setup.exe

暴风影音5

Beijing Baofeng Technology Co., Ltd.

This is a setup and installation application. The file has been seen being downloaded from dl.mojing.cn.
Publisher:
北京暴风科技股份有限公司  (signed by Beijing Baofeng Technology Co., Ltd.)

Product:
暴风影音5

Description:
暴风影音飞屏应用程序

Version:
5.44.1230.5222

MD5:
e00b2149eecfac85da0834212865d015

SHA-1:
b280d7f4e9ef57318bdfb3ab9239249d2b234c90

SHA-256:
bd9c76d7bc65c792e0487ec2ec2fc0002212a3af68cb2ef57cf8e40de614fd74

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/28/2024 8:57:35 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Application.Win32.Amonetize.NE
23784

Dr.Web
MULDROP.Trojan
9.0.1.092

File size:
4.4 MB (4,570,984 bytes)

Product version:
5.44.1230.5222

Copyright:
Copyright (C) 2007-2015 北京暴风科技股份有限公司

Original file name:
FPMJInst.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/5/2015 8:00:00 AM

Valid to:
4/6/2016 7:59:59 AM

Subject:
CN="Beijing Baofeng Technology Co., Ltd.", OU=在线QA, O="Beijing Baofeng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F5A9D93D770229C503B8355B15B6DF0

File PE Metadata
Compilation timestamp:
8/24/2015 11:11:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:DFXDq70OCbKV9YxgOrLPNnWkhiy5qld+uMKESIQKDbzgDSTJTM:9PbKVvIL3hN5gnDESilTJTM

Entry address:
0x4ABF6

Entry point:
E8, E1, 74, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 0A, 6A, 00, FF, 75, 08, E8, 28, 77, 00, 00, 83, C4, 0C, 5D, C3, 8B, FF, 55, 8B, EC, 5D, E9, DF, FF, FF, FF, FF, 35, D0, B6, 47, 00, FF, 15, F4, 12, 46, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, DB, 0D, 00, 00, 6A, 01, 6A, 00, E8, 43, 77, 00, 00, 83, C4, 0C, E9, 08, 77, 00, 00, 8B, FF, 55, 8B, EC, 8B, 55, 08, 53, 8B, 5D, 14, 56, 57, 85, DB, 75, 10, 85, D2, 75, 10, 39, 55, 0C, 75, 12, 33, C0, 5F, 5E, 5B, 5D, C3, 85, D2, 74, 07, 8B, 7D, 0C, 85, FF...
 
[+]

Entropy:
7.9247  (probably packed)

Code size:
381.5 KB (390,656 bytes)

The file setup.exe has been seen being distributed by the following URL.

Scan setup.exe - Powered by Reason Core Security