baofeng.exe

暴风影音2015安装程序

北京暴风科技股份有限公司

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from xiazai.xiazaiba.com and multiple other hosts.
Publisher:
北京暴风科技股份有限公司

Product:
暴风影音2015安装程序

Version:
5.49.0528.2111

MD5:
58b6482d73343075b52027e8e975c254

SHA-1:
725224c2b011bd6a96c5afed90b219f3870012c7

SHA-256:
bbadc69f47df6a77c80b3f33fd62d8ab75571ba505e617453255d11ab440f830

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/23/2024 7:48:42 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader.Generic13
2016.0.2895

McAfee
Artemis!58B6482D7334
5600.6551

NANO AntiVirus
Trojan.Win32.Genome.cyoqbt
0.30.26.4437

Vba32 AntiVirus
TrojanDropper.Agent
3.12.26.4

File size:
21.8 MB (22,854,709 bytes)

Product version:
5.49.0528.2111

Copyright:
Copyright (C) 2007-2015 北京暴风科技股份有限公司

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\baofeng.exe

File PE Metadata
Compilation timestamp:
5/30/2012 2:08:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:Qq7Z19Wvvk4VZFATnreOHuJoxPlsBcoNvTD+G5tdCXcAv:QGZagTnlDxOBrLDf+

Entry address:
0x364D

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, BC, 89, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 05, 43, 00, E8, 90, 27, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 04, 43, 00, 8D, 44, 24, 38, 50, 53, 68, BA, 89, 40, 00, FF, 15, 58, 81, 40, 00, 68, B0, 89, 40, 00, 68, C0, FC, 42, 00, E8, D0, 24, 00, 00, FF, 15, AC, 80, 40, 00, 50, BF, 00, 60, 43, 00, 57, E8, BE, 24, 00, 00...
 
[+]

Entropy:
7.9997

Packer / compiler:
Nullsoft install system v2.x

Code size:
25.5 KB (26,112 bytes)

The file baofeng.exe has been seen being distributed by the following 2 URLs.

Scan baofeng.exe - Powered by Reason Core Security