va7etldz.exe

Spotify

Spotify AB

va7etldz.exe.part is part of the Spotify on-demand music streaming service (partial p2p based service). The file has been seen being downloaded from up.br.bav.baidu.com and multiple other hosts.
Publisher:
Spotify Ltd  (signed by Spotify AB)

Product:
Spotify

Description:
SpotifyInstaller

Version:
0,0,0,0

MD5:
bae906c7aaf619aabadb80688ef3ba6a

SHA-1:
82b8b9dfa08e8ac8a396960c7bc8ddde34b752f1

SHA-256:
c4deafc4f380fc07bfd4d83768f5aa935fb8b9be245b932bfcee939806e5eb71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:44:30 PM UTC  (today)

File size:
342.7 KB (350,936 bytes)

Product version:
1.0.27.75.gdc223232

Copyright:
Copyright (c) 2016, Spotify Ltd

Original file name:
SpotifyInstaller.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\va7etldz.exe.part

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
9/16/2014 2:00:00 AM

Valid to:
11/22/2017 1:00:00 PM

Subject:
CN=Spotify AB, O=Spotify AB, L=Stockholm, S=Stockholm, C=SE

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
01454BE484613B4D151F0C63B3439319

File PE Metadata
Compilation timestamp:
4/11/2016 2:44:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:WhinNSdLG7M60m6oekkFhwf345DhRkDmqKhhkqucBnMFoKxjZO6kLSx1dHf:3nEMM+6o2Qg5uZYhkqucBnMFoKxjZO6X

Entry address:
0xBCDD0

Entry point:
60, BE, 00, 90, 48, 00, 8D, BE, 00, 80, F7, FF, C7, 87, 68, 72, 09, 00, A5, A3, 5C, 56, 57, EB, 11, 90, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Code size:
212 KB (217,088 bytes)

The file va7etldz.exe has been seen being distributed by the following 10 URLs.

http://up.br.bav.baidu.com/?rh=80CA9A1657DA5519AB65A18D560DD9EA&baidusign=22519431&baidurand=18918

http://www.tamindir.com/indir/MjAxNi0wNC0yNSAyMDoxNToxNA==/spotify/windows/.../

http://www.tamindir.com/indir/MjAxNS0xMC0wMyAwODozNTo1OA==/spotify/.../1.0.11.134

http://dw.uptodown.com/dwn/_8tv1sE_M-OPnon9y9iQReVwAclHIDhEe_S6wsJ3Xr0cTR3q0icfeCL94JV3gkoxA0MfQBqkI5z75CAqZN0bmqOJb7S-BsDkV61P1sreAGVZ_zIezvqL2Yy1ogQzHJb3/E9F7MABwPQ3KLTc1QcDu6uGDcDlx7-ntwo-amykYsNDueOZtjEXrE2s80AZoBVKEjQ1YPGgt2dxaXVq-xhL0bvhMVDZenC1p0Ju8E9yUhNWcv11NmufaK2ix1LhPvToA/.../

http://dw.uptodown.com/dwn/vVa367O084l2rrkHX-PIAdHyw6LwuwSh195sD8LpnywWeFZxR6PsQ6JU9i5Ue2tmO8Z7gNviFGR_G9iFVuDy46mDGFtQiN8M7ETgkYwzf5vAv9XSytSlEycsudyi-jw2/EMTaxGXHEOO1r-JbJiiFKOdpPhom23Yt69_yRWvqbIc37bbob_8hKf1jBS5zdWw6RPrYUEcI81LojcQCUzepvcIkCtQsbWi7lh5PcLuvz_u8HAhQn-lvsr7QmQe8_nX2/.../