× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ac85032ffb2f22d6d0f903217e73bbdcacd4ac5a0197bd7e69b13709a7a1b70f
File name: ffmpeg.exe
Detection ratio: 0 / 59
Analysis date: 2017-06-22 12:06:30 UTC ( 5 months ago )
Antivirus Result Update
Ad-Aware 20170622
AegisLab 20170622
AhnLab-V3 20170622
Alibaba 20170622
ALYac 20170622
Antiy-AVL 20170622
Arcabit 20170622
Avast 20170622
AVG 20170622
Avira (no cloud) 20170622
AVware 20170622
Baidu 20170622
BitDefender 20170622
Bkav 20170622
CAT-QuickHeal 20170622
ClamAV 20170622
CMC 20170619
Comodo 20170622
CrowdStrike Falcon (ML) 20170420
Cyren 20170622
DrWeb 20170622
Emsisoft 20170622
Endgame 20170615
ESET-NOD32 20170622
F-Prot 20170622
F-Secure 20170622
Fortinet 20170622
GData 20170622
Ikarus 20170622
Sophos ML 20170607
Jiangmin 20170622
K7AntiVirus 20170622
K7GW 20170622
Kaspersky 20170622
Kingsoft 20170622
Malwarebytes 20170622
McAfee 20170622
McAfee-GW-Edition 20170622
Microsoft 20170622
eScan 20170622
NANO-Antivirus 20170622
nProtect 20170622
Palo Alto Networks (Known Signatures) 20170622
Panda 20170621
Qihoo-360 20170622
Rising 20170622
SentinelOne (Static ML) 20170516
Sophos AV 20170622
SUPERAntiSpyware 20170622
Symantec 20170622
Symantec Mobile Insight 20170621
Tencent 20170622
TheHacker 20170621
Trustlook 20170622
VBA32 20170622
VIPRE 20170622
ViRobot 20170622
Webroot 20170622
WhiteArmor 20170616
Yandex 20170621
Zillya 20170619
ZoneAlarm by Check Point 20170622
Zoner 20170622
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows command line subsystem.
FileVersionInfo properties
Copyright
FFmpeg is a trademark of Fabrice Bellard, originator of the FFmpeg project

Product FFmpeg
Original name ffmpeg.exe
Internal name ffmpeg.exe
File version N-49746-gda726a8-Sherpya
Description FFmpeg video converter
Comments FFmpeg video converter
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-02-09 15:31:38
Entry Point 0x000014D0
Number of sections 10
PE sections
PE imports
CryptReleaseContext
CryptGenRandom
CryptAcquireContextA
capCreateCaptureWindowA
capGetDriverDescriptionA
AVIFileGetStream
AVIStreamRead
AVIFileInfoA
AVIStreamReadFormat
AVIFileInit
AVIFileExit
AVIStreamInfoA
AVIFileOpenA
AVIStreamRelease
AVIFileRelease
PeekNamedPipe
GetLastError
GetStdHandle
EnterCriticalSection
ReleaseMutex
GetSystemInfo
SetThreadContext
LoadLibraryW
TryEnterCriticalSection
ResumeThread
FreeLibrary
QueryPerformanceCounter
WaitForSingleObject
GetProcessTimes
SetConsoleTextAttribute
TlsAlloc
GetHandleInformation
GetModuleFileNameA
LoadLibraryA
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
SetThreadPriority
GetCurrentProcessId
ReleaseSemaphore
OpenProcess
GetCommandLineW
WideCharToMultiByte
UnhandledExceptionFilter
MultiByteToWideChar
VirtualProtect
SetProcessAffinityMask
GetProcAddress
GetConsoleScreenBufferInfo
GetThreadContext
GetCurrentThread
SuspendThread
CreateMutexA
QueryPerformanceFrequency
CreateSemaphoreA
CreateThread
MapViewOfFile
GetModuleHandleA
SetUnhandledExceptionFilter
GetStartupInfoA
CloseHandle
GetSystemTimeAsFileTime
CreateFileMappingA
DuplicateHandle
WaitForMultipleObjects
GetThreadPriority
SetEvent
LocalFree
TerminateProcess
GetProcessAffinityMask
GetTimeZoneInformation
ResetEvent
InitializeCriticalSection
UnmapViewOfFile
VirtualQuery
VirtualFree
CreateEventA
TlsGetValue
Sleep
TlsSetValue
GetTickCount
GetCurrentThreadId
VirtualAlloc
SetLastError
LeaveCriticalSection
GetProcessMemoryInfo
CommandLineToArgvW
SendMessageA
GetWindowLongA
MessageBoxA
SetWindowLongA
DestroyWindow
getaddrinfo
htonl
shutdown
accept
ioctlsocket
WSAStartup
freeaddrinfo
connect
getsockname
getpeername
select
gethostname
getsockopt
closesocket
ntohl
send
WSAGetLastError
listen
__WSAFDIsSet
WSACleanup
getnameinfo
recv
setsockopt
socket
bind
recvfrom
sendto
__lconv_init
fseek
fclose
strtoul
fflush
isxdigit
_fmode
strtol
fputc
wcscmp
strtok
fwrite
_wcsdup
fputs
isspace
_close
ceil
_isatty
__dllonexit
strrchr
strstr
_write
memcpy
perror
memmove
signal
_get_osfhandle
_mkdir
_initterm
strcmp
memchr
strncmp
_kbhit
toupper
fgetc
_hypot
memset
strcat
cosh
_setmode
fgets
__pioinfo
strchr
asin
fopen
clock
fgetpos
fsetpos
ftell
exit
sprintf
_unlink
_wsopen
_acmdln
strcspn
ferror
gmtime
free
ungetc
_fstati64
sinh
__getmainargs
_lseeki64
_vsnprintf
putchar
_read
strcpy
bsearch
islower
acos
isupper
_ftime
_iob
_sopen
rand
realloc
__doserrno
_tempnam
_setjmp3
_access
printf
_getch
_rmdir
strncpy
getchar
_cexit
frexp
raise
puts
mktime
scanf
qsort
_open
_onexit
memcmp
__setusermatherr
log10
srand
_fdopen
_stricmp
getenv
atoi
vfprintf
atol
_winmajor
atof
tanh
localeconv
strerror
wcscpy
_beginthreadex
strspn
_strnicmp
localtime
vsprintf
rename
malloc
sscanf
fread
abort
fprintf
tan
feof
_endthreadex
_amsg_exit
floor
strlen
_vscprintf
_lock
__initenv
_strdup
_fileno
strncat
longjmp
tolower
atan
_unlock
strpbrk
isgraph
calloc
_exit
_errno
atan2
_filelengthi64
strftime
time
setvbuf
__set_app_type
CoUninitialize
CoTaskMemFree
CoCreateInstance
CoInitialize
CoTaskMemAlloc
Number of PE resources by type
RT_ICON 5
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 7
PE resources
ExifTool file metadata
libavformat
54.61.104

SpecialBuild
http://oss.netfarm.it/mplayer-win32.php

libavcodec
54.91.102

SubsystemVersion
4.0

Comments
FFmpeg video converter

LinkerVersion
2.22

ImageVersion
1.0

FileSubtype
0

FileVersionNumber
1.0.0.0

LanguageCode
Neutral

FileFlagsMask
0x0000

FileDescription
FFmpeg video converter

CharacterSet
Unicode

InitializedDataSize
17490432

EntryPoint
0x14d0

OriginalFileName
ffmpeg.exe

MIMEType
application/octet-stream

LegalCopyright
FFmpeg is a trademark of Fabrice Bellard, originator of the FFmpeg project

FileVersion
N-49746-gda726a8-Sherpya

TimeStamp
2013:02:09 16:31:38+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
ffmpeg.exe

UninitializedDataSize
5634560

OSVersion
4.0

FileOS
Win32

Subsystem
Windows command line

libavutil
52.17.101

MachineType
Intel 386 or later, and compatibles

CodeSize
11812352

ProductName
FFmpeg

ProductVersionNumber
1.0.0.0

FileTypeExtension
exe

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 63d45500f386c30327da2838a36460a7
SHA1 80fc90eb2c0dde54d8c96cdaea049226f46e2bb6
SHA256 ac85032ffb2f22d6d0f903217e73bbdcacd4ac5a0197bd7e69b13709a7a1b70f
ssdeep
196608:V32VwC0uYV5iHs1Vp/0JLrsT9G0tUHy+Nqst4Z0tu25IaRyhCwF5Jq/vLNVkxWQf:fcJMAIXCwjJqXkxeZs8pFFOp8R9yY

authentihash 4e68d8f5c1ea5846c999c44ce9f07c4bcc1cbc4d7f0096dd497ec27ec689b88b
imphash 17f46c33f9f441c6fc5f38e207841272
File size 16.8 MB ( 17602048 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (console) Intel 80386 32-bit

TrID InstallShield setup (54.3%)
Win64 Executable (generic) (34.8%)
Win32 Executable (generic) (5.6%)
Generic Win/DOS Executable (2.5%)
DOS Executable Generic (2.5%)
Tags
peexe

VirusTotal metadata
First submission 2016-01-13 05:41:47 UTC ( 1 year, 10 months ago )
Last submission 2017-06-22 12:06:30 UTC ( 5 months ago )
File names ffmpeg.exe.3188.dr
ffmpeg.exe
ffmpeg.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.