rsitx64.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.malwareremoval.com and multiple other hosts.
Version:
3, 3, 6, 1

MD5:
662c39fc1e27131551d557862cec47f0

SHA-1:
090ec97996bc7a881032205da1c795f217402bac

SHA-256:
39ddc5dfdce1d42681b416683eea8be0ae8e66b5015a97b2425d70631d1bd7d9

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 12:20:08 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
AU3SCRIPT:Malware.Banker!1.9DF6
23.00.65.131223

File size:
913.3 KB (935,175 bytes)

File type:
Executable application (Win64 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\rsitx64.exe

File PE Metadata
Compilation timestamp:
4/16/2010 9:47:52 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:B69zDWz/xwNqdlbrIX3JALF1QbOagrEGgtNryyCJuDT/PNa0AYQ/HywlfeZbHI0:B2DW/xbHX2YIbCQsu3/PNL7Q/Hy+fi

Entry address:
0x1D47C

Entry point:
48, 83, EC, 28, E8, E7, C0, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 4D, 85, C0, 74, 75, 48, 2B, D1, 4C, 8B, CA, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, F6, C1, 07, 74, 1F, 8A, 01, 42, 8A, 14, 09, 48, FF, C1, 3A, C2, 75, 57, 49, FF, C8, 74, 4E, 84, C0, 74, 4A, 48, F7, C1, 07, 00, 00, 00, 75, E1, 4A, 8D, 14, 09, 66, 81, E2, FF, 0F, 66, 81, FA, F8, 0F, 77, D1, 48, 8B, 01, 4A, 8B, 14, 09, 48, 3B, C2, 75, C5, 48, 83, C1, 08, 49, 83, E8...
 
[+]

Code size:
599 KB (613,376 bytes)

The file rsitx64.exe has been seen being distributed by the following 3 URLs.

Scan rsitx64.exe - Powered by Reason Core Security