dandelion_1.5.4.1.exe

TAOBAO (CHINA) SOFTWARE CO.,LTD.

It runs as a scheduled task under the Windows Task Scheduler named DandelionStarter triggered daily at a specified time. The file has been seen being downloaded from c10.97you.net.
Publisher:
TAOBAO (CHINA) SOFTWARE CO.,LTD.  (signed and verified)

Version:
1.5.4.1

MD5:
1900c34f5f8d7bb60d8ab2b1ab0bbf5e

SHA-1:
62be761f29a60bac19b492ac2694cf23466110ba

SHA-256:
bad8ecf6349a5d937ab89eac45c85c7668462d8f49608b21eacd15fe98b81693

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 1:41:50 PM UTC  (today)

File size:
1.9 MB (2,008,032 bytes)

Product version:
1.5.4.1

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\dandelion\dandelion_1.5.4.1.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/23/2014 8:00:00 AM

Valid to:
6/22/2016 7:59:59 AM

Subject:
CN="TAOBAO (CHINA) SOFTWARE CO.,LTD.", OU=RDC, O="TAOBAO (CHINA) SOFTWARE CO.,LTD.", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
348A4D46C9A1A9EDC2B4818465A66BED

File PE Metadata
Compilation timestamp:
3/11/2016 4:36:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:SWqUC8jIHbcekhXtMhIu7nav45AJp/jjUwbR6:SUMHAekzMhr7av/j0

Entry address:
0x1579DE

Entry point:
E8, 77, D9, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 00, FC, 5C, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 3F, B4, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 8D, 85, E4, FC, FF, FF, 6A, 4C, 6A, 00, 50, E8, 3E, FD, FF, FF, 8D, 85, E0, FC, FF, FF, 83, C4, 0C, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
6.7318

Code size:
1.5 MB (1,547,776 bytes)

Scheduled Task
Task name:
DandelionStarter

Trigger:
Daily (Runs daily at 16:14)

Description:
Dandelion client startup tasks


The file dandelion_1.5.4.1.exe has been seen being distributed by the following URL.

Scan dandelion_1.5.4.1.exe - Powered by Reason Core Security