reaper520-install.exe

Cockos Incorporated

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dw12.uptodown.com and multiple other hosts.
Publisher:
Cockos Incorporated  (signed and verified)

MD5:
f4f226fffbe7160f944368ff67a02df2

SHA-1:
e6281dd49b73670b683312f99cda619925a4c3fa

SHA-256:
fd24c10d6619acde9743b3c2c6fda4c9b05e6d3934bf656ba850ded9c6b2e02b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 12:38:28 PM UTC  (today)

File size:
8.8 MB (9,257,656 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\cockos.reaper.v5.20.incl.patch\cockos reaper v5.20 incl patch x32\reaper520-install.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/14/2016 10:00:00 PM

Valid to:
1/14/2021 9:59:59 PM

Subject:
CN=Cockos Incorporated, O=Cockos Incorporated, STREET=319 Lafayette Street, STREET="#255", L=New York, S=NY, PostalCode=10012, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7719736A3F6AA54CA85555CFCCC64643

File PE Metadata
Compilation timestamp:
4/2/2016 12:20:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:KdW9nWI8MDjMESSo4AgdYA6JqYeIVI7wWwg0rj0mD2qnCqFo14T6:L1WI84tAzedwWV0r3PnzO1h

Entry address:
0x326C

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 20, C7, 44, 24, 14, 30, 91, 40, 00, 89, 5C, 24, 1C, C6, 44, 24, 18, 20, FF, 15, B4, 70, 40, 00, FF, 15, B0, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 07, 2E, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, 80, 72, 40, 00, 56, E8, 83, 2D, 00, 00, 56, FF, 15, AC, 70, 40, 00, 8D, 74, 06, 01, 38, 1E, 75, EB, 6A, 0D, E8, DB, 2D, 00, 00, 6A, 0B, E8, D4, 2D, 00, 00, A3, 64, 3F, 42, 00, FF, 15, 38, 70, 40, 00, 53, FF, 15, 6C...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file reaper520-install.exe has been seen being distributed by the following 13 URLs.

https://dw12.uptodown.com/dwn/6NtwSlsyBBaiC-e2FjXQfQGUD-_8l9Rbk_umAp6bcWbh19UIhQrKODyu6PrDaMe2zL-i2GsIGa1ms2V5es39N8ZprRNhxWr5SrcFh2y79CC5FJKYQYKB8YJ2-cQ-VKvG/NeMdx_nbr65EklEAxnWAEP-fXkUh_h5ghqeFGSZAsPQmyFhp3SOtptcBgc6nzxKBFK7ZKxniIrEEp_JE_Az8QHKAJGa-Bw64WMQ--FQWLXwTQg55bw-vUVfmcEw1xmtM/dNMoQMUaLNfNp8nvjPcMCbUoTBDVFrwPDXYJgDmMg4X15G2uwpvWkcjwHkDYq79lfAp7jccyvCNQK3hi5xIX6bT7Irta5rOqjyVy6Nta0wNdCbkXG37BrB3wndW8UCv0/.../reaper-5-20-32-bit.exe

http://dw.uptodown.com/dwn/NWJ0Om6ZkIHA2Toa9cVwmNeb-XKpKIF1F8wSK4nLo5Yf2jnm933AfYmBZIVvfh7IFNeP_KtjLu5TTJ5zEkm-rbN8VN29LUYA9iZq0Wxsc9QQ4sopgOUx_CtdxnxhrXaZ/ZKJ6rVeZn9Zow7GOolGhjCp1bN70YiM05_WA6focJ857vv_BCEGUS-IIoAivwMZdTJ_ZqmBywwPnpELf208hNxwXPjrqdefjQphpYYjJybxfzcr7DQ39MTlc9uuutHsB/.../

https://dw.uptodown.com/dwn/kwtQ4OLG8zu9Oyq3A1SEus25VuVtIxFRjRNoWhIG0WQ5xebPtkd8g-Tca53oaL5GYfyGvixrWLLEGwZNPCdqz5AQAEd9yn0NJWybnVqVWSwHNMdA5NaJ84GGNjbevam5/iIej3T4wsSYLLQ71MTbf7NMfnGM17KHNHXqe9kmSPES9W4gI9xzCNuEL-3UWdjk1RdBzY1iDk9O_eZC9QAQfA-2wDPRDEJYL6FHkynrCbYFjND8Nic_h9fvxeQJ_YcHG/.../

https://dw12.uptodown.com/dwn/Uk2CQz6H7JAmhSast6ZmmRz_EXEUwpJXD1X-TmO4W_U0sbcIu3O4X6i8RhFo9RYig1ZP-O3Mi3izQXpNmdo-EF3QG80SONABoY9XYcGSDsNhvC2F8sR1TZsC4VBNkf5m/xMKvBXB-ObOZ6mU6AEvf0hANbcfGDAPKDOeVcvq7W5Mhf8FUJ5fU-1Iks6AAOE_pPx0G4Keok_jxiHgBW7Y5qdt8sIPkJHn5BzKrQh0HR5ez689A9CSMWmvlW4sDUciA/FUiSnxiVXzmKBPA39S7WTPNjkV-L_mgeN5jCIhCkFc6wMXxeVJsAlnOZmgX_TMv7ph6NDVzEPvBS-nZX5bsEID-SlvzHPJx89ik8vXS0nkf_elF7QAbb4o6vXf3ktcQI/.../reaper-5-20-32-bit.exe

https://dw.uptodown.com/dwn/OwCpH2xgu1Wp-SnMKxo8GUV_1wU4KNw85Ce-oA0XAjoWPPoIQ6Yoy-Vs1nsmUoRsAUvw3U-pPqFwQO1kko8gt_VF4wfr4b515HH5spfGc5Jo09knp0qHdRyrSKNSY-OI/8iy27ISmtBV0rYeaRrjVwPWJz2FuG8GEtjT67IKvdZbVNUZjVK-b3C1WqikKkGmTa2VYlTRaQfpnPLSzdCm0eK5wgolAcJJfLOP_abI5BVxqHrhEl8HTBDFbUA8GvXYs/oCgN2vyWKDT00KY1lgN_5UqqcblqDhGc6flrXQA1OTiCyTW4BB5dInY9Kij_IVRAzsj95LgCedybigKASl-oUfRG-HsPibsMNFof7nBDjMY6INKjO_CLkT3e8nZonzWh/.../

https://dw.uptodown.com/dwn/1ZyAtlq5BAuOFrB8WWoDsKGT5Z33W8g56qW8JnNmPnmxUkumAUiAiVfUOdcOOsBNmAaDeVG8z05ZGfl-s5RpEFIP3vv2kO7Qyb0Y6IVl0iAFBSa1WH4xdSTpvOXzbZ89/DZ7upt_-P73ni3_pmXfpU4YJufVTC4US3HlQZlgdNQCF3lNJIrD1uokOqQYJvqGXIfMJervRCxOPY5s-Ze4coMDvsYuktromTKV5v6ihSwKZrkVGzQ-5ncjR0wtGn89L/4U78WQtk3U65QuyeTMQnmqsKR54q-RrAxVAZSc-CsvXqGN7Qbe2a0Dxi_2LX49rfa_R-FmjRGZJxKr873tMuSWin1QodMkhe9fhmr3Qw65JgVNpZKBbnViprdEGDtBan/.../

https://dw.uptodown.com/dwn/BzuUTN0hh2JkkKLatRdVkgmqNMm551Z9BJORB0HIl27XjsXdvPZyBnAHCRkW9oGa99bGBidsp9KQ76e35yTf6Jrg27YyrZ82UXZe4krl69Vw3Oukf0rHzkHTijAkQY75/kgNAphD77lyqvFhbGCsltr2f07xu7uFrj_k8pmZ-vlwVCG0TggeXRPd9itWqFA0nW2qHgIOL6_poaEFVv2EeUkIsqOCO9xdl6Fe9tu0uNK4RyvG5z4FTT1sIirZZMXG7/aRx1f6nFrTQH9-Q91Ltyj5nqBZOQaYhXkcSLDHT7d3sRSolbX0KtvtOW-z8pKVjiYQGdvnBeFM2oPTrhKBNQdk5o4qoXn6UnLegOA2BLLnN9ofUX8h5Uy2UP51kn2pwj/.../

http://dw.uptodown.com/dwn/h6tyBsxz_2zaNXxQoywlLFSC-7UHwLE3ZmSL9UhtSCEPaRwvfoqmKdDnzrFga5fNHNLNijDoltS_CgKsqYqyWB6FZM4J0fzw-_4ig1CtIMFu1eTZT5ZE3aCWR2q5nqeO/X1hFKqfiUv2bnd_RyFSHIvC9wBn5K3FEPkyyBI0pvqk3OTw5cuEnTWGaGISPYCFnP4SOQvdFpj2ukwHcy3GpGu70Zc0IsMXyYxRLURUiTyVBbcqEcoCrOxZyQCzPsxjl/7AjW9QcsruU9eI7sfkLnyuBzoIip7WiPRHtrAdYa4d2rOTT1agB19cizt2QFnffUU6EH0T7V9W8PeqzRiEnQG8S6UYQLyDeadZidQCoF_0kwOnMi1NSl8eWc-legoxma/.../

https://dw1.uptodown.com/dwn/HwBbMx605WxtS9HFwW5FJgXhmLuse_99qQoCGRUEHan2IYeWHjnlAWvYK4ttruumZU-U2PnF-feA5IlVv1pw8kNF8xANMz0K1yLBSimxaTCB-DgGhPhcwIkuKYap_c1b/rJCCfW9muXWzXn-BoxlNjPwHYqdIE0Xr3N_vkmfYiv4GJF4HsqVM7gcHjMfDowepWRYCKGEK9Lo0zmWpzkRulcTwCNWMxtfduCu6G6JgUc5KhrF-s4LYSILjTASbPcYg/.../reaper-5-20-32-bit.exe

Scan reaper520-install.exe - Powered by Reason Core Security