rich(r).exe

MD5:
091765f847c37cf16a38cb592d2b8a70

SHA-1:
ee4cbdf79324d46e4bbc9fc29c53fdbda703ab88

SHA-256:
57e196dab85f1392b5dc739d6a366c1747151ff52bb9f5f286b8ad67fd20d3d9

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
5/12/2025 1:45:02 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
Heur.Suspicious
18012

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14327

File size:
2.4 MB (2,480,069 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\????\????????\rich(r).exe

File PE Metadata
Compilation timestamp:
4/13/2001 12:38:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:/0GhsO0nhn7YRdneypHpOR+4zQAMdhSa949F6s:/0G+LhEIuOA4amj

Entry address:
0x28704A

Entry point:
55, 8B, EC, 60, B8, B9, 70, 68, 00, 2D, 4A, 70, 68, 00, 03, 05, BA, 70, 68, 00, C7, 05, 4A, 70, 68, 00, E9, 00, 00, 00, A3, 4B, 70, 68, 00, 68, 09, 70, 68, 00, A0, 2D, 70, 68, 00, 3C, 01, 74, 07, B8, 00, 00, 00, 00, EB, 03, 8B, 45, 08, 50, E8, 33, 00, 00, 00, 83, C4, 08, 83, F8, 00, 74, 1C, C7, 05, 4A, 70, 68, 00, C2, 00, 00, 00, C7, 05, 4B, 70, 68, 00, 0C, 00, 00, 00, 50, A1, 29, 70, 68, 00, FF, D0, 61, 5D, EB, 06, 72, 16, 61, 13, 60, 0D, E9, FD, 4D, E5, FF, 55, 8B, EC, 81, EC, F8, 02, 00, 00, 56, 57, 8D...
 
[+]

Entropy:
7.8980

Developed / compiled with:
Microsoft Visual C++

Code size:
952 KB (974,848 bytes)

Scan rich(r).exe - Powered by Reason Core Security