BaofengPlatform.exe

暴风影音5

Beijing Baofeng Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BaofengPlatform’.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音5

Description:
暴风影音平台中心

Version:
5.44.1230.0

MD5:
3d8e629bf1a45b1f6c14bc3d120009f5

SHA-1:
1326ab02425cae8779236d950def9669dc667417

SHA-256:
68f6831b1223d8ccd175041ca79f06caeb1f04521d799bb5d9124f5728cc76e8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 1:14:25 AM UTC  (today)

File size:
647.8 KB (663,367 bytes)

Product version:
5.44.1230.0

Copyright:
Copyright (C) 2007-2014 北京暴风科技股份有限公司

Original file name:
BaofengPlatform.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\baofeng\stormplayer\baofengplatform.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 8:00:00 AM

Valid to:
2/22/2015 7:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1183EF096F14D7BCF9F0699CEA156B7F

File PE Metadata
Compilation timestamp:
12/29/2014 8:49:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x468A6

Entry point:
E9, 5F, 8F, FE, FF, E9, 6B, FD, FF, FF, FF, 25, 30, 03, 45, 00, FF, 25, 34, 03, 45, 00, FF, 25, 38, 03, 45, 00, FF, 25, 3C, 03, 45, 00, FF, 25, 40, 03, 45, 00, FF, 25, 44, 03, 45, 00, FF, 25, 48, 03, 45, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 66, 63, 44, 00, 68, B0, 61, 46, 00, E8, 64, 04, 00, 00, 83, C4, 18, 5D, C3, CC, FF, 25, 4C, 03, 45, 00, FF, 25, 50, 03, 45, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 81, 46, 00, 89, 0D, 94, 81, 46, 00, 89, 15, 90, 81...
 
[+]

Entropy:
6.9421

Packer / compiler:
Xtreme-Protector v1.05

Code size:
316 KB (323,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BaofengPlatform

Command:
"C:\Program Files\baofeng\stormplayer\baofengplatform.exe" \autorun


Scan BaofengPlatform.exe - Powered by Reason Core Security