spark_install.exe

Spark

Baidu Online Network Technology (Beijing) Co.,Ltd.

This is a self-extracting archive and installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:

Product:
Spark

Description:
Baidu Browser

Version:
40.16.1000.126

MD5:
cf202a0612befb51c00710eabb6f7225

SHA-1:
5828cd8b5f78354dee720aefe06b67e07c205cde

SHA-256:
b86985e3200844b1519c600b7cec1909fd9f9ed3b4f4111d27ed7b02c44a3ef1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:08:09 PM UTC  (today)

File size:
50.4 MB (52,799,152 bytes)

Product version:
40.16.1000.126

Copyright:
Copyright (c) Baidu Inc.

Original file name:
SparkSetup.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\temp\spark_install.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/24/2015 5:00:00 PM

Valid to:
3/25/2016 4:59:59 PM

Subject:
CN="Baidu Online Network Technology (Beijing) Co.,Ltd.", OU=Baidu security, O="Baidu Online Network Technology (Beijing) Co.,Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5FAEE9E83F32948F3B2040AC6DF0145C

File PE Metadata
Compilation timestamp:
12/18/2013 11:14:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:al3IKjLu48uuknbULw0DbNR3pdvgp5QoF/9wxIMLWSMdJBF3HfiCfIr/2vVhDyN:yPmklK73pdgp5h9wgJNbfIT2vTON

Entry address:
0x5A707

Entry point:
E8, A4, 81, 00, 00, E9, 89, FE, FF, FF, 6A, 00, FF, 15, 7C, 2B, 78, 00, C3, FF, 15, 68, 2B, 78, 00, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, FF, 35, 30, 6C, 4A, 00, FF, 15, 64, 2B, 78, 00, FF, D0, 5D, C2, 04, 00, A1, 2C, 6C, 4A, 00, C3, 8B, FF, 56, FF, 35, 30, 6C, 4A, 00, FF, 15, 64, 2B, 78, 00, 8B, F0, 85, F6, 75, 1B, FF, 35, BC, 77, 76, 00, FF, 15, 80, 2B, 78, 00, 8B, F0, 56, FF, 35, 30, 6C, 4A, 00, FF, 15, 60, 2B, 78, 00, 8B, C6, 5E, C3, 8B, FF, 55, 8B, EC, FF, 75, 0C, FF, 75, 08, FF, 35, C0, 77, 76...
 
[+]

Entropy:
7.9977  (probably packed)

Code size:
550.5 KB (563,712 bytes)

The file spark_install.exe has been seen being distributed by the following 32 URLs.

https://dw.uptodown.com/dwn/LwQQe_lVoEC4cgeSde_DY62-q5RTIF6e-_rTVxabKaIm7mmxqB808V752tS5-onoq2TjX-ct4Rh1bbogCCP19162TO1mGeNiKXQI7JIRuYVjMUAziHVpbwXjsfku_2zR/npvrKReSEMBgrJeZylMucyEOB5iuudvITgJjqPxL555JRlkISL0eV91Rdl3YTub-iR9QvISd-myh-fZSY2zIkdVnNUMQPEj-l1WTHHqnzZfZXDYYpY1bj9iRr8mtAR8a/b4jRX7JHmkX-RMIWGB6giiFsV8nGfoZ2U0ycWpvtVaA4J1oouzB2qcgbq9nGktV7FAMlkBOuKNQqblKUfOvOyO-1GHX4QPrGHcA9lld6QCmOGpTsNOwOK_bwIlujmVn4/.../

https://docs.google.com/uc?export=download&confirm=mbKW&id=0Bz12HtjL1N9YeXpIZGd2RUpFZ28

http://dw.ar.uptodown.com/dl/1435448971/.../baidu-spark-browser-40-16-1000-126-multi-win.exe

temp:Spark_Setup_all.exe

https://dw.uptodown.com/dwn/fABOMha-tx46JbshQlNzkZeqaHrrIBy6P2pPfomBkqHQFd2WoePj6DX43ml4iFOfd1rrjHZ3Z1gvFiv7WoHNRKe5IM8PgPYfv3wTX8mstPVyeM4l95mdc697rJTyJKbE/gQ1kJNSPWt0-7RVZfzzTFRqtNXsMQK2E_gD5voluiQsLZxSFGXc3NznsxDmh_nEHgChQYYXeXqA2ErW26pce_obHRBCJkSDs2piCGLq9mDRWi7luZBk9nJgV7N-bMLY8/UcqIhWxMDlVDSrlaXsLME36O80ArH6wLamTlhAVSfrntavT1NU7IIOaYEyt28KFndLo_QvMaROmBna9iDaxu2weOnpoDrQIJIJF6Q0iJ_KNXfwSut7cHhIWdnOwoujTa/.../

https://docs.google.com/uc?export=download&confirm=LPg9&id=0Bz12HtjL1N9YeXpIZGd2RUpFZ28

http://dw.ar.uptodown.com/dl/1431820269/.../baidu-spark-browser-40-16-1000-126-multi-win.exe

http://dw2.ar.uptodown.com/dw/1435862037/.../baidu-spark-browser-40-16-1000-126-multi-win.exe

http://dw.ar.uptodown.com/dl/1439672732/.../baidu-spark-browser-40-16-1000-126-multi-win.exe

http://share2.earthlinktele.com/download.aspx?file=672495994

https://dw.uptodown.com/dwn/Z5Pa_dHUv7vT8usBKqbuQUFtg0ocaokXPso-lGC_MLRAEKlQKjum3xlMl1zAVDqysi-Ni3rs5VZrLs9hXjPZmxhTq_6uIJjTNsv15kKkaP6dl1PIr_7d5bgZPa4Jo_6J/qzbDMAS3SEF2KAAjjg7imo97v3wlgroKQw4iH_iljpb2ph0uPKXObAEBJSnDQ6MSHvENT-dT_2Dier6AbmXyq1D-JG8c8D2s08Iaj1mserGy_3IoevMHs5v6fQLtxRli/5MPb5B41hLB44Wlt2qMTPCjexMdwSn8-VxtHiNZnDbDIb6CGbNU9Ge0Ebkb0tBwLmJtutFmD_mke8I_Sk4XMSglxeyNXG4KKFgbavdjGwkpOdd6kAeAXrWsQldBzkZBS/.../

temp:baidu-spark-browser-40-16-1000-126-multi-win.exe

Latest 30 of 32 download URLs

Scan spark_install.exe - Powered by Reason Core Security