ppsupdate.exe

爱奇艺PPS影音

BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.

Publisher:
爱奇艺  (signed by BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.)

Product:
爱奇艺PPS影音

Description:
爱奇艺PPS升级模块

Version:
1, 1, 2, 1006

MD5:
04432b13391aacdc4334fe38c3db61c3

SHA-1:
65a7160ac3ff6b7d2587c4bf26ad5553f4ad1f77

SHA-256:
c6ef5617d82ed96c1d64bd3169aec27c972e9f9273107df4618b1ff16c8b2b7f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 10:21:04 PM UTC  (today)

File size:
258.9 KB (265,152 bytes)

Product version:
1, 1, 2, 1006

Copyright:
Copyright (C) 2014 爱奇艺 All Rights Reserved

Original file name:
QyUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\appdata\roaming\ppstream\ppsupdate.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/19/2013 8:00:00 AM

Valid to:
2/10/2017 7:59:59 AM

Subject:
CN="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", OU=TECHNOLOGY PRODUCTS DEPARTMENT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", L=BEIJING, S=BEIJING, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
46C18F6601633DAE52FFD9A4FA162F40

File PE Metadata
Compilation timestamp:
7/16/2014 5:25:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:sdfANPM40IcMiDyHmWIGn14192/PIRQh4JmIsL7JS+rwf1/TBfR3IyUD5MHgSZ:sdINgIctD5I/PIRQh4JAL0+rsTBJ3SiD

Entry address:
0x197D0

Entry point:
E8, 5B, BF, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 53, 33, DB, 3B, CB, 76, 28, 6A, E0, 33, D2, 58, F7, F1, 3B, 45, 10, 73, 1C, E8, 6D, C0, FF, FF, 53, 53, 53, 53, 53, C7, 00, 0C, 00, 00, 00, E8, 04, A8, FF, FF, 83, C4, 14, 33, C0, EB, 41, 0F, AF, 4D, 10, 56, 57, 8B, F1, 39, 5D, 08, 74, 0B, FF, 75, 08, E8, 97, 94, 00, 00, 59, 8B, D8, 56, FF, 75, 08, E8, 01, D9, FF, FF, 8B, F8, 59, 59, 85, FF, 74, 14, 3B, DE, 73, 10, 2B, F3, 56, 6A, 00, 03, DF, 53, E8, B5, A2, FF, FF, 83, C4, 0C, 8B, C7...
 
[+]

Entropy:
6.5987

Code size:
190.5 KB (195,072 bytes)

The file ppsupdate.exe has been seen being distributed by the following URL.

Scan ppsupdate.exe - Powered by Reason Core Security