TurboMeetingStarter.exe

TurboMeeting Starter

RHUB Communications Inc

This is a setup program which is used to install the application. The file has been seen being downloaded from meeting.logitech.com.
Publisher:
RHUB Communications, Inc.  (signed by RHUB Communications Inc)

Product:
TurboMeeting Starter

Description:
TurboMeetingStarter

Version:
1.0

MD5:
f973faa80b42b99df09163a4fd672e12

SHA-1:
a6b3162f537854649f52fce781a573ba809805d4

SHA-256:
95b327843f8d00207dec4d67a6b96898fa1297765ff198c8994b9ea327ca270d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/12/2025 12:48:36 PM UTC  (today)

File size:
631.4 KB (646,544 bytes)

Product version:
1.0

Copyright:
Copyright (c) 2003-2013

Original file name:
TurboMeetingStarter.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\turbomeetingstarter.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/6/2013 7:00:00 PM

Valid to:
2/7/2015 6:59:59 PM

Subject:
CN=RHUB Communications Inc, O=RHUB Communications Inc, L=San Jose, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6E50EEB4A8371F48DA665C632DA4D1DC

File PE Metadata
Compilation timestamp:
4/21/2014 12:09:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:WY2DTuPNeF4+YADWcSrMJ+9lhM5qXgPVTnRkTvayD4dU1v:vHC4fnvX0VWTvV4dU1v

Entry address:
0x34610

Entry point:
E8, AA, 93, 00, 00, E9, 7F, FE, FF, FF, FF, 35, 98, E3, 48, 00, FF, 15, 58, 02, 46, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, A6, 8B, 00, 00, 6A, 01, 6A, 00, E8, A3, 98, 00, 00, 83, C4, 0C, E9, BA, 98, 00, 00, 56, 6A, 04, 6A, 20, E8, D7, 9A, 00, 00, 59, 59, 8B, F0, 56, FF, 15, 5C, 02, 46, 00, A3, 60, 1B, 49, 00, A3, 5C, 1B, 49, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 0C, 68, E0, AA, 47, 00, E8, 81, 71, 00, 00, E8, 30, 79, 00, 00, 83, 65, FC, 00, FF, 75, 08, E8, 23, 00, 00, 00...
 
[+]

Code size:
379.5 KB (388,608 bytes)

The file TurboMeetingStarter.exe has been seen being distributed by the following URL.

Scan TurboMeetingStarter.exe - Powered by Reason Core Security