bit_che_2_0_60_install.exe

Bit Che

Convivea Inc.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from download2103.mediafire.com and multiple other hosts.
Publisher:
Convivea Inc.   (signed by Convivea Inc.)

Product:
Bit Che

Description:
Bit Che Installer

Version:
2.0.60

MD5:
f74986a00ddb5d8e4fa9b75715b84dc9

SHA-1:
7a99df9c8f05a313ee46f24c1f71583565fed548

SHA-256:
d0802bf47487cea5dd2c8e1dc5ec011d58f83e431713bdbeb5f053ddf6798d66

Scanner detections:
8 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/23/2024 2:52:37 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9958749
1115

Bitdefender
Trojan.Generic.9958749
1.0.20.75

Bkav FE
W32.Clod056.Trojan
1.3.0.4613

Emsisoft Anti-Malware
Trojan.Generic.9958749
8.14.01.15.03

G Data
Trojan.Generic.9958749
14.1.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

MicroWorld eScan
Trojan.Generic.9958749
15.0.0.45

nProtect
Trojan.Generic.9958749
14.01.13.01

File size:
2.3 MB (2,436,392 bytes)

Product version:
2.0 build 60

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/10/2013 2:00:00 AM

Valid to:
4/11/2015 1:59:59 AM

Subject:
CN=Convivea Inc., OU="Chip Warner ", O=Convivea Inc., STREET=PO Box 5867, STREET=Newport Beach, L=Newport Beach, S=CA, PostalCode=92662, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
30B7F76BAD719B5D18ABDAA9F2CE3BFF

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:V965e3oF/QvqkIsVLugpdEin76GVQnoBip0Y8nZRMC5V4g8YyiDUjXK:z65syMIqLxp3nejn1mY8Zf5MYfUjXK

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file bit_che_2_0_60_install.exe has been seen being distributed by the following 37 URLs.

http://download2103.mediafire.com/elmgulvg3nsg/.../bit_che_ 2.0.exe

https://bit-che.de.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAPNbFIbvPqwG59DNzhKGKPopOS/.../l5U3UKPtWpiNimxUZH3Jr6HGtrBRD5cvw1jlKkwKJKS42h9Ytp4QacsIrB1K6d34=

http://download962.mediafire.com/hhluhx95rrfg/.../bit_che_ 2.0.exe

https://bit-che.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/.../AO2TiksFcecgEJYpkoajE1YWCLLCQxs5Ll0Mho=

https://bit-che.nl.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAPNbFIbvPqwG59DNzhKGKPopOS/.../l5U3UKPtWpiNimxUZH3Jr6HGtrBRD5cvw1jlKkwKJKS42h9Ytp4QacsIrB1K6d34=

https://bit-che.en.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAPNbFIbvPqwG59DNzhKGKPopOS/.../l5U3UKPtWpiNimxUZH3Jr6HGtrBRD5cvw1jlKkwKJKS42h9Ytp4QacsIrB1K6d34=

https://bit-che.it.softonic.com/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAPNbFIbvPqwG59DNzhKGKPopOS/.../l5U3UKPtWpiNimxUZH3Jr6HGtrBRD5cvw1jlKkwKJKS42h9Ytp4QacsIrB1K6d34=

https://mega.nz/temporary/.../k0ZCyASQ

http://download2115.mediafire.com/mhn72yn1h65g/.../bit_che_ 2.0.exe

http://server3.xnavigation.net/dl/eTLPN/891/13900/defa/.../bit-che

Latest 30 of 37 download URLs

Scan bit_che_2_0_60_install.exe - Powered by Reason Core Security