acronistrueimage2016.exe

Acronis True Image 2016

Acronis International GmbH

This is a self-extracting archive and installer. The file has been seen being downloaded from dl.cleverbridge.com and multiple other hosts.
Publisher:
Acronis International GmbH  (signed and verified)

Product:
Acronis True Image 2016

Description:
Installer

Version:
19,0,0,6027

MD5:
2dbd3ca259fea7ea6b76d32fde583e2e

SHA-1:
c9f6f38aeba7fa935a341eeb22c2258edacc0e5f

SHA-256:
b212d510eabe0038fbd812b0d2fa58f36a62fbfe6187a29ad19bb3c0a3c5aacf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/19/2018 2:54:52 AM UTC  (today)

File size:
404.5 MB (424,108,520 bytes)

Product version:
19,0,0,6027

Copyright:
Copyright (C) Acronis International GmbH, 2002-2015.

Trademarks:
Acronis International GmbH. All rights reserved.

Original file name:
atih_installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\acronistrueimage2016.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
8/4/2015 8:00:00 PM

Valid to:
10/3/2018 7:59:59 PM

Subject:
CN=Acronis International GmbH, O=Acronis International GmbH, L=Schaffhausen, S=Schaffhausen, C=CH

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7A68E99B5C7D7F14BA19F3D4A9B92C27

File PE Metadata
Compilation timestamp:
11/26/2015 5:27:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6291456:P4PKnyVld9/WQvsFBxzDzwHFG9UHY/z8kKhm87Y6eOa0KI52QIrLSRXpIycSl7sI:P4+kvdvGBpHGeug802a0KI8LSfIycU1

Entry address:
0x4A91F

Entry point:
E8, EF, 48, 00, 00, E9, 7F, FE, FF, FF, 56, 6A, 04, 6A, 20, E8, D7, 4E, 00, 00, 59, 59, 8B, F0, 56, FF, 15, 30, 93, 47, 00, A3, B0, 03, 4B, 00, A3, AC, 03, 4B, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 0C, 68, 10, FA, 49, 00, E8, 1C, 4E, 00, 00, 83, 65, E4, 00, E8, 02, 3F, 00, 00, 83, 65, FC, 00, FF, 75, 08, E8, 23, 00, 00, 00, 59, 8B, F0, 89, 75, E4, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 8B, C6, E8, 33, 4E, 00, 00, C3, 8B, 75, E4, E8, DD, 3E, 00, 00, C3, 55, 8B, EC...
 
[+]

Entropy:
7.9989  (probably packed)

Code size:
477 KB (488,448 bytes)

The file acronistrueimage2016.exe has been seen being distributed by the following 30 URLs.

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

http://store.acronis.com/882/.../91929820-ZX8nxxM3TekI1BxIGUzR-1-2-1

http://cdn.soft-download.ru/?s=dtzf6yucFOpgrbx-cAWCCg&pf=AcronisTrueImage_Trial_Rus_Setup.exe&pt=Acronis True Image 2015 ??? Windows&src=softcatalog.info

https://www.google.com/url?hl=en&q=http://store.acronis.com/882/.../96080668-22aMAImTddrxU9ia0YAu-1-2-1&source=gmail&ust=1471554475833000&usg=AFQjCNF6EDjOdgQc7VVc5B4ImfTxIYNpHg

https://www.acronis.com/de-de/my/.../?AcronisTrueImage2016_6027.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

http://store.acronis.com/882/.../96107189-nM69iljQeRMJIhK4W1yG-1-2-1

https://www.google.com/url?hl=en-GB&q=http://store.acronis.com/882/.../93671233-hz6It1WVlcukI9TBvRTZ-1-2-1&source=gmail&ust=1467109295974000&usg=AFQjCNEbd4mZ932q0Bi6ieVRYZV2-dOyuQ

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

http://dl.acronis.com/.../AcronisTrueImage2016.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

https://dl.cleverbridge.com/882/.../AcronisTrueImage2016_web.exe

Latest 30 of 30 download URLs