twainnew.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.ricoh.com and multiple other hosts.
MD5:
e6507580c05082daea6950d7d8ef2ae5

SHA-1:
ffcee0b7fb9a8cb772ac42a5f353f666ea30e4a7

SHA-256:
0c241f517b4242a54f09cbe3e3fb2f45c2ccfd73f5fac6ae9f5cba88745f1322

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 11:31:57 AM UTC  (today)

File size:
1.2 MB (1,262,103 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\twainnew.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24576:M/WjUg1RvwRRNSikxieZT8f8/ahCimfO0V9GIOz2MV6PtXl4I2:M/WjUgRvwROlbQj2pGZK31Xv2

Entry point:
4D, 5A, AB, 00, 04, 00, 00, 00, 02, 00, 00, 10, FF, FF, F0, FF, 00, 01, 00, 00, 00, 01, F0, FF, 1C, 00, 00, 00, 00, 00, 00, 00, EB, 79, 20, 00, 4C, 48, 41, 27, 73, 20, 53, 46, 58, 20, 32, 2E, 36, 37, 53, 20, 28, 63, 29, 20, 59, 6F, 73, 68, 69, 2C, 20, 31, 39, 39, 35, 0D, 0A, 00, 52, 65, 6E, 61, 6D, 65, 20, 74, 6F, 20, 45, 58, 45, 2E, 45, 58, 45, 00, 2E, 45, 58, 54, 00, 4F, 76, 65, 72, 77, 72, 69, 74, 65, 20, 00, 5B, 59, 2F, 4E, 5D, 20, 00, 42, 72, 6F, 6B, 65, 6E, 20, 66, 69, 6C, 65, 20, 00, 57, 72, 69, 74...
 
[+]

Entropy:
7.9986  (probably packed)

The file twainnew.exe has been seen being distributed by the following 2 URLs.

https://www.ricoh.com/r_dc/pages/.../twainnew.exe

Scan twainnew.exe - Powered by Reason Core Security