TudouReporter.exe

Tudou.com

Shanghai Quan Tudou Network Technology Co., Ltd.

Publisher:
土豆网  (signed by Shanghai Quan Tudou Network Technology Co., Ltd.)

Product:
Tudou.com

Version:
1.0.0.1

MD5:
6764f702acd9bad253afb29612549171

SHA-1:
efb0ab7f13c27ea4bc6235a7e7e2703ac07c3bd2

SHA-256:
a8fe3ed9ead69c869b0e6e90cd5975f283e4a00572d95a0dde3df07346558dc5

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 7:08:58 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
TrojanDownloader.Agent
3.12.24.3

File size:
401.4 KB (411,072 bytes)

Product version:
1.0.0.1

Copyright:
土豆网 2005-2010。保留所有权利。

Original file name:
TudouReporter.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\tudou\feisu\update_backup\tudoureporter.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/12/2011 8:00:00 AM

Valid to:
6/11/2012 7:59:59 AM

Subject:
CN="Shanghai Quan Tudou Network Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shanghai Quan Tudou Network Technology Co., Ltd.", L="Shanghai ", S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
543BB553D7EA548AF55E0B75804AEE1D

File PE Metadata
Compilation timestamp:
11/17/2011 2:06:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:IgvMiCvzYhCHBJ4xoa34+9OY5CkTECrCybGi59P+N7a8cxZ0J5cisiEPU:BvMiCvUsI41Y5jTEaCyzG7wxSJ5cYEPU

Entry address:
0x27F86

Entry point:
E8, 59, 74, 00, 00, E9, 17, FE, FF, FF, 51, C7, 01, 34, 9B, 44, 00, E8, DC, 74, 00, 00, 59, C3, 56, 8B, F1, E8, EA, FF, FF, FF, F6, 44, 24, 08, 01, 74, 07, 56, E8, 9B, 52, FE, FF, 59, 8B, C6, 5E, C2, 04, 00, 8B, 44, 24, 04, 83, C1, 09, 51, 83, C0, 09, 50, E8, 25, 75, 00, 00, F7, D8, 59, 1B, C0, 59, 40, C2, 04, 00, 3B, 0D, 68, 77, 45, 00, 75, 02, F3, C3, E9, 94, 75, 00, 00, 51, 53, 55, 56, 57, FF, 35, A8, CD, 45, 00, E8, C5, 6D, 00, 00, FF, 35, A4, CD, 45, 00, 8B, F0, 89, 74, 24, 18, E8, B4, 6D, 00, 00, 8B...
 
[+]

Entropy:
6.4440

Code size:
276 KB (282,624 bytes)

Scan TudouReporter.exe - Powered by Reason Core Security