reguse_installer.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from regusesoftware.s3.amazonaws.com.
MD5:
68fb60cd945a54bf0ba78fa2594f0878

SHA-1:
2dd2680a658565148fc92db40207aa52ee49eae8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 5:09:34 AM UTC  (today)

File size:
4.5 MB (4,768,784 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\documents and settings\admine\documenti\downloads\reguse_installer.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:s30IPAGnVNLw8VbqAyINaDjRuKCM8xJKH/DusPcWsT9Dp+sjj+pP:c9AIb1gCaZCM8xJKnzMjeZ

Entry address:
0x30CB

Entry point:
85, FA, 0F, B7, D9, 81, CD, AA, 42, 65, 4F, 0F, B7, CF, 10, CB, 88, E6, 69, E8, 75, E5, D9, D6, F6, C0, 5F, 69, F0, 54, 51, A7, 46, 8D, 35, 5C, 6E, D5, 93, 4B, FE, C3, BF, 8B, 07, 00, 00, 87, C9, 81, F7, AA, 37, 00, 00, 39, EA, 81, EF, 08, 0E, 00, 00, 20, D7, 81, C2, 73, E4, 72, A4, 28, E2, 33, C7, 3B, D5, B9, 9B, B7, C1, 4E, 87, C9, BA, CF, A4, A5, 36, 81, C1, 52, 5B, E3, 74, 74, 02, 23, EE, 88, DA, 86, CC, 85, D0, E8, 00, 00, 00, 00, 80, E6, F1, 87, C1, 87, C8, 8A, C4, EB, 0E, 89, FA, 8D, 0D, 4A, 8D, A6...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file reguse_installer.exe has been seen being distributed by the following URL.

Scan reguse_installer.exe - Powered by Reason Core Security