r66668en.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from support.ricoh.com.
Version:
2. 2. 0. 0

MD5:
11b826a7293e26d803c6cdca6eb1309a

SHA-1:
3a53f47404bce658a99d4896b1db09a2ef54b1b7

SHA-256:
3aed2a7e19cb6f78a82e4854deac297395054ec67acd607b93cf19223e69e9eb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 9:47:17 AM UTC  (today)

File size:
3.8 MB (3,938,289 bytes)

Product version:
2, 2, 0, 0

Copyright:
Copyright © 2001-2010 RICOH COMPANY, LTD. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\r66668en.exe

File PE Metadata
Compilation timestamp:
4/7/2010 3:45:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:iOdNdAfRgutsd01Y+YdsOUK2xW7/2deB4Q+BVkI:3NGiwsdnyOh2xPeBfuVx

Entry address:
0x5E84

Entry point:
69, F2, 1D, 13, C6, 9A, 80, F1, D5, F3, 8B, CE, 4E, 68, 80, 3B, B3, 00, 52, 8A, DD, 1C, 52, 88, F3, 50, 51, 0F, AF, FA, 80, DC, 1D, E8, 12, 00, 00, 00, 4E, 49, 46, 02, EE, 21, FA, 03, FD, 85, C0, 77, 05, B3, 23, 48, 32, E8, 87, CE, BE, 4A, 2A, 42, 51, 3B, EF, 84, C1, 2A, EC, 35, FA, C3, 00, 00, 11, D9, 85, DA, 5F, EB, 02, FF, C0, F2, 0F, AF, CD, 8D, 35, D6, 68, A2, 1E, 4A, F6, C0, 2F, F6, C2, 03, 3B, CE, 09, C9, 10, E2, FE, CC, 0F, BE, F3, 4D, 8D, 35, 73, 5A, 99, 64, 69, F0, FE, C8, A7, C2, 30, D0, 8B, EF...
 
[+]

Entropy:
7.9895  (probably packed)

Code size:
80 KB (81,920 bytes)

The file r66668en.exe has been seen being distributed by the following URL.

Scan r66668en.exe - Powered by Reason Core Security