pps3update.exe

爱奇艺PPS影音

BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.

Publisher:
爱奇艺  (signed by BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.)

Product:
爱奇艺PPS影音

Description:
爱奇艺PPS升级模块

Version:
1, 1, 2, 1009

MD5:
428f705f14eb02b67401a3228a7fb984

SHA-1:
bbbc88496ece58fb0f4a0df81893638f0841497e

SHA-256:
d19be7b3eef5972a23bdeedc0bb9d0e857d8eb0855f93aeb2816b4f65899d3c8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 10:41:22 PM UTC  (today)

File size:
259.4 KB (265,664 bytes)

Product version:
1, 1, 2, 1009

Copyright:
Copyright (C) 2014 爱奇艺 All Rights Reserved

Original file name:
QyUpdate.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pps3update.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/19/2013 8:00:00 AM

Valid to:
2/10/2017 7:59:59 AM

Subject:
CN="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", OU=TECHNOLOGY PRODUCTS DEPARTMENT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", L=BEIJING, S=BEIJING, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
46C18F6601633DAE52FFD9A4FA162F40

File PE Metadata
Compilation timestamp:
9/4/2014 4:48:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:jXQ17vbgCQh/pehgBT6nXqxcLHcYKTBJFpm:EbrQh/peYT6XqKrtKTrC

Entry address:
0x19850

Entry point:
E8, 55, BF, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 53, 33, DB, 3B, CB, 76, 28, 6A, E0, 33, D2, 58, F7, F1, 3B, 45, 10, 73, 1C, E8, 6D, C0, FF, FF, 53, 53, 53, 53, 53, C7, 00, 0C, 00, 00, 00, E8, 04, A8, FF, FF, 83, C4, 14, 33, C0, EB, 41, 0F, AF, 4D, 10, 56, 57, 8B, F1, 39, 5D, 08, 74, 0B, FF, 75, 08, E8, E7, 94, 00, 00, 59, 8B, D8, 56, FF, 75, 08, E8, 01, D9, FF, FF, 8B, F8, 59, 59, 85, FF, 74, 14, 3B, DE, 73, 10, 2B, F3, 56, 6A, 00, 03, DF, 53, E8, B5, A2, FF, FF, 83, C4, 0C, 8B, C7...
 
[+]

Entropy:
6.5974

Code size:
190.5 KB (195,072 bytes)

The file pps3update.exe has been seen being distributed by the following 2 URLs.

Scan pps3update.exe - Powered by Reason Core Security