ctm_v5_setup.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.chikka.com and multiple other hosts.
MD5:
c821ba79922c077bbbd67bd596564fcd

SHA-1:
e612b2e6c0bdc4aa3b9abec378b6347673d71498

SHA-256:
1522e7148e269e7b30beac58b560f760542427de9a54b495ed49f4f7d56dbd48

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 2:38:51 PM UTC  (today)

File size:
2.3 MB (2,459,767 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\ctm_v5_setup.exe

File PE Metadata
Compilation timestamp:
6/7/2009 5:41:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:HmM1qwDJ0dyBFBSeX2cYMDY3R6ADVU60gxmJ5IiGufLdt1Twt:HmYqU1Dz2cYMDYDz5mJEQLdbu

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ctm_v5_setup.exe has been discovered within the following program.

Chikka Messenger  by Chikka
Chikka Text Messenger is the world’s first instant messaging desktop client to support communication with mobile phones via SMS, allowing users send free SMS messages to buddies. Users who register their mobile numbers can also receive messages on their phones whenever offline.
www.chikka.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file ctm_v5_setup.exe has been seen being distributed by the following 4 URLs.

http://www.chikka.com/pcinstaller

Scan ctm_v5_setup.exe - Powered by Reason Core Security