BaofengPlatform.exe

暴风影音5

Beijing Baofeng Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BaofengPlatform’.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音5

Description:
暴风影音平台中心

Version:
5.44.1230.0

MD5:
befac3d220ae989bc78a52c9215b1a62

SHA-1:
eefa21bd001d88b1736cbb0d72b7bf2b6ad1e693

SHA-256:
88ff21b9990ca3ca1de43eeace37c15954a549660ab513baa1805133c1163537

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 10:35:25 PM UTC  (today)

File size:
647.8 KB (663,367 bytes)

Product version:
5.44.1230.0

Copyright:
Copyright (C) 2007-2014 北京暴风科技股份有限公司

Original file name:
BaofengPlatform.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\baofeng\stormplayer\baofengplatform.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 8:00:00 AM

Valid to:
2/22/2015 7:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1183EF096F14D7BCF9F0699CEA156B7F

File PE Metadata
Compilation timestamp:
12/29/2014 8:49:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x468A6

Entry point:
E9, 13, 50, FF, FF, E9, 6B, FD, FF, FF, FF, 25, 30, 03, 45, 00, FF, 25, 34, 03, 45, 00, FF, 25, 38, 03, 45, 00, FF, 25, 3C, 03, 45, 00, FF, 25, 40, 03, 45, 00, FF, 25, 44, 03, 45, 00, FF, 25, 48, 03, 45, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 66, 63, 44, 00, 68, B0, 61, 46, 00, E8, 64, 04, 00, 00, 83, C4, 18, 5D, C3, CC, FF, 25, 4C, 03, 45, 00, FF, 25, 50, 03, 45, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 81, 46, 00, 89, 0D, 94, 81, 46, 00, 89, 15, 90, 81...
 
[+]

Entropy:
6.9401

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
316 KB (323,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BaofengPlatform

Command:
"C:\Program Files\baofeng\stormplayer\baofengplatform.exe" \autorun


Scan BaofengPlatform.exe - Powered by Reason Core Security