atom.exe

A hackable text editor for the 21st Century.

GitHub, Inc

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘atom’. The file has been seen being downloaded from atom.io.
Publisher:
GitHub Inc.  (signed by GitHub, Inc)

Product:
A hackable text editor for the 21st Century.

Version:
1.0.7

MD5:
4d47fb08cb9bec37906515197dd0eeed

SHA-1:
47c5f3085e561ad09337d15c060a0f19ecfdc33b

SHA-256:
f0f750bb0e0053afa2240f04b8f912c34f24b712dd55a7e56aeac352e482462e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/29/2024 4:40:05 AM UTC  (today)

File size:
71.9 MB (75,389,192 bytes)

Product version:
1.0.7

Copyright:
Copyright (C) 2014

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\squirrelmachineinstalls\atom.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/8/2013 1:00:00 PM

Valid to:
6/7/2016 11:59:59 AM

Subject:
CN="GitHub, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="GitHub, Inc", L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2EA078CF4DAE81459313B225E26B568B

File PE Metadata
Compilation timestamp:
7/29/2015 12:22:47 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
1572864:5dj5WTzejDJepWGKxyBKo0AKl45BTpszmtlXPxhoaLUWlBlx4yQ2:r5Wn2DJAWG3KzE5BT9zXPxiTWfl2B2

Entry address:
0xAD35

Entry point:
E8, D1, 65, 00, 00, E9, 7F, FE, FF, FF, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 44, 99, 42, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 04, 84, 42, 00, 01, 0F, 82, 0F, 67, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06...
 
[+]

Entropy:
7.9988  (probably packed)

Code size:
109.5 KB (112,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
atom

Command:
C:\ProgramData\squirrelmachineinstalls\atom.exe --checkinstall


The file atom.exe has been seen being distributed by the following URL.

Scan atom.exe - Powered by Reason Core Security