HipChatVideo.exe

AddLive

LiveFoundry Inc

The executable HipChatVideo.exe, “HipChat Video Plugin Installer” has been detected as malware by 6 anti-virus scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
LiveFoundry Inc.  (signed by LiveFoundry Inc)

Product:
AddLive

Description:
HipChat Video Plugin Installer

Version:
3.0.2.19

MD5:
af2040a23fcb9ae5f45d0b1fb0205b27

SHA-1:
9dd08cfbafdb6a46ac428b5e39b3bd4e2057c04b

SHA-256:
a6080ce2eeacf51a3f97b386291d6236491580e55236759689e583060da6c703

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/29/2024 4:23:05 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/DH
2016.0.3217

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

Kaspersky
HEUR:Trojan.Win32.KillFiles
14.0.0.2578

McAfee
Artemis!AF2040A23FCB
5600.6873

Panda Antivirus
Trj/Chgt.N
15.01.27.08

Trend Micro House Call
Suspicious_GEN.F47V1128
7.2.27

File size:
3.4 MB (3,544,904 bytes)

Product version:
3.0.2.19

Original file name:
HipChatVideo.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\hipchatvideo.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/26/2014 5:41:31 PM

Valid to:
1/12/2016 11:35:22 AM

Subject:
E=support@addlive.com, CN=LiveFoundry Inc, OU=IT, O=LiveFoundry Inc, L=San Francisco, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121CB331CBB3F504B14359C97C437F54B56

File PE Metadata
Compilation timestamp:
11/27/2014 7:40:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:PPYjIdPkqtIDo8zNEvhHY9eT3zHNzpQBcCup1XiBmYi1TlLKcXah6J2A5AeqVno6:PQMdt88hR3z9uTshl7J2ASeGnos

Entry address:
0x5F473

Entry point:
E8, 40, C0, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8D, 45, 14, 50, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 1A, 3F, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, 53, FF, 75, 10, 8D, 4D, F0, E8, 06, FC, FF, FF, 33, DB, 39, 5D, 08, 75, 2B, E8, 14, 4B, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 18, F9, FF, FF, 83, C4, 14, 38, 5D, FC, 74, 07, 8B, 45, F8, 83, 60, 70, FD, B8, FF, FF, FF, 7F, EB, 5D, 39, 5D, 0C, 74, D0, 8B, 45, F0, 8B, 48, 10, 3B, CB, 75, 0F, FF, 75, 0C...
 
[+]

Entropy:
7.8071  (probably packed)

Code size:
564.5 KB (578,048 bytes)

Remove HipChatVideo.exe - Powered by Reason Core Security