BaofengPlatform.exe

暴风影音5

Beijing Baofeng Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BaofengPlatform’.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音5

Description:
暴风影音平台中心

Version:
5.44.1230.0

MD5:
ecf1656aaa7537f4544c40039d6425c8

SHA-1:
35550038d16fdc9d7b14bc326efcf84ff3e2c293

SHA-256:
567909cb4d2c7c3b8776d87cec9a4c718d1a6aaddf0d0d094cbee462b941e916

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:22:38 PM UTC  (today)

File size:
647.8 KB (663,367 bytes)

Product version:
5.44.1230.0

Copyright:
Copyright (C) 2007-2014 北京暴风科技股份有限公司

Original file name:
BaofengPlatform.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\baofeng\stormplayer\baofengplatform.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 8:00:00 AM

Valid to:
2/22/2015 7:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1183EF096F14D7BCF9F0699CEA156B7F

File PE Metadata
Compilation timestamp:
12/29/2014 8:49:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x468A6

Entry point:
E9, 65, 65, FE, FF, E9, 6B, FD, FF, FF, FF, 25, 30, 03, 45, 00, FF, 25, 34, 03, 45, 00, FF, 25, 38, 03, 45, 00, FF, 25, 3C, 03, 45, 00, FF, 25, 40, 03, 45, 00, FF, 25, 44, 03, 45, 00, FF, 25, 48, 03, 45, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 66, 63, 44, 00, 68, B0, 61, 46, 00, E8, 64, 04, 00, 00, 83, C4, 18, 5D, C3, CC, FF, 25, 4C, 03, 45, 00, FF, 25, 50, 03, 45, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 81, 46, 00, 89, 0D, 94, 81, 46, 00, 89, 15, 90, 81...
 
[+]

Entropy:
6.9427

Packer / compiler:
Xtreme-Protector v1.05

Code size:
316 KB (323,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BaofengPlatform

Command:
"C:\Program Files\baofeng\stormplayer\baofengplatform.exe" \autorun


Scan BaofengPlatform.exe - Powered by Reason Core Security