bingdictsetup.exe

微软必应词典

上海美斯恩网络通讯技术有限公司

This is a setup and installation application.
Publisher:
Microsoft Corporation.  (signed by 上海美斯恩网络通讯技术有限公司)

Product:
微软必应词典

Description:
微软必应词典安装程序

Version:
2.4.0.3629

MD5:
d9cfc0bf8e55704e9b1c63e2c762fbef

SHA-1:
b3c4015dc4b92891584765caab98bd390b27edf3

SHA-256:
865b80c5f8ab5f6273a0a1ad99cb9809de08af9d4cd3610354301246c72abbf6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:38:46 AM UTC  (today)

File size:
28.5 MB (29,928,272 bytes)

Product version:
2.4.0.3629

Copyright:
Microsoft Corporation. Copyright (C) 2013

Original file name:
BingDictMsiWrapper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\bingdict\update\bingdictsetup.exe

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
6/27/2012 1:59:00 AM

Valid to:
6/30/2015 11:03:06 PM

Subject:
E=j-hogao@microsoft.com, CN=上海美斯恩网络通讯技术有限公司, O=上海美斯恩网络通讯技术有限公司, L=上海市, S=上海市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
1CD7A9516EBD55

File PE Metadata
Compilation timestamp:
9/9/2013 2:12:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
786432:DgBZ1wYpm1m/cxNnbY/KGMbRFJrV+Y+Sh0a118RG8AWopv:oSm/crGkzV+aOQ8RGVWov

Entry address:
0x1526D

Entry point:
E8, 7F, B2, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, F1, 8B, 4D, 08, C6, 46, 0C, 00, 85, C9, 75, 66, E8, 03, 83, 00, 00, 8B, D0, 89, 56, 08, 8B, 4A, 6C, 89, 0E, 8B, 4A, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, BC, B9, 43, 00, 74, 11, A1, 7C, BA, 43, 00, 85, 42, 70, 75, 07, E8, DC, 80, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, C8, BA, 43, 00, 74, 15, 8B, 4E, 08, A1, 7C, BA, 43, 00, 85, 41, 70, 75, 08, E8, 59, B6, 00, 00, 89, 46, 04, 8B, 4E, 08, 8B, 41, 70, A8, 02, 75, 16, 83, C8, 02, 89, 41, 70, C6, 46, 0C, 01, EB...
 
[+]

Entropy:
7.8690  (probably packed)

Code size:
181.5 KB (185,856 bytes)

Scan bingdictsetup.exe - Powered by Reason Core Security