asc-setup.exe

Kheifets Iliya Mikhailovich IP

The application asc-setup.exe by Kheifets Iliya Mikhailovich IP has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from 1576985.softload1.ru and multiple other hosts. While running, it connects to the Internet address anvir.com on port 80 using the HTTP protocol.
Publisher:
Kheifets Iliya Mikhailovich IP  (signed and verified)

MD5:
d79a5bd28f1006ac056695049b9902f1

SHA-1:
f99b42551c4650893e98848b8b1a742cdc159365

SHA-256:
1844a15b10befca67672a5886e9d518e1bcd9b43ccf3351386e90b3488b9bf3e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 2:34:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.28.6

File size:
131.3 KB (134,440 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\000\asc-setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2016 3:00:00 AM

Valid to:
10/5/2018 2:59:59 AM

Subject:
CN=Kheifets Iliya Mikhailovich IP, O=Kheifets Iliya Mikhailovich IP, STREET=29 Altaiskaya ul., L=Moscow, S=Moscow, PostalCode=107589, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3328622BC7BC78D18B8650DD085A8CDC

File PE Metadata
Compilation timestamp:
9/26/2011 4:21:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:xweqOYEUXPnN7951hx3Vc775uhh29x/Gymv0ciBkEx:GEUXH57x3qV2M7/1msFb

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file asc-setup.exe has been seen being distributed by the following 8 URLs.

http://1576985.softload1.ru/asc-setup.exe

http://1522724.softload5.ru/asc-setup.exe

http://1567816.softload5.ru/asc-setup.exe

http://1564279.softload10.ru/asc-setup.exe

http://1581199.softload10.ru/asc-setup.exe

http://1572441.softload3.ru/asc-setup.exe

http://1531540.softload9.ru/asc-setup.exe

http://1539354.softload1.ru/asc-setup.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to anvir.com  (185.22.234.46:80)

Remove asc-setup.exe - Powered by Reason Core Security