setup_aster211.exe

ASTER

IBIK, LLC

The program is a setup application that uses the Tarma Installer installer. The file has been seen being downloaded from www.ibik.ru.
Publisher:
IBIK Software Ltd  (signed by IBIK, LLC)

Product:
ASTER

Description:
Installer for ASTER

Version:
2016.4.3.2045

MD5:
1befee131cbc2c5c5cc08cc21b144ef8

SHA-1:
2c03d43818bd013f2c87b888684a4f4026eff3e2

SHA-256:
fe6311e0ccfc621cc230f03738bc8e29f09bc239a4ca9dd29949c363faed02f1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/1/2024 1:27:54 PM UTC  (today)

File size:
20 MB (20,979,400 bytes)

Product version:
v2.11

Copyright:
Copyright © 2016 IBIK Ltd

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
Tarma Installer

Common path:
C:\users\{user}\downloads\setup_aster211.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/5/2015 8:26:44 AM

Valid to:
1/23/2018 6:51:37 AM

Subject:
CN="IBIK, LLC", O="IBIK, LLC", L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D88E3D9EA407112D3BA4F31769DAB134

File PE Metadata
Compilation timestamp:
10/1/2015 6:30:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:7CzNQ3jE1GSc5hQGvC4PazPE6Ju8LP4LrgX4XtybLzW4VqRKi6X3T1+vqE:wNajE1Gt5O2686o8k8o9yzVqRHL

Entry address:
0x144A

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 68, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 64, 30, 40, 00, FF, 15, 60, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 5C, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 58, 30, 40, 00, 85, C0, 75, 41, FF, 15, 54, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A4, 32, 40, 00, E8, 99, FB, FF, FF, 59, C7, 05, 08, 44, 40, 00, FD, 00, 00, 00...
 
[+]

Entropy:
7.9998

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file setup_aster211.exe has been seen being distributed by the following URL.

Scan setup_aster211.exe - Powered by Reason Core Security