QyUpdate.exe

爱奇艺PPS影音

BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.

Publisher:
爱奇艺  (signed by BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.)

Product:
爱奇艺PPS影音

Description:
爱奇艺PPS升级模块

Version:
1, 1, 2, 1013

MD5:
05bc187717bc35a7c2f2735650f9a1d1

SHA-1:
a0a6f7aad2ec664c014880ce8bcbf668e6f4cc1a

SHA-256:
846b5109b898fb5d7fd4ee8273584231514e91422033db85a150a0ff3afb20e3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:31:54 PM UTC  (today)

File size:
259.1 KB (265,320 bytes)

Product version:
1, 1, 2, 1013

Copyright:
Copyright (C) 2014 爱奇艺 All Rights Reserved

Original file name:
QyUpdate.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\ppstream\qyupdate.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/19/2013 1:00:00 AM

Valid to:
2/10/2017 12:59:59 AM

Subject:
CN="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", OU=TECHNOLOGY PRODUCTS DEPARTMENT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="BEIJING QIYI CENTURY SCIENCE&TECHNOLOGY CO.,LTD.", L=BEIJING, S=BEIJING, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
46C18F6601633DAE52FFD9A4FA162F40

File PE Metadata
Compilation timestamp:
10/30/2014 3:10:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:QRnoB4Mf41XFXKi/T/owF4I5tLWITlTBJZRB:P4Mf4tFXKikwFD5tialTrZ

Entry address:
0x19AC0

Entry point:
E8, 59, BF, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 53, 33, DB, 3B, CB, 76, 28, 6A, E0, 33, D2, 58, F7, F1, 3B, 45, 10, 73, 1C, E8, 3D, D9, FF, FF, 53, 53, 53, 53, 53, C7, 00, 0C, 00, 00, 00, E8, 44, A7, FF, FF, 83, C4, 14, 33, C0, EB, 41, 0F, AF, 4D, 10, 56, 57, 8B, F1, 39, 5D, 08, 74, 0B, FF, 75, 08, E8, C9, 69, 00, 00, 59, 8B, D8, 56, FF, 75, 08, E8, 80, EF, FF, FF, 8B, F8, 59, 59, 85, FF, 74, 14, 3B, DE, 73, 10, 2B, F3, 56, 6A, 00, 03, DF, 53, E8, F5, A1, FF, FF, 83, C4, 0C, 8B, C7...
 
[+]

Entropy:
6.5928

Code size:
191 KB (195,584 bytes)

The file QyUpdate.exe has been seen being distributed by the following 3 URLs.

http://update.pps.tv/product/.../pps3update.exe

Scan QyUpdate.exe - Powered by Reason Core Security