流量宝流量版.exe

liuliangbao

Hangzhou Yunbao Network&Technology Co.,Ltd

Publisher:
www.liuliangbao.cn  (signed by Hangzhou Yunbao Network&Technology Co.,Ltd)

Product:
liuliangbao

Description:
流量宝流量版

Version:
2.3

MD5:
911e5e35cca2ee57d517e92a60de74ba

SHA-1:
e97bf4bd38fb45f345266bf18fd7fe8f619fd423

SHA-256:
9442123103d51d848214db5a52a3fa9c0c045c319471d886620db399e73c26b9

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/25/2024 9:54:16 PM UTC  (today)

Scan engine
Detection
Engine version

G Data
Win32.Application.Liuliangbao
16.3.25

IKARUS anti.virus
PUA.Liuliangbao
t3scan.2.0.9.0

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1120

File size:
1.6 MB (1,679,032 bytes)

Product version:
2.3

Copyright:
版权所有 (C) 2012

Original file name:
liuliangbao

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\流量宝流量版.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
7/17/2015 5:30:00 AM

Valid to:
9/15/2016 5:29:59 AM

Subject:
CN="Hangzhou Yunbao Network&Technology Co.,Ltd", OU=IT Dept., O="Hangzhou Yunbao Network&Technology Co.,Ltd", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1BED00C480C169774B3859AEBBC46346

File PE Metadata
Compilation timestamp:
3/22/2016 7:22:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Wg2QuJk+/hN6hAPZih0GAuHwz+WjQNH+NZsT3ePoBfdEBWP:Wg2QmkIhXMVA2Y+Wjy0ZsTRoWP

Entry address:
0xC2090

Entry point:
E8, 06, 99, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 68, C8, 06, 51, 00, FF, 15, 4C, 12, 50, 00, 85, C0, 74, 15, 68, B8, 06, 51, 00, 50, FF, 15, 34, 12, 50, 00, 85, C0, 74, 05, FF, 75, 08, FF, D0, 5D, C3, 8B, FF, 55, 8B, EC, FF, 75, 08, E8, C8, FF, FF, FF, 59, FF, 75, 08, FF, 15, DC, 11, 50, 00, CC, 6A, 08, E8, 6A, 8C, 00, 00, 59, C3, 6A, 08, E8, 88, 8B, 00, 00, 59, C3, 8B, FF, 56, E8, 9A, 49, 00, 00, 8B, F0, 56, E8, 69, 45, 00, 00, 56, E8, 93, 47, 00, 00, 56, E8, 80, 7E, 00, 00, 56, E8, 2A, 9B, 00...
 
[+]

Entropy:
6.6956

Code size:
1021 KB (1,045,504 bytes)

The file 流量宝流量版.exe has been seen being distributed by the following 4 URLs.

Scan 流量宝流量版.exe - Powered by Reason Core Security