itchsetup.exe

The best way to play itch.io games

Open Source Developer, Amos Wenger

This is a setup and installation application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘itch’. The file has been seen being downloaded from nuts.itch.zone.
Publisher:
Itch Corp  (signed by Open Source Developer, Amos Wenger)

Product:
The best way to play itch.io games

Version:
0.13.2

MD5:
a9c29d4928f9124e7b2e76c00078b23a

SHA-1:
d644ef4273282a6ec09e9df34a3f6fa4ae0a71f7

SHA-256:
c194d3a6f9e897419c1f27df53d1c6cafc2b20a159307d2a36bc9ce44646fe7c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:56:06 AM UTC  (today)

File size:
44.7 MB (46,880,240 bytes)

Product version:
0.13.2

Copyright:
Copyright © 2016 Itch Corp

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\itchsetup.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
11/1/2015 10:16:38 PM

Valid to:
10/4/2016 11:02:39 AM

Subject:
E=amoswenger@gmail.com, CN="Open Source Developer, Amos Wenger", O=Open Source Developer, C=FR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
22CCC1926E8CECB9DD84046CADB6415F

File PE Metadata
Compilation timestamp:
1/16/2016 2:17:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:ZumB/R5Kn9TqtttgXEjCPOU67v0a68MzIVAoYjTLGqdRpSZJUEcYjTvUt0+XiJ:Zd5K8x7v0v8MzIuj/4JUgw0+XS

Entry address:
0xAD5E

Entry point:
E8, 48, 66, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 44, 99, 42, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 04, 84, 42, 00, 01, 0F, 82, 7F, 67, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83...
 
[+]

Entropy:
7.9980  (probably packed)

Code size:
109.5 KB (112,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
itch

Command:
C:\ProgramData\squirrelmachineinstalls\itch.exe --checkinstall


The file itchsetup.exe has been seen being distributed by the following URL.

Scan itchsetup.exe - Powered by Reason Core Security