cyberlink_power2go_downloader.exe

CLDownloader

CyberLink Corp.

Publisher:
CyberLink  (signed by CyberLink Corp.)

Product:
CLDownloader

Description:
CyberLink Downloader

Version:
2.9.1.6109

MD5:
6de4d74ae710ce2a1d18572c5f24c27c

SHA-1:
40107f41ee903eace791266436206ebbf01e34f5

SHA-256:
97815136994fa345c0ffedd860965c122a12b702945783180afd2fdbf706b880

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 3:36:33 AM UTC  (today)

File size:
1.2 MB (1,208,864 bytes)

Product version:
2.9.1.6109

Copyright:
Copyright (C) CyberLink Corporation. All rights reserved

Original file name:
CLDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\cyberlink_power2go_downloader.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
3/4/2015 4:00:00 PM

Valid to:
5/3/2018 4:59:59 PM

Subject:
CN=CyberLink Corp., O=CyberLink Corp., L=New Taipei City, S=Taiwan, C=TW

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2CD2C5777BFC596CE3F6EBFDFB9B9469

File PE Metadata
Compilation timestamp:
1/9/2015 1:29:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:2aSB9F2NqBbKDwhjWxQMLyOqe3brZ1BjsOx6rjKEYLheaW2:2/F2NuRtORrrZPqjKtP1

Entry address:
0x7C347

Entry point:
E8, 0B, B0, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 10, 75, 20, E8, F4, 2B, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 16, E6, FF, FF, 83, C4, 14, 83, C8, FF, E9, A1, 00, 00, 00, 8B, 45, 0C, 3B, C3, 56, 8B, 75, 08, 74, 21, 3B, F3, 75, 1D, E8, C5, 2B, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, E7, E5, FF, FF, 83, C4, 14, 83, C8, FF, EB, 74, 3D, FF, FF, FF, 3F, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 76, 09, C7, 45, E4, FF, FF, FF, 7F, EB...
 
[+]

Entropy:
7.1733

Code size:
588 KB (602,112 bytes)

The file cyberlink_power2go_downloader.exe has been seen being distributed by the following 18 URLs.

http://dw.uptodown.com/dwn/lcWCcxK_OY7tNphYD5A_iqKRJ65v-K0ybxAs4ryNPV5pWNNL-ox2WPTQ3wnnyoCPZgm_ZpiVWfS3ze3jzS4kZYV-U9h6ymwqmbvQK2nk3BXY5Z5n0IT2leD9amgmRNCB/L4pZoUEjMNKzbOBo2lzNNd7XE1MWrlUGJ3AS-pu1pPOwzXe8Ret_UODlYerKs0ynBfr1F43GDz1U_yoi2dUjA-nOh3B1u7lThKFZ5N1qIE4fKQAkl-u2kbERjjO7iSDq/L4TU-D_CBkaF3-GlHh4T2CIb8wUP0JEj0Rp8bI6mF0gb1_8JmcqQYUBRKjAbLwLAfy1Ol14Cq7jZnxqTmap09GtMeJJbkq5dhrBafuxXf6fM7MoZGyObnqdrve9jrXyN/.../

https://dw.uptodown.com/dwn/n84AuMR2HNwK9HrG4bDswgByGAuXlnMdo20-LE1BfwsBdRf048dl3sanIz8uIbzouD4S4kvlKc0cPI9XyYSsmJmX7b1G07Amyqns0Fz-1tQHxUDIaz5o-SWIfqCfDNpd/KZLEDC2qXJ07tZEZF_k0sHFNI5AYaiPHK2SJyoZmjO5uKfsL2f8iNPvIc-ms3GNdfNILqS_N3mKBzEORFt8rcoPzQbW-eMIwyJrWeYGev2OnsRS6cTaob21eaRt0nSXh/lFBTWVZBZ_CbnTKFgpuuvMHSWKBm3Id75Dtgw6MBwSYcwFJyTNXuFnCM49C3VDRNo5Jm0Wjxbh0-tEyRj-ihDxexagwDtkqJXCP6Uoad3aAo6FxBJVkkAvYZzS4EFKEI/.../

http://update.cyberlink.com/Retail/Power2Go/DL/.../CyberLink_Power2Go_Downloader.exe

https://dw.uptodown.com/dwn/wlU1EwJOBFcBYwImTbJfcfasFg_4R0CHJJbFQRewFLGFN6GzR_mpiAgC-c1KOeTOEi4nDnG4mdWxMtpCwse07wVjbGKV5Ze6u-jL7Xx8LcsuhWY9uiMyY3Zr4INBrMfl/nXAg5KNOjWICXmn1pLNDQwP6YmfKVGsUU2mEHGeKJ3x2voSqd3G2-LPqTJcV_QwoJ4Cp6T4AKfX6V6SRCmejmhBFfiZNHkyEt9yIpg4fADj_PXrjmZsoEiVuirX1Vzkc/XdsL1KqbvzssDpZRZ6gO9O8_XSB8hrfTRXTPMYIoQ0crJV8KNhI28ZAeYB8JnidgAjd-5tTZYUo889tDHoGzH2XvOgQCwJHFLrOgORSo8-o4rXllN0NjRZnajD3Qt715/.../

https://dw.uptodown.com/dwn/JM8WP8s673TGNNFpjYckXetr9HdXlCf8HGTaMUOWdXWrVcrRAG_5e_xiym65t11kKIvSRY9B6pSJfwEdzWqU1vymeTWaq0lBODL04jgQj_u6GNpnnSVeihDY87QDo0RQ/BUZ0fd6iPNXVI_Oxa3QAIi7INWCV8tGDTv7G08TcWdNkiFbYANnOVXhIJBl_ffHC5CxV33jRwTV-WRUoqO4UUSPKelNj468FlQ-lPiwdB90AN3cuKe5306ADyUPAoCJZ/rw6dYvSi5u0w85S85l1-gP3P1PjfIPOBEX5c72gHyFV5OV-3lVpvupsJ5gbdRUQ25xc-UqIOslIJBMX-QLigXMCK3t8RnhIwZyvffjVX8ls97x8OjigRWPl7-dp1RH9J/.../

https://dw.uptodown.com/dwn/qFOwfSQL5k5ke8yq0MjA4YGpXluUNNo_4t_NCJVqLpLW7Po0z0ZTS_DDnKMFHHYP8cPrQMT-8tbzysUHVHuio-8cX67Um9FR3sM3JHaAYkWN-QYgwpT49Nq92_s4cjwp/xhXGOWRdOMIbY9zA9AyobXcoTj7J6eiBVTVIoPzeFopbipthGzjXva3ux3Uv9hzlocYpWKmv7bDYBTW68EzdtRoMClncpoHnKUvZp5dXF0g2WHnwlO40CNhqWkoxv8C2/V-tYmNg8TvAEaDAHmbwi-lF2cs5osszA7fLDaVpJB6pgh2P_zckHK0Ie2sa2yo4-ZeiEiZuKE4A29GhX8o4iWc5SffCLjfl0hHfwo2A4rqG4R8EZDnQArMteNfypSoZ9/.../

https://dw.uptodown.com/dwn/V_m6Ps9By5SET2InCqLLKUjru34gtHDLu7ZeQhIalj476aTZdJyOSk10m8-9JrzwzrOoc5DvWtonO90Br4qlw2nrNLurcy4e5fvkRug1g0EZhjmQrIU1U3szyGTJk3HN/KIUVOlZQ-jHabK_LCFBwmMA5DPeXl_F6IoY5h-AEhUWgORJku0O7dH8VysXqdd0BQxnHD7zj49keCS9Mx2SzoiDmPQ3ERVzAwoTrPzgHFUFXeTAc1rXpIlfSuNJum9YX/JVAtZsE80lYhi59jtjLGgfmyBkgzTNSJJBI4h9g1WRgWnmsxrzenBn-dJZZVxRGXAZf2HW5OH8NUGNhiV_6LaoNZJuX-VFVn_zvj70nNqQuahC29f_n12K8JDz-Tpg_g/.../

http://dw.uptodown.com/dwn/GQmhWoZanI14AajINUwA81113LpZes8XzYKvtSzpTs_eUnVXYtLC9z7k7gpJq_1mil_Y3OVziU1rjfL6drFCNZ0HNEgJvTwI63hE2cDG0Hun3tbcVXSYu2rVnFKg3Hqg/rT0V_VyKzuhp7Nc5SDC6Jm7982DPNgBX3ni9X8I3YG5Rej879QfVGEEg2LdGachIPT0X2U3TPKLrgOxEVOV8ZxAOEfZK4LTvDsUNlzXo0u6-2qYoXYL32qUsACBXcmQ6/LTfAF6l15MZ5L1-Og1zKyckUNrEIALT6H6K3QuXSdCFhmzePriOqx-zWQOrsIBcuHFoxpCeHK15lHzPLqVp7NlZH7Iv1l04C2F0lU__aJAm0GSfUZ7kgx1SRo3aUdoyw/.../