cloud.exe file report

MD5 632e6c142fbc082288fbd5a2ff736a0b
Latest seen 2024-10-14 23:08:29 (2 years ago)
First seen 2019-08-10 23:53:07 (6 years ago)
Size 4 MB

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for cloud.exe. ThreatInfo does not have a final classification for this sample yet.

cloud.exe is a Windows file recorded in the ThreatInfo database. It is associated with DriverPack Cloud. The reported company name is DriverPack Solution. The current detection status is Undefined, based on the latest analysis from 2024-10-14 23:08:29 (2 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: DriverPack Cloud
Company Name: DriverPack Solution
MD5: 632e6c142fbc082288fbd5a2ff736a0b
Size: 4 MB
First Published: 2019-08-10 23:53:07 (6 years ago)
Latest Published: 2024-10-14 23:08:29 (2 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2024-10-14 23:08:29 (2 years ago)
%appdata%\drpsu
%appdata%\drpsu
%appdata%\drpsu
%appdata%\drpsu
%profile%\ser\application data\drpsu
%appdata%\drpsu
%appdata%\drpsu
%appdata%\drpsu
%appdata%\drpsu
%appdata%\drpsu

ThreatInfo has observed cloud.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

10.9%
10.0%
9.1%
8.2%
4.5%
4.5%
3.6%
3.6%
3.6%
3.6%
3.6%
3.6%
2.7%
2.7%
1.8%
1.8%
1.8%
1.8%
1.8%
1.8%
1.8%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%
0.9%

The strongest geographic signal for this file is Russian Federation with 10.9% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 51.3%
Windows 7 46.9%
Windows XP 1.8%

The most common operating system signal for cloud.exe is Windows 10 with 51.3% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

cloud.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0028f1f0

PE Sections:

Name Size of data MD5
.text 3106816 7468d2f259c691f1fdbf67f19e941bd2
_text32 43008 87e937cf44f053d613df8eff66e017f5
.rdata 588800 829852d9e9e2faf34c6d1408e29c360a
.data 12800 26faa7f3a315eff9085961f7a90c8de7
.didat 512 d885d4dd7125c6b4fcd32258a01dae04
CPADinfo 512 d273139d7dd4280f40c57791927d34c6
.tls 512 1f354d76203061bfdd5a53dae48d5435
_RDATA 512 6a4d701a80c9128ba46180eb8218a58f
.rsrc 396288 26d914556deb6e53cf01c90ea2fe34bc
.reloc 91648 24f3c1bc3d708f5042911d24245d359a

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: