cloudpop.exe

Qzoneinteractive

The application cloudpop.exe by Qzoneinteractive has been detected as a potentially unwanted program by 20 anti-malware scanners.
Publisher:
Qzoneinteractive  (signed and verified)

MD5:
dead6a3fcd343d016db2c290d7f677f6

SHA-1:
ea515a058580af8e35ee7aa720a046896e8f4bce

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 5:41:32 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Adware
7.1.1

AhnLab V3 Security
PUP/Win32.CloudPop
2014.06.15

Avira AntiVirus
TR/Spy.Banker.Gen
7.11.154.230

avast!
Win32:Adware-AVB [Adw]
2014.9-150422

AVG
Win32/DH{gQwuICQiJS17gRI}
2016.0.3131

Baidu Antivirus
Adware.Win32.Kraddare
4.0.3.15422

Bkav FE
W32.Clodef6.Trojan
1.3.0.4959

Comodo Security
TrojWare.Win32.Agent.~tgr
18545

ESET NOD32
Win32/Adware.Kraddare
9.9945

Fortinet FortiGate
Riskware/Kraddare
4/22/2015

IKARUS anti.virus
Trojan-Spy.Banker
t3scan.1.6.1.0

Malwarebytes
Trojan.Banker
v2015.04.22.01

McAfee
GenericTRA-AF!DEAD6A3FCD34
5600.6787

Panda Antivirus
Trj/CI.A
15.04.22.01

Rising Antivirus
PE:Trojan.Win32.Generic.12B53A52!313866834
23.00.65.15420

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
ADW_KRADDARE
7.2.112

Trend Micro
ADW_KRADDARE
10.465.22

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
30284

File size:
835.4 KB (855,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cloudpop\cloudpop.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/14/2011 9:00:00 AM

Valid to:
11/14/2012 8:59:59 AM

Subject:
CN=Qzoneinteractive, OU=EC Team, O=Qzoneinteractive, L=Gwangjin-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
51790DE8CFF3FB8E48D3E671F9021D0B

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:zDDpdLIEpQIv5IEWJDfkvDBU/WG/ccLhaoYd2ZsNXoaxnQM9rYP5J6:1dcEpQNEWJD4DcWYccLhaokqIoqBYP36

Entry address:
0xB0DD4

Entry point:
55, 8B, EC, 83, C4, E8, 53, 33, C0, 89, 45, EC, 89, 45, E8, B8, 84, 07, 4B, 00, E8, 97, 56, F5, FF, 33, C0, 55, 68, 88, 0E, 4B, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, A1, 60, 4A, 4B, 00, 8B, 00, E8, C2, B7, FA, FF, 8B, 45, E8, 8D, 55, EC, E8, 3B, 84, F5, FF, 8B, 45, EC, E8, 0F, 39, F5, FF, 50, 6A, FF, 6A, 00, E8, B1, 58, F5, FF, 8B, D8, E8, A2, 59, F5, FF, 3D, B7, 00, 00, 00, 75, 08, 53, E8, AD, 5A, F5, FF, EB, 30, A1, 60, 4A, 4B, 00, 8B, 00, E8, DB, B0, FA, FF, 8B, 0D, 00, 48, 4B, 00, A1, 60, 4A, 4B, 00...
 
[+]

Entropy:
6.6058

Developed / compiled with:
Microsoft Visual C++

Code size:
704 KB (720,896 bytes)

Remove cloudpop.exe - Powered by Reason Core Security