chemsk12.exe

ACD/Installer 2012

Advanced Chemistry Development Inc.

This is a setup and installation application. The file has been seen being downloaded from dl.dropboxusercontent.com and multiple other hosts.
Publisher:
Advanced Chemistry Development Inc.

Product:
ACD/Installer 2012

Description:
ACD/Installer application file

Version:
14.0.0.66576

MD5:
67ea9586cc119584d4628391d568dd43

SHA-1:
34bd65d40a5e8da2629b0e6b69d2ac56f7702265

SHA-256:
6f4f72a2fca57c29dafb57b16b9bf945db79f881ca275396aa058b5d45ea52a0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 11:32:45 AM UTC  (today)

File size:
38.2 MB (40,091,418 bytes)

Product version:
14

Copyright:
Copyright © ACD Inc. 1995-2013

Original file name:
SETUP.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\chemsk12.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:vuQrIAwAzTJg4pelBX4O4qN/u27SIuSI67wB6fHqIE9sGruUAOfFe:vuQrIAhNg4pMBoO4qM27SiPwBqHdE9hg

Entry address:
0x19B924

Entry point:
55, 8B, EC, 83, C4, F4, B8, 14, AC, 59, 00, E8, 94, BC, E6, FF, E8, E7, F1, FF, FF, E8, 86, 84, E6, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9878

Developed / compiled with:
Microsoft Visual C++

Code size:
1.6 MB (1,681,920 bytes)

The file chemsk12.exe has been seen being distributed by the following 18 URLs.

https://dl.dropboxusercontent.com/sh/1pv74cprt962uqy/j6KGYGpBwe/Second Year/.../chemsk12.exe

http://www.senddeliveryshare.com/wtM97yga Jh9BW EMn46SCZq7Ycsq_fdvH505FH3nc O7DUeXf_G4JzMOpmTbo4hz1Fhs2mDf6jiLVVKd 8jaZMWdNMyO0Nex4PRoSNQIaeMzW0tOhDX3 Aoab11j5BwxpcIZXI12EDpFkbwy578dV2zSjSCUV6i8fu4A2FytoZ5V0TA6fFxRM5JSDVnEieM8WJLqI7pqczf2kkGZhKrALwohOZtwaby_88rmCOPbC0uY_02ilxuQqADlXwwPCs0Zsp8iln4luLIATn6siR1lyeYS2gusolmPqRujQOwYEKV6PEpAQG4AgsDkaBNX3 ycvSmwzXfb7mNOrZ8kKhQ1tFNEd9a9f_vTqa6X2LxQhau0EBh5pwXV5X0pnjhxSZomZdkZLySH7ZlIz6iEC1kQnNInW1OSJ0wYi4kAWPV34VBifkukraYOxfZaqfd_8Ay_w4fosEx-G0AAAATKbTFti3m BwMxvUFwyAFr8iBtAUvgOLTnm0TxxhbNaU5EEV3UzBouV2uXhuvD0yQf

http://chemsketch.software.informer.com/.../

&onid=2054&oid=3001-2054_4-10591465&rsid=cbsidownloadcomsite&sl=fr&sc=us&topicguid=education/science&topicbrcrm=&pid=13457815&mfgid=6287463&merid=6287463&ctype=dm&cval=NONE&devicetype=desktop&pguid=1432262b6539207a1e82baa9&viewguid=b9O6pgdnWnoiMt1Xn16FvsI@0fwH4XMwLoIo&destUrl=http://files.downloadnow.com/s/software/13/45/78/.../chemsk12.exe

&onid=2054&oid=3001-2054_4-10591465&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=education/science&topicbrcrm=&pid=13457815&mfgid=6287463&merid=6287463&ctype=dm&cval=NONE&devicetype=desktop&pguid=7042fd250ded08002f9b2fa5&viewguid=dsusA7uOm6VAdDPjKC2tSN7mPKb-52A4Pzgp&destUrl=http://files.downloadnow.com/s/software/13/45/78/.../chemsk12.exe

Scan chemsk12.exe - Powered by Reason Core Security