dsdl.exe

游戏下载工具

NetEase(Hangzhou) Network Co. Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetEase Dragon Sword Downloader’. The file has been seen being downloaded from ds.gdl.netease.com.
Publisher:
Netease  (signed by NetEase(Hangzhou) Network Co. Ltd.)

Product:
游戏下载工具

Version:
1.0.0.1

MD5:
f6aaa6d3b3d70fbda1c8c72e522eb00e

SHA-1:
2a47b478d24c507181a0a9edd525e895e12ddbd9

SHA-256:
e1b993fcc4c3787cd06cd580ea4893773fcb4456bf2ced726b161a1eb93eb889

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:20:32 AM UTC  (today)

File size:
4.8 MB (5,063,536 bytes)

Product version:
1.0.0.1

Copyright:
(C) Netease 保留所有权利。

Original file name:
GDShell.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/21/2013 8:00:00 AM

Valid to:
6/21/2016 7:59:59 AM

Subject:
CN=NetEase(Hangzhou) Network Co. Ltd., OU=NetEase(Hangzhou), OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NetEase(Hangzhou) Network Co. Ltd., L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6E784D426DC9B224B766A95D34B03A8E

File PE Metadata
Compilation timestamp:
4/23/2014 6:47:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:DKCXZjW8Jh+wg1PzGAfh0RxcJTFSBvtsEe4a8A6bJI5xtsEe4a8A6Nq2IgXj1:DNpgjh0RxcJTFShtsDi11I5xtsDi1A2x

Entry address:
0x143185

Entry point:
E8, B4, C5, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 68, A8, 5D, 00, E8, 55, 1D, 00, 00, E8, 81, C7, 00, 00, 0F, B7, F0, 6A, 02, E8, 47, C5, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 04, 7D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.8602

Code size:
1.5 MB (1,613,312 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetEase Dragon Sword Downloader

Command:
C:\users\{user}\desktop\dsdl.exe autorun


The file dsdl.exe has been seen being distributed by the following URL.

Scan dsdl.exe - Powered by Reason Core Security