bitmessage.exe

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PyBitmessage’. The file has been seen being downloaded from bitmessage.org.
MD5:
b60f028ff79fab2491c41d619e8ab3b2

SHA-1:
f5534923f4327fcf5546f4eed1bf3431ff68e592

SHA-256:
c1544dea6f5bca3f15c33f1f7f9820c6ac764ac3bfd92cab369323028b0d7e3d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:49:55 AM UTC  (today)

File size:
14.1 MB (14,814,670 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/25/2012 4:26:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:GEClYqoMPqza4M1pulhcybnHHmZ0UuMc6ewqFOIgfO8rnq0:GEClYPMySp2OybH+IX6ewqfLCX

Entry address:
0x93B1

Entry point:
E8, 62, 5B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, C4, 41, 00, 89, 0D, 3C, C4, 41, 00, 89, 15, 38, C4, 41, 00, 89, 1D, 34, C4, 41, 00, 89, 35, 30, C4, 41, 00, 89, 3D, 2C, C4, 41, 00, 66, 8C, 15, 58, C4, 41, 00, 66, 8C, 0D, 4C, C4, 41, 00, 66, 8C, 1D, 28, C4, 41, 00, 66, 8C, 05, 24, C4, 41, 00, 66, 8C, 25, 20, C4, 41, 00, 66, 8C, 2D, 1C, C4, 41, 00, 9C, 8F, 05, 50, C4, 41, 00, 8B, 45, 00, A3, 44, C4, 41, 00, 8B, 45, 04, A3, 48, C4, 41, 00, 8D, 45, 08, A3, 54, C4, 41...
 
[+]

Entropy:
7.9946  (probably packed)

Code size:
75.5 KB (77,312 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PyBitmessage

Command:
C:\apps\bitmessage.exe


The file bitmessage.exe has been seen being distributed by the following URL.

Scan bitmessage.exe - Powered by Reason Core Security