xbmc-13.1-gotham.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
MD5:
9cf4f51ea71dec1d1214be803aa0f399

SHA-1:
0f1e1809d7e0e9396234f88676e3adb1c2b7653c

SHA-256:
99f060167649cd1e99b167ecffb5eb6781700b8db7399b544fc40ddf7f743719

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 6:48:40 AM UTC  (today)

File size:
60.8 MB (63,722,695 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\xbmc-13.1-gotham.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:5x3i1g9uGYDJhdhdWCIN97vRim4eqWkNOYPfEHG3KgfO4el0U:5x3nuGY7dWFN9D14WdYP8HERNez

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file xbmc-13.1-gotham.exe has been discovered within the following program.

XBMC  by Team XBMC
XBMC is a free and open source media player application developed by the XBMC Foundation, a non-profit technology consortium. XBMC is available for multiple operating-systems and hardware platforms, featuring a 10-foot user interface for use with televisions and remote controls.
xbmc.org
About 9% of users remove it
 
Powered by Should I Remove It?

The file xbmc-13.1-gotham.exe has been seen being distributed by the following 32 URLs.

https://dw.uptodown.com/dwn/MxQ5RAFpSyOzyQI5PrljsLUy0d-Ut5Ct2KzQMwu1AqygKe0WMeTNmif2Bm2fkS-7ZIXKn1wH50lIKeDAMVJIN_kQwDu7XOufIvqZ0IVifuUSvm1fWOz4a5LeuaCt3lpO/Up_HUjUk6303KXASyWqgcDt60b4QbvYfLEg_VBPbvzsTjRO0XDKwIx77FLkMv4Yu7GSmq8ju58NyyI8gLcW0WC4nE115EFJ6AxNKI2XEbZcaYRXkM6vnn8sOe5S0HYMP/Or_i0sqvS118On4fc8_8d2mFPytxvMcw49y2ZLekibz9VGD7VBr5cNz76y541OqaspX0-TyvHBjs3-c26lL8mPmtK8DvFRqDN6zfMnwHgWJ0_9YqbAs351VpBwre1nP7/.../

http://mirror.yandex.ru/mirrors/xbmc/releases/.../xbmc-13.1-Gotham.exe

http://installs.innovativesys.co/.../xbmc-13.1-Gotham.exe&u={9FC52C6A-CB13-44CC-92F3-DA97262290E8}

https://dw.uptodown.com/dwn/zvUo43Kj0x3NdtdWVUU1JgaNbkMLz5Eg1uB4AIC2QRtAMb6_r_HL026FqAQ4qJ4R5IvgTm7rNbopEukYBYKSTgDdnSXnMKlYiaB3QAgZbmFevNxDPgdXQdkV1wnOulQR/drZv3hAJz5A3v_mqvvZz6ypvlG4Dijju_k1sMaom3wopUMsY-x_2qF2g_GVAmfeTWGTvArPHE9rlQZ95tCyMUIOrer8A9LmhvVceGdj2Ynp4I_bsaiG7F9ZZyCl-qz5q/lKa3C_byGZQ1Y69UZb1v9iTwNGRpUNqda80BPhUSxRC5muX4EMwYNM-SBjgYkFkuXV6mmdiQxSUWk8Y-c0Ci3um9tr8BTmSNTWsfBueQQEe4bDBR8lhZCZ39bTrp2dgj/.../

http://64.50.236.52/pub/xbmc/releases/.../xbmc-13.1-Gotham.exe

Latest 30 of 32 download URLs

Scan xbmc-13.1-gotham.exe - Powered by Reason Core Security