theskyxsae10.5.0build10305fullinstaller.exe

TheSkyX Serious Astronomer Edition

Software Bisque Inc

The file theskyxsae10.5.0build10305fullinstaller.exe, “TheSkyX Serious Astronomer Edition Setup ” by Software Bisque Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.bisque.com.
Publisher:
Software Bisque   (signed by Software Bisque Inc)

Product:
TheSkyX Serious Astronomer Edition

Description:
TheSkyX Serious Astronomer Edition Setup

MD5:
2d9169a0f00c0a8375e2abd13c5f4477

SHA-1:
57ee3a552330941d077b84b054bc9f7fb08aace8

SHA-256:
83fedf068599465ac1f809d6422750771089bd5e90ab31a9b2e0e114aaf3eda2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/6/2024 12:59:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.1.10.17

File size:
824.1 MB (864,117,784 bytes)

Product version:
10.5.0 Build 10305

Copyright:
(c) 2016 Software Bisque, Inc. All rights reserved.

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\theskyxsae10.5.0build10305fullinstaller.exe.part

Digital Signature
Authority:
Symantec Corporation

Valid from:
7/1/2015 1:00:00 AM

Valid to:
9/30/2017 12:59:59 AM

Subject:
CN=Software Bisque Inc, O=Software Bisque Inc, L=Golden, S=Colorado, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7391B30423EC4F105282B1C5A390B99A

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9996

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file theskyxsae10.5.0build10305fullinstaller.exe has been seen being distributed by the following URL.

http://www.bisque.com/sc/media/p/.../download.aspx

Remove theskyxsae10.5.0build10305fullinstaller.exe - Powered by Reason Core Security