progenesis qi for proteomics.exe

Waters Corporation

This is a self-extracting archive and installer. The file has been seen being downloaded from www.nonlinear.com.
Publisher:
Nonlinear Dynamics  (signed by Waters Corporation)

Description:
Installation Extractor

Version:
1, 0, 0, 1

MD5:
07bf3e15141881c1b8115d485eb72eeb

SHA-1:
bf825a75ff5fa0df0f6c480efcfcdbebd7642f91

SHA-256:
5b3d1742bf9bc315f0915c9335a1efa1f9e22a3a856f2e373d0685b8c93a8909

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 2:36:03 PM UTC  (today)

File size:
124.1 MB (130,156,976 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright Nonlinear Dynamics 2007

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\progenesis qi for proteomics.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/23/2015 8:00:00 PM

Valid to:
7/23/2018 7:59:59 PM

Subject:
CN=Waters Corporation, OU=Informatics, O=Waters Corporation, L=Milford, S=Massachusetts, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
24D24D7D4DA000FDC719A8E2D87E235D

File PE Metadata
Compilation timestamp:
8/10/2015 5:44:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3145728:XnQv6VLDyt31EHLasfumA3s2jOHkXfI3YuCo6OFq:X3VnynqLnfunpOEXg3IUq

Entry address:
0xFA1E

Entry point:
E8, 1B, 7E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, FF, 75, 0C, 8D, 4D, F0, E8, 53, F7, FF, FF, 8B, 45, F0, 83, B8, AC, 00, 00, 00, 01, 7E, 16, 8D, 45, F0, 50, 68, 03, 01, 00, 00, FF, 75, 08, E8, 81, 7E, 00, 00, 83, C4, 0C, EB, 12, 8B, 80, C8, 00, 00, 00, 8B, 4D, 08, 0F, B7, 04, 48, 25, 03, 01, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 4D, F8, 83, 61, 70, FD, C9, C3, 8B, FF, 55, 8B, EC, 83, 3D, 90, 7E, 43, 00, 00, 75, 14, 8B, 45, 08, 8B, 0D, A8, 69, 43, 00, 0F, B7, 04, 41, 25, 03, 01, 00, 00...
 
[+]

Entropy:
7.9930  (probably packed)

Code size:
169 KB (173,056 bytes)

The file progenesis qi for proteomics.exe has been seen being distributed by the following URL.

Scan progenesis qi for proteomics.exe - Powered by Reason Core Security