pps3update.exe

爱奇艺PPS影音

BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.

Publisher:
爱奇艺  (signed by BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.)

Product:
爱奇艺PPS影音

Description:
爱奇艺PPS升级模块

Version:
1, 1, 2, 1008

MD5:
9b310d3fa652b08315cc3a585ae07348

SHA-1:
fddacf33e17302c13370a7c52263bfa39758463f

SHA-256:
fb50cdd3ae2c5c589224aaf98d1f1e50e2a33a570718da115ed49938e66022f1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 11:11:08 AM UTC  (today)

File size:
259.4 KB (265,664 bytes)

Product version:
1, 1, 2, 1008

Copyright:
Copyright (C) 2014 爱奇艺 All Rights Reserved

Original file name:
QyUpdate.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pps3update.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/19/2013 8:00:00 AM

Valid to:
2/10/2017 7:59:59 AM

Subject:
CN="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", OU=TECHNOLOGY PRODUCTS DEPARTMENT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", L=BEIJING, S=BEIJING, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
46C18F6601633DAE52FFD9A4FA162F40

File PE Metadata
Compilation timestamp:
8/1/2014 11:07:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:HHQvjucrXyGzmuCupmiHgRT6nXmxJLG8K8TBJIph:O9rVKuCupmimT6XmXC78TrG

Entry address:
0x19840

Entry point:
E8, 55, BF, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 53, 33, DB, 3B, CB, 76, 28, 6A, E0, 33, D2, 58, F7, F1, 3B, 45, 10, 73, 1C, E8, 6D, C0, FF, FF, 53, 53, 53, 53, 53, C7, 00, 0C, 00, 00, 00, E8, 04, A8, FF, FF, 83, C4, 14, 33, C0, EB, 41, 0F, AF, 4D, 10, 56, 57, 8B, F1, 39, 5D, 08, 74, 0B, FF, 75, 08, E8, E7, 94, 00, 00, 59, 8B, D8, 56, FF, 75, 08, E8, 01, D9, FF, FF, 8B, F8, 59, 59, 85, FF, 74, 14, 3B, DE, 73, 10, 2B, F3, 56, 6A, 00, 03, DF, 53, E8, B5, A2, FF, FF, 83, C4, 0C, 8B, C7...
 
[+]

Entropy:
6.5970

Code size:
190.5 KB (195,072 bytes)

The file pps3update.exe has been seen being distributed by the following 2 URLs.

http://update.webscache.net/product/.../pps3update.exe

Scan pps3update.exe - Powered by Reason Core Security