ppstreamsetup_hao123soft.exe

PPStream

SHANGHAI ZHONGYUAN NETWORKS LIMITED

This is a self-extracting archive and installer.
Publisher:
PPStream Inc.  (signed by SHANGHAI ZHONGYUAN NETWORKS LIMITED)

Product:
PPStream

Description:
PPStream Installer

Version:
2.7.0.1310

MD5:
0f58a8cb7daa137f2ea65d5f3f12228b

SHA-1:
d42fbc6663b471c492e968f730d316bdd8ca0680

SHA-256:
2580936c3f3bcac7de1b37f2f76c297fae29cfb495f588b9473cd83f2bc08d46

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 1:07:05 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
DLOADER.Trojan
9.0.1.062

File size:
10.3 MB (10,775,952 bytes)

Product version:
2.7.0.1310

Copyright:
Copyright (C) 2005-2011 PPStream Inc. All Rights Reserved.

Original file name:
ppstreamsetup_hao123soft.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/12/2011 8:00:00 AM

Valid to:
8/11/2012 7:59:59 AM

Subject:
CN=SHANGHAI ZHONGYUAN NETWORKS LIMITED, OU=Development department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SHANGHAI ZHONGYUAN NETWORKS LIMITED, L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F7FE25AE1191062E67174403487897F

File PE Metadata
Compilation timestamp:
9/13/2011 7:20:39 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x3274D0

Entry point:
60, BE, 00, 10, 72, 00, 8D, BE, 00, 00, CE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.9998

Packer / compiler:
UPX 2.90LZMA

Code size:
28 KB (28,672 bytes)

Windows Firewall Allowed Program
Name:
ppstream installer


Scan ppstreamsetup_hao123soft.exe - Powered by Reason Core Security