hesoolver v2.6.4 ru.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from rghost.ru.
MD5:
85168f2195d4c52665ccced2bf1ae835

SHA-1:
e0de42026a2dbe7f911ef15cdd18ff1b36bf330a

SHA-256:
0bf3d56895e7453ced87dd2c3220e50bcdac1bb7466f64223e2c2942b613fdb9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 10:51:47 PM UTC  (today)

File size:
122 KB (124,928 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/25/2015 4:47:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
3072:sTEuqG+mV2krlKL64bEotiiaVKuXSyFYooN6IVlTCOUbEPAJFEx+92:sTEuqGUkrg64YotiZfXSboO6CTCOUbEq

Entry address:
0x12A0

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, D8, 14, 42, 00, E8, 98, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, F8, 14, 42, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, E8, 14, 42, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 5D, E9, 97, 45, 01, 00, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 83, EC, 38, C7, 05, 04, BA, 41, 00, 00, 80, 41, 00, C7, 05, F8, B9, 41, 00, 25, 00, 00, 00, C7, 05, 08, BA, 41, 00, 10, B0, 41, 00, E8, E3, 36, 00, 00, E8, 20, 8F, 00, 00, C7, 44...
 
[+]

Packer / compiler:
MingWin32

Code size:
89 KB (91,136 bytes)

The file hesoolver v2.6.4 ru.exe has been seen being distributed by the following URL.

Scan hesoolver v2.6.4 ru.exe - Powered by Reason Core Security