BaofengPlatform.exe

暴风影音5

Beijing Baofeng Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BaofengPlatform’.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音5

Description:
暴风影音平台中心

Version:
5.44.1230.0

MD5:
94fb902e4c68603d4b15cd8a8c0be4ba

SHA-1:
cc9e13d64f97c25f64397c15426fb5c20b3661e7

SHA-256:
0f4e3a2f96ab5b73032d711d5276f21c65c1e45fadf87f44076feb87e8cd8f95

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 8:56:48 AM UTC  (today)

File size:
647.8 KB (663,367 bytes)

Product version:
5.44.1230.0

Copyright:
Copyright (C) 2007-2014 北京暴风科技股份有限公司

Original file name:
BaofengPlatform.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\baofeng\stormplayer\baofengplatform.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 8:00:00 AM

Valid to:
2/22/2015 7:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1183EF096F14D7BCF9F0699CEA156B7F

File PE Metadata
Compilation timestamp:
12/29/2014 8:49:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x468A6

Entry point:
E9, FE, 85, FE, FF, E9, 6B, FD, FF, FF, FF, 25, 30, 03, 45, 00, FF, 25, 34, 03, 45, 00, FF, 25, 38, 03, 45, 00, FF, 25, 3C, 03, 45, 00, FF, 25, 40, 03, 45, 00, FF, 25, 44, 03, 45, 00, FF, 25, 48, 03, 45, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 66, 63, 44, 00, 68, B0, 61, 46, 00, E8, 64, 04, 00, 00, 83, C4, 18, 5D, C3, CC, FF, 25, 4C, 03, 45, 00, FF, 25, 50, 03, 45, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 81, 46, 00, 89, 0D, 94, 81, 46, 00, 89, 15, 90, 81...
 
[+]

Entropy:
6.9423

Packer / compiler:
Xtreme-Protector v1.05

Code size:
316 KB (323,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BaofengPlatform

Command:
"C:\Program Files\baofeng\stormplayer\baofengplatform.exe" \autorun


Scan BaofengPlatform.exe - Powered by Reason Core Security