baofeng5_89821302.exe

暴风影音2015安装程序

Beijing Baofeng Technology Co., Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from g.pc6.com.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音2015安装程序

Version:
5.49.0528.2231

MD5:
283a0c1e2bab0c43d4e716b50277e8ef

SHA-1:
f8b44f8ecefecf0cd8bd1a69baf4f5f27f77f799

SHA-256:
2594d74917e3cf74cf91454640ddbfe97bdb6f6f49f720e6207cacf54fc1b470

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/8/2024 10:28:59 AM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.Agent.dnpzpg
0.30.24.2996

File size:
44 MB (46,187,936 bytes)

Product version:
5.49.0528.2231

Copyright:
Copyright (C) 2007-2015 北京暴风科技股份有限公司

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\downloads\baofeng5_89821302.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/5/2015 7:00:00 AM

Valid to:
4/6/2016 6:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=在线QA, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F5A9D93D770229C503B8355B15B6DF0

File PE Metadata
Compilation timestamp:
5/29/2015 2:47:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:haqaqDx7mdQJD74fHTc9mmPQSfQAIAsW3rdKqOLfMNsj9qGIJQnOROsAKUqNV:0q/DWbImIQdAH9Brafqsj9qG/nH/a

Entry address:
0x9E3E0

Entry point:
E8, 4C, DA, 00, 00, E9, 89, FE, FF, FF, FF, 35, A4, B0, 4F, 00, FF, 15, 50, F3, 4B, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 94, 1C, 00, 00, 6A, 01, 6A, 00, E8, 66, 18, 00, 00, 83, C4, 0C, E9, 2B, 18, 00, 00, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, 8B, 5D, 08, 56, 85, DB, 74, 11, 83, 7D, 0C, 00, 76, 11, 85, DB, 75, 23, 33, C0, E9, BC, 00, 00, 00, 83, 7D, 0C, 00, 74, EF, E8, 09, 12, 00, 00, 6A, 16, 5E, 89, 30, E8, 71, 38, 00, 00, 8B, C6, E9, A0, 00, 00, 00, FF, 75, 0C, 53, E8, 3C, FD, FF, FF, 59, 59, 3B, 45, 0C...
 
[+]

Entropy:
7.9925  (probably packed)

Code size:
758.5 KB (776,704 bytes)

The file baofeng5_89821302.exe has been seen being distributed by the following URL.

Scan baofeng5_89821302.exe - Powered by Reason Core Security