startmenu64.exe

暴点菜单

Beijing Baofeng Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘StartMenu64.exe’.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴点菜单

Description:
暴点菜单启动程序

Version:
1.1.0.0

MD5:
d801746cbcbd7319497691603a34c7b9

SHA-1:
e59bc35fe48b41fff8215fd94449c2ef67d77069

SHA-256:
fdeb51c274e7fc81e17f5b67e25f5b0a23a5ee6122e7066369f75daf67f3469f

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 3:18:18 AM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.667

Trend Micro House Call
Suspicious_GEN.F47V0104
7.2.44

File size:
541.4 KB (554,360 bytes)

Product version:
1.1.0.0

Copyright:
Copyright (C) 2007-2014 北京暴风科技股份有限公司

Original file name:
StormMenu_v1.1.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\baofeng\stormmenu\startmenu64.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 9:00:00 AM

Valid to:
2/22/2015 8:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1183EF096F14D7BCF9F0699CEA156B7F

File PE Metadata
Compilation timestamp:
12/24/2014 6:22:53 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:nFnWvh1owXEA3UN6aJtZFnWvh1owXEA3UN6aJt:gEA3UN6wAEA3UN6w

Entry address:
0x1830

Entry point:
48, 83, EC, 28, E8, DB, 03, 00, 00, 48, 83, C4, 28, E9, 26, FD, FF, FF, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, 99, 18, 00, 00, FF, 15, 13, 08, 00, 00, 48, 8B, 05, 84, 19, 00, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, 71, 04, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24, 28, 48, 8D, 05, 44, 18, 00, 00, 48, 89, 44, 24...
 
[+]

Entropy:
6.6877

Code size:
3.5 KB (3,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
StartMenu64.exe

Command:
"C:\Program Files\baofeng\stormmenu\startmenu64.exe"


Scan startmenu64.exe - Powered by Reason Core Security