liuliangbao

liuliangbao

Hangzhou Yunbao Network&Technology Co.,Ltd

Publisher:
www.liuliangbao.cn  (signed by Hangzhou Yunbao Network&Technology Co.,Ltd)

Product:
liuliangbao

Description:
流量宝沙盒模块进程

Version:


MD5:
5903705cf722f29a95fbe91f12ee0b73

SHA-1:
4b361c8c106f37e8d2221da8769a650d6b01bf9a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 4:09:55 PM UTC  (today)

File size:
389.1 KB (398,432 bytes)

Product version:


Copyright:
版权所有 (C) 2011

Original file name:
liuliangbao

Common path:
C:\Documents and Settings\{user}\Application data\liuliangbaogp\liuliangbao

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/14/2012 8:00:00 AM

Valid to:
6/15/2013 7:59:59 AM

Subject:
CN="Hangzhou Yunbao Network&Technology Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Hangzhou Yunbao Network&Technology Co.,Ltd", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
20A8A051262352A8DD384AEAB5155BB6

File PE Metadata
Compilation timestamp:
9/26/2012 3:01:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:KIIc7H1RzMmMfhPF52cUI/tgz44eeS8ziZHdLyx12E65r71nSvvuYrT:KSeHg8lUez8ziZ9+x12EQJmT

Entry address:
0x2DF2F

Entry point:
E8, CB, 72, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 68, FC, 86, 44, 00, FF, 15, 60, 30, 44, 00, 85, C0, 74, 15, 68, EC, 86, 44, 00, 50, FF, 15, E4, 31, 44, 00, 85, C0, 74, 05, FF, 75, 08, FF, D0, 5D, C3, 8B, FF, 55, 8B, EC, FF, 75, 08, E8, C8, FF, FF, FF, 59, FF, 75, 08, FF, 15, 60, 31, 44, 00, CC, 6A, 08, E8, 91, 74, 00, 00, 59, C3, 6A, 08, E8, AF, 73, 00, 00, 59, C3, 8B, FF, 56, E8, 44, 50, 00, 00, 8B, F0, 56, E8, 05, 50, 00, 00, 56, E8, 36, 32, 00, 00, 56, E8, 4C, 59, 00, 00, 56, E8, 9C, 76, 00...
 
[+]

Entropy:
6.4584

Code size:
261.5 KB (267,776 bytes)

Scan liuliangbao - Powered by Reason Core Security