
CN="Cheng Du YunDuan Network Tech.,Ltd", O="Cheng Du YunDuan Network Tech.,Ltd", C=CN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001244C60A585

File PE Metadata
Compilation timestamp:
5/31/2010 7:18:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:lM4/wcnnWaygkny9ZRC+4TQCOUiIiWYZrlwvKMaO13wVus+YpTSKXtjec:hw8GevCdOUiIiWYXwvKMaOdwVaKBec

Entry address:
0x17DA3E

Entry point:
55, 8B, EC, 6A, FF, 68, 60, 78, 5B, 00, 68, 9C, DB, 57, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 54, 6C, 5A, 00, 59, 83, 0D, 40, 02, 60, 00, FF, 83, 0D, 44, 02, 60, 00, FF, FF, 15, 58, 6C, 5A, 00, 8B, 0D, 34, 02, 60, 00, 89, 08, FF, 15, 5C, 6C, 5A, 00, 8B, 0D, 30, 02, 60, 00, 89, 08, A1, 60, 6C, 5A, 00, 8B, 00, A3, 3C, 02, 60, 00, E8, 40, 01, 00, 00, 39, 1D, 08, 1F, 5F, 00, 75, 0C, 68, EA, DB, 57, 00, FF, 15, 64, 6C...
 
[+]

Entropy:
6.8608

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
1.6 MB (1,724,416 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cloud.exe

Command:
"C:\cloud\cloud1.0_beta2_jfsky\cloud.exe" "min"


Scan cloud.exe - Powered by Reason Core Security