osu!.exe

osu!

Dean Herbert

This is the uninstaller utility registered in the Windows Control Panel for the program osu! by ppy Pty Ltd. The file has been seen being downloaded from m1.ppy.sh and multiple other hosts.
Publisher:
ppy  (signed by Dean Herbert)

Product:
osu!

Version:
1.3.3.7

MD5:
7d5cde9324671ad20452ba470e0031f5

SHA-1:
074863d41c1242c5815e216ebed84a0ab8bebb7d

SHA-256:
c8bfce86356afc5fff4913b11b1bf47d7c73a9aa0dc89b068704e66bc343f956

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 2:07:18 PM UTC  (today)

File size:
3.1 MB (3,285,560 bytes)

Product version:
1.3.3.7

Copyright:
ppy 2007-2015

Original file name:
osu!.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\osu!\osu!.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/22/2015 5:00:00 PM

Valid to:
9/22/2018 4:59:59 PM

Subject:
CN=Dean Herbert, O=Dean Herbert, STREET=41 Gregory Street, STREET=Wembley, L=Perth, S=WA, PostalCode=6014, C=AU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D3860BBF7C4FCFA5ED6D5F7775204FB9

File PE Metadata
Compilation timestamp:
11/27/2015 6:14:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:RMRxpYbhTO2def9Fe+XQk4onxozvi7CmFODBFHh2Zep+ao:RMRxpYbhy2ge+gQxoz7hVA

Entry address:
0x1F16E2

Entry point:
FF, 25, D2, 16, 5F, 00, 00, 00, 5F, 43, 6F, 72, 45, 78, 65, 4D, 61, 69, 6E, 00, 6D, 73, 63, 6F, 72, 65, 65, 2E, 64, 6C, 6C, 00, 2B, C8, 02, 00, 7B, 7A, 7D, 01, 00, 98, 03, 00, 1B, C8, 02, 00, 00, 98, 03, 00, EC, BD, 09, 9C, 25, 55, 79, 28, DE, 03, AE, 2C, 4A, 0C, 26, 88, 24, 56, 8F, C1, EE, 96, DE, 67, A5, A1, 80, DB, DB, 4C, 43, 6F, F6, ED, 99, 11, 18, 6C, EB, DE, 5B, B7, BB, 98, 7B, AB, 2E, 55, 75, A7, E7, 82, 88, 2B, 3C, 77, 11, F5, 69, DC, A3, 31, AE, 21, 2A, 51, 34, 46, 09, 10, F5, 19, 77, 13, 7D, C6...
 
[+]

Entropy:
6.3951

Code size:
2.9 MB (3,080,704 bytes)

Program Uninstaller
Program name:
osu!

Display publisher:
ppy Pty Ltd

Display version:
latest

Uninstall string:
C:\users\{user}\appdata\local\osu!\osu!.exe -uninstall


The file osu!.exe has been seen being distributed by the following 3 URLs.

Scan osu!.exe - Powered by Reason Core Security