BaofengPlatform.exe

暴风影音5

Beijing Baofeng Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BaofengPlatform’.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音5

Description:
暴风影音平台中心

Version:
5.44.1230.0

MD5:
9245657a112c477efb917f88537c8648

SHA-1:
f8d385e465b0599d165ee5039c8507a9d1eaa519

SHA-256:
ca10752de89ea6f7162597f468c8cda8c113c71e938063e4e2a18d409c105efe

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:49:45 PM UTC  (today)

File size:
647.8 KB (663,367 bytes)

Product version:
5.44.1230.0

Copyright:
Copyright (C) 2007-2014 北京暴风科技股份有限公司

Original file name:
BaofengPlatform.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\baofeng\stormplayer\baofengplatform.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/22/2012 8:00:00 AM

Valid to:
2/22/2015 7:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1183EF096F14D7BCF9F0699CEA156B7F

File PE Metadata
Compilation timestamp:
12/29/2014 8:49:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x468A6

Entry point:
E9, 55, 5F, FD, FF, E9, 6B, FD, FF, FF, FF, 25, 30, 03, 45, 00, FF, 25, 34, 03, 45, 00, FF, 25, 38, 03, 45, 00, FF, 25, 3C, 03, 45, 00, FF, 25, 40, 03, 45, 00, FF, 25, 44, 03, 45, 00, FF, 25, 48, 03, 45, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 66, 63, 44, 00, 68, B0, 61, 46, 00, E8, 64, 04, 00, 00, 83, C4, 18, 5D, C3, CC, FF, 25, 4C, 03, 45, 00, FF, 25, 50, 03, 45, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 81, 46, 00, 89, 0D, 94, 81, 46, 00, 89, 15, 90, 81...
 
[+]

Entropy:
6.9425

Packer / compiler:
Xtreme-Protector v1.05

Code size:
316 KB (323,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BaofengPlatform

Command:
"C:\Program Files\baofeng\stormplayer\baofengplatform.exe" \autorun


Scan BaofengPlatform.exe - Powered by Reason Core Security