ustreamproducer-2.0.2.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.ranchsendgift.com and multiple other hosts.
MD5:
678d023cc59865469ec03de10544d671

SHA-1:
a7fb1f0765035fd7d768ecc0b5527a8691aa20a3

SHA-256:
5cf24e5a7e2d8e0cfc108dca3459d1040b4105b9f9d6096e3e1adcf2850e96c0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:40:48 PM UTC  (a few moments ago)

File size:
32.3 MB (33,898,892 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\ustreamproducer-2.0.2.exe

File PE Metadata
Compilation timestamp:
10/10/2008 10:49:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:a1vMzYorN70UmlQ1Iu3AFR0PZzql0ekhscpq1F+CQmcAbb:a1UDBQ3UIRCtx0+Cdbb

Entry address:
0x30E3

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 58, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, 23, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 90, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 4C, 91, 40, 00, 68, 60, E3, 42, 00, E8, DA, 27, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, C8, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ustreamproducer-2.0.2.exe has been seen being distributed by the following 4 URLs.

http://www.ranchsendgift.com/hm1mVoMi_OLYLLIG9oV2r2Cdv9k5KSV3QXm7i9EGPBnu1kzfMrtxf bxyOcRr0I0xUwNfVPwplrbJgYfHGcDqUvd2kMBRpux2vivGsmcX1mFI1LpG7BCHEr2UDs2DCXihwxm4to58Eg7PNgX OWMFkW6qxYH3vgGJaqVgxP7whdMoAWmgNfozdZPuZqVKuk3yplxkPnD DDmdL0epCHSx4y9KXcIOg==-G00AAASybTFte5a6IV4ziYJOOWCvlaQBBngAuufwOaQEtXe6xih_l40ZbmftKG3z6JNqsrC Ybwc1eOaDw==

http://www.ranchsendgift.com/pU_l3aLWGOqKmBMgPFXgEAY75wTvnlXvoM35oDYSFvinW6 5fPN6UzM ZsIOKscvgGjcSky2WbMBAcaFp5_Cuig7J9PQmOmCAJ4CbS9pRnnGvc k95jqmquiKIjnUeM0COMJpBPQtpRuYXv7hI0i0utBWVubEDh8A79QSTAKttjZzv9vBR1kSyVlGmtEk8kYo7Hh8fae74htXve_p2IWcm_ty9Vilw==-G00AAASybTFte5a6IV4ziYJOOWCvlaQBBngAuufwOaQEtXe6xih_l40ZbmftKG3z6JNqsrC Ybwc1eOaDw==

http://www.ranchsendgift.com/78U531YtuqPyaE0IRSv8nlGv4cHlNrfIBKv_mG2cRrAfdRewHW3pN7Gmy k2iFy85cP328FLGnsHz5LzFwpDQuk2mcS5sFpBshYR_lv2uu77MNxj57kqoObtZiwyhj5C6gnYOUPEBdGf_6goBAeff4JU_r5r2Hm JzmYdfx4Ff9MG34r8mIPCG7fOA4MH0RjZXVN2a8RfUcEGy07 cMEwZ3tDb1mSu4WmvtdPxBCgHMq 3Y_LznvIgSXB8E0yoBSqb8qtmQm5tFUPYddrX_4QMrvnYQFltymrVUSkFA2jusqYZ DQFp79RVe6r8aWAMsGKwsONP7yg3JRtwJxKPEyIYb7DoxiKOk9JjCZigI7 dw5Ix4WOtvr8pkL1WOXhPyLbPs3792SNhoN41kN6iZJXbKPfiIbiyi5UZUGvEZu1RYV7XxGrwlnlowhBqkemSVRdbbc2q2d8Av3axEDGYYS6btJImxzXyZ3JrYe31redaLyQg_XZyAYsu2RZxtk2Hs nvWQlWRIkOXzH7XZVphO2 xkSJ0Q35Q_rh5e95C2LCkYy_JikwYSqOAb5zYFcegC r6zaE3-G00AAASybTFte5a6IV4ziYJOOWCvlaQBBngAuufwOaQEtXe6xih_l40ZbmftKG3z6JNqsrC Ybwc1eOaDw==-e

Scan ustreamproducer-2.0.2.exe - Powered by Reason Core Security