ams-beauty-studio-1-87-32-bits.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.ranchsendgift.com and multiple other hosts.
MD5:
81350c522e9bddb1c4ab7885f360e38f

SHA-1:
868c0a8d092519b7f89edba6023c428b38d39d14

SHA-256:
e0df04e90f8861ad9c597258b78c44f51f1db352c52fc35b14b50b9021940cda

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:26:28 AM UTC  (today)

File size:
3 MB (3,115,817 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\ams-beauty-studio-1-87-32-bits.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:0W5ajgekTjIS76F9fmJbBOV4CZfinlAI9vNeJlDrBzmGXhnmt4fga54Xg8XwANqO:0klHAb5V6lA4vNElPDia5ETNqM6wrHGm

Entry point:
50, 4B, 03, 04, 14, 00, 00, 00, 08, 00, 90, 66, 9E, 3A, 1D, 19, 6E, F2, BC, 01, 00, 00, 14, 03, 00, 00, 0A, 00, 00, 00, 52, 65, 61, 64, 6D, 65, 2E, 74, 78, 74, 8D, 92, 41, 8F, D3, 40, 0C, 85, EF, 95, FA, 1F, BC, F7, 36, 15, 1C, 39, C1, 72, 5A, 24, C4, A1, 20, 8E, C8, 49, 9C, C4, EA, CC, 78, 98, F1, 6C, 09, BF, 1E, 3B, DD, 0A, 2D, 27, 6E, D1, C4, FE, FC, FC, 9E, 1F, 09, 9B, AE, 70, D6, 36, B2, C0, 7E, B7, DF, 7D, F8, 7C, 86, C7, 57, AF, 5C, 01, 21, D1, 15, 72, 91, B9, 60, 84, 49, 0A, 50, 5A, 30, 0D, 14, 29...
 
[+]

The file ams-beauty-studio-1-87-32-bits.exe has been seen being distributed by the following 2 URLs.

http://www.ranchsendgift.com/gwcXnIStPy2QJAnxX5fe84Ov8tNUSXEurS07dIfoJiTmKDMpgIUkUevT3kYfnbX6oTSs0V5BaVMUg4zWtGtRiyTqj6HkYSAkv3syZ3T rcghrPHgE8rKiVjjjX70ZUVCVpYvrrF20uWog3cI1fTtoI148tUZDS0aIzYMV3lj_ay62SgARlOmTil0XvWjfcTz7eBfO4V37uOM8jOTFbz56 YI WrVgw==-Gy0AAERPFtOVILUHQTA2BMAhBw7fNaEoDyZyYkmSfrfGZTTWAgIYq1Pjzr0wW8p7AQ==

Scan ams-beauty-studio-1-87-32-bits.exe - Powered by Reason Core Security