node.exe

Node.js

Joyent, Inc

This is a setup program which is used to install the application. The file has been seen being downloaded from nodejs.org.
Publisher:
Joyent, Inc  (signed and verified)

Product:
Node.js

Description:
Evented I/O for V8 JavaScript

Version:
0.12.0

MD5:
b96998f1d4b4d0f2044c27685ff3377e

SHA-1:
c54021b701cebc3ba713c920531ca4fdc96cf9fe

SHA-256:
f6c6ec910e60531ba5dacabd90f3305faf4a7d61f707286c8c01a124d9a8ac99

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 3:19:07 AM UTC  (today)

File size:
9 MB (9,414,528 bytes)

Product version:
0.12.0

Copyright:
Copyright Joyent, Inc. and other Node contributors. MIT license.

Original file name:
node.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\nodejs\node.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
11/20/2014 2:00:00 AM

Valid to:
11/21/2015 1:59:59 AM

Subject:
CN="Joyent, Inc", O="Joyent, Inc", L=San Francisco, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
54DEF11DABA5F782C77D9C8AC3CA2170

File PE Metadata
Compilation timestamp:
2/6/2015 10:46:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
98304:qVEGnRDbrbSgxfE9Ro7CA4CQ9am5BOjQ3pPVvYJXYooyj3PnlYaRyIaRQ:FGDbYjo7CqycsVvXyj3PlYaRyIH

Entry address:
0x4B2BE7

Entry point:
E8, 9B, D6, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 51, 8D, 45, F8, 50, FF, 15, F4, 21, 8F, 00, 8B, 45, F8, 8B, 4D, FC, 6A, 00, 05, 00, 80, C1, 2A, 68, 80, 96, 98, 00, 81, D1, 21, 4E, 62, FE, 51, 50, E8, 0F, D7, 00, 00, 83, FA, 07, 7C, 0E, 7F, 07, 3D, FF, 6F, 40, 93, 76, 05, 83, C8, FF, 8B, D0, 8B, 4D, 08, 85, C9, 74, 05, 89, 01, 89, 51, 04, C9, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 51, 8B, 55, 08, 57, 8B, F8, 3B, FA, 76, 6C, 8B, 4D, 0C, 8D, 04, 0A, 53...
 
[+]

Code size:
4.9 MB (5,180,416 bytes)

The file node.exe has been seen being distributed by the following URL.

Scan node.exe - Powered by Reason Core Security