bitmessage.exe

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PyBitmessage’. The file has been seen being downloaded from bitmessage.org.
MD5:
388435ed4ef12d0dede411b37a9064df

SHA-1:
cb5721eafb555ff61ce3fd87d0bd33431ed6773f

SHA-256:
3e02dbf31960b5a8bb39cfed2d8b1740485e3cabe25ad6b084e0ed1809a46019

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 3:37:08 AM UTC  (today)

File size:
13.8 MB (14,476,210 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\bitmessage.org\bitmessage.exe

File PE Metadata
Compilation timestamp:
5/25/2012 11:26:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:2M6BLPqPqza49yVpur9XijZ0Xw5+fQbJfSEsnnad:2M6BLPqyAVpbN3IQt6z8

Entry address:
0x93B1

Entry point:
E8, 62, 5B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, C4, 41, 00, 89, 0D, 3C, C4, 41, 00, 89, 15, 38, C4, 41, 00, 89, 1D, 34, C4, 41, 00, 89, 35, 30, C4, 41, 00, 89, 3D, 2C, C4, 41, 00, 66, 8C, 15, 58, C4, 41, 00, 66, 8C, 0D, 4C, C4, 41, 00, 66, 8C, 1D, 28, C4, 41, 00, 66, 8C, 05, 24, C4, 41, 00, 66, 8C, 25, 20, C4, 41, 00, 66, 8C, 2D, 1C, C4, 41, 00, 9C, 8F, 05, 50, C4, 41, 00, 8B, 45, 00, A3, 44, C4, 41, 00, 8B, 45, 04, A3, 48, C4, 41, 00, 8D, 45, 08, A3, 54, C4, 41...
 
[+]

Code size:
75.5 KB (77,312 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PyBitmessage

Command:
C:\users\{user}\downloads\bitmessage.org\bitmessage.exe


The file bitmessage.exe has been seen being distributed by the following URL.

Scan bitmessage.exe - Powered by Reason Core Security