jitsi-latest-x86.exe

Jitsi

BlueJimp

This is a setup and installation application. The file has been seen being downloaded from ofire.dream-cyber.com and multiple other hosts.
Publisher:
jitsi.org  (signed by BlueJimp)

Product:
Jitsi

Description:
Jitsi Setup

Version:
2.8.5426

MD5:
74e5f7dc010c01b67dab09d5955e0637

SHA-1:
7eb03a90c17fffd43311d79919784ab4f4b41b3f

SHA-256:
9cf2a12d2f2a40f392e42eab131b4b65c8ffdf8626f2cd6924922ed7c2e0c3e3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 8:20:20 PM UTC  (today)

File size:
53 MB (55,571,160 bytes)

Product version:
2.8.5426

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\jitsi-latest-x86.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/8/2013 3:49:20 PM

Valid to:
11/12/2016 12:19:44 AM

Subject:
CN=BlueJimp, O=BlueJimp, L=Schiltigheim, C=FR

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B8F26C76CD24D

File PE Metadata
Compilation timestamp:
3/19/2015 9:09:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.21

CTPH (ssdeep):
1572864:HXt376CjsAlnNtMAnSm+rHw13IafXap0nnn4Nn36jTJ5x:3t37ptNRnS3rsIafWgnn4t6N

Entry address:
0x1140

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 02, 00, 00, 00, FF, 15, 0C, 33, 42, 00, E8, C8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, 0C, 33, 42, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 53, 83, EC, 14, 8B, 45, 08, 8B, 00, 8B, 00, 3D, 91, 00, 00, C0, 77, 3B, 3D, 8D, 00, 00, C0, 72, 4B, BB, 01, 00, 00, 00, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 08, 00, 00, 00, E8, 67, 8D, 01, 00, 83, F8, 01, 0F, 84, FF, 00, 00, 00, 85, C0...
 
[+]

Code size:
100.5 KB (102,912 bytes)

The file jitsi-latest-x86.exe has been seen being distributed by the following 2 URLs.

Scan jitsi-latest-x86.exe - Powered by Reason Core Security