paiot.exe

360Play

VNG Corporation

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘CuHanhPlay’.
Publisher:
VNG Corporation  (signed and verified)

Product:
360Play

Description:
360Play Notification

Version:
1.0.0.3

MD5:
94752f014b070e73ffb39a494d3b5991

SHA-1:
c0ca9e67dfbbe3729d1dcdcfbd3bc3ecc487607a

SHA-256:
ba9346653c5530521229e6dc9b4f4c63f2db4e65f1798595286ef71c6face74b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 9:34:41 PM UTC  (today)

File size:
2 MB (2,078,248 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2015 by VNG Corporation.

Original file name:
CuHanhPlayTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\360play\paiot.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2015 7:00:00 AM

Valid to:
9/28/2017 6:59:59 AM

Subject:
CN=VNG Corporation, O=VNG Corporation, L=Ho Chi Minh, S=Vietnam, C=VN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
69E915413BDF99A03D3AB8D92C3A2C52

File PE Metadata
Compilation timestamp:
3/17/2016 3:22:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x390F63

Entry point:
55, 89, E5, 81, EC, 1C, 00, 00, 00, 81, EC, 04, 00, 00, 00, 89, 04, 24, 53, 51, C7, 85, E8, FF, FF, FF, 47, 45, 4B, 00, 81, EC, 04, 00, 00, 00, 89, 14, 24, 81, EC, 04, 00, 00, 00, 89, 34, 24, C7, 85, FC, FF, FF, FF, 30, A9, 00, 00, 8B, B5, E8, FF, FF, FF, B8, 48, 2F, 00, 00, 68, 00, 00, 00, 00, 8B, 9D, FC, FF, FF, FF, 81, C3, 40, FA, 58, 00, 8B, 0C, 24, 81, C4, 04, 00, 00, 00, 03, 0B, 81, C0, FC, FF, FF, FF, 03, 0B, 29, F1, 03, 0B, 29, F1, 03, 0B, 29, F1, 03, 0B, 81, E9, 06, A9, 94, 4E, 03, 0B, 29, F1, C1...
 
[+]

Entropy:
7.8867  (probably packed)

Code size:
4.7 MB (4,959,232 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CuHanhPlay

Command:
C:\users\{user}\appdata\local\360play\paiot.exe


Scan paiot.exe - Powered by Reason Core Security