asterctl.exe

IBIK, LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘asterctl’.
Publisher:
IBIK, LLC  (signed and verified)

MD5:
1fb2ebbcd455953cb1e576684d1aa6c6

SHA-1:
482ba03fa2148f0ef3e3eafdcbbd2b8282327834

SHA-256:
e3da6be3fea23cad227190c944704f126a5b1d2b926676ff0d3f80d629295293

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 8:04:36 AM UTC  (today)

File size:
9.2 MB (9,696,968 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\aster\asterctl.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/5/2015 3:26:44 PM

Valid to:
1/23/2018 1:51:37 PM

Subject:
CN="IBIK, LLC", O="IBIK, LLC", L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D88E3D9EA407112D3BA4F31769DAB134

File PE Metadata
Compilation timestamp:
10/25/2016 3:12:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:jONuVemT8pK7KY4GqM1+X38C4U1hDHgtckyAW3pdVYMjYYRdsfPTjuGgLws8q1m:6SmKeYoMIX38CFKcktW3pdVYMUUdKbjt

Entry address:
0x1EA0F48

Entry point:
EB, 08, 00, 34, 34, 00, 00, 00, 00, 00, 60, E8, 00, 00, 00, 00, 5D, 81, ED, 10, 00, 00, 00, 81, ED, 48, 0F, EA, 01, E9, 04, 00, 00, 00, 24, 71, 63, 74, B8, 48, 0F, EA, 01, 03, C5, 81, C0, 4C, 00, 00, 00, B9, 73, 05, 00, 00, BA, A2, 58, 05, 37, 30, 10, 40, 49, 0F, 85, F6, FF, FF, FF, E9, 04, 00, 00, 00, 1B, EB, D2, 9F, 29, 6F, 29, 2B, 9E, A2, A2, A2, 23, 63, 5A, A2, A2, A2, A1, 6F, 1A, A4, A2, A2, A2, 18, 8A, A2, A2, A2, 55, 40, A1, 6A, 29, 23, AE, A2, A2, A2, A1, 67, F2, F2, CA, BA, 15, FE, A2, CA, 92, FA...
 
[+]

Code size:
1.5 MB (1,547,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
asterctl

Command:
C:\Program Files\aster\asterctl.exe -autostart


Scan asterctl.exe - Powered by Reason Core Security