nw_15133_autodesksketchbookpr.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.softsalad.ru and multiple other hosts.
MD5:
fff4e6d2102d6b23bf6f2ba2cb0cc358

SHA-1:
b05675e76cb8dd9acedeedb3d2b54097a19c7d41

SHA-256:
6e1df42b20fcc8fbc9432ecb2cdd8ccb712879e030501e0391d87a15b77e554b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 7:28:54 AM UTC  (today)

File size:
42.8 MB (44,851,551 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\nw_15133_autodesksketchbookpr.exe

File PE Metadata
Compilation timestamp:
7/19/2012 7:02:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
786432:FwvOgffaXUxtd7vp5vOGIYhxmjWN65n6:6OgfyUtP5vXAWN65n6

Entry address:
0x1DFA8D

Entry point:
E8, DF, 9F, 00, 00, E9, 16, FE, FF, FF, 3B, 0D, 64, 5C, 7E, 00, 75, 02, F3, C3, E9, 5F, A0, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 8B, 7D, 08, 33, C0, 83, C9, FF, F2, AE, 83, C1, 01, F7, D9, 83, EF, 01, 8A, 45, 0C, FD, F2, AE, 83, C7, 01, 38, 07, 74, 04, 33, C0, EB, 02, 8B, C7, FC, 5F, C9, C3, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, E0, BD, 8E...
 
[+]

Code size:
2.3 MB (2,433,024 bytes)

The file nw_15133_autodesksketchbookpr.exe has been seen being distributed by the following 8 URLs.

http://www.softsalad.ru/.../dc38c413f00544d4da1eaa5c35dfeb11

http://www.softsalad.ru/go/?url=http://www-ru.jt7.net/.../86b81a0e9a5222392bf311de951984ea

Scan nw_15133_autodesksketchbookpr.exe - Powered by Reason Core Security