bitmessage.exe

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PyBitmessage’. The file has been seen being downloaded from bitmessage.org.
MD5:
f245879c0aacb8d57a872c8d26f0c84f

SHA-1:
8009b24f84ecc90fc05ee4fab34a6b96a23c759e

SHA-256:
f4444037f54a87d001f274b26048baf64eadfff6005422a62bfd339d44410d34

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:29:28 PM UTC  (today)

File size:
14.6 MB (15,298,071 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/25/2012 11:26:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:UJB4Bpyc6QAXP8s0PZzZJimZ05vgPXAZ4KLHFh/vh1:0Bayv5oZzZ/k4PXI7h/vh1

Entry address:
0x93B1

Entry point:
E8, 62, 5B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, C4, 41, 00, 89, 0D, 3C, C4, 41, 00, 89, 15, 38, C4, 41, 00, 89, 1D, 34, C4, 41, 00, 89, 35, 30, C4, 41, 00, 89, 3D, 2C, C4, 41, 00, 66, 8C, 15, 58, C4, 41, 00, 66, 8C, 0D, 4C, C4, 41, 00, 66, 8C, 1D, 28, C4, 41, 00, 66, 8C, 05, 24, C4, 41, 00, 66, 8C, 25, 20, C4, 41, 00, 66, 8C, 2D, 1C, C4, 41, 00, 9C, 8F, 05, 50, C4, 41, 00, 8B, 45, 00, A3, 44, C4, 41, 00, 8B, 45, 04, A3, 48, C4, 41, 00, 8D, 45, 08, A3, 54, C4, 41...
 
[+]

Entropy:
7.9945  (probably packed)

Code size:
75.5 KB (77,312 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PyBitmessage

Command:
C:\users\{user}\desktop\bitmessage.exe


The file bitmessage.exe has been seen being distributed by the following URL.

Scan bitmessage.exe - Powered by Reason Core Security