tixati-2.48-1.win64-install.exe

Tixati Software Inc.

This is a setup and installation application. The file has been seen being downloaded from download3.tixati.com and multiple other hosts.
Publisher:
Tixati Software Inc.  (signed and verified)

MD5:
8fcba5ed502a2496cd8032d9921a7fb5

SHA-1:
bafdfabe86dd8f8f33901d8d286501c5c0a3ce94

SHA-256:
155d569cc2bfc73d6be5892f7d0c1226ed002bcff6d3e56bdd2a5d5b58a4a47e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:41:55 AM UTC  (today)

File size:
12.8 MB (13,380,248 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\programs\tixati-2.48-1.win64-install.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/27/2016 3:00:00 AM

Valid to:
4/28/2017 2:59:59 AM

Subject:
CN=Tixati Software Inc., O=Tixati Software Inc., POBox=M5E 1W7, STREET=1 Yonge Street Suite 1801, L=Toronto, S=Ontario, PostalCode=M5E 1W7, C=CA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6E6A65E8390481F174C5E393961B9619

File PE Metadata
Compilation timestamp:
11/2/2016 12:02:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:FGb+l8sSkY4ZEUoRKiDJ2WzQkshnASVcJpeovNbz8fp:M8828ULiDxDshjmJpt1bz8fp

Entry address:
0x1B317

Entry point:
E8, 3F, 54, 00, 00, E9, 17, FE, FF, FF, 3B, 0D, F0, EE, 43, 00, 75, 02, F3, C3, E9, BF, 54, 00, 00, B8, 48, EC, 43, 00, C3, A1, A0, 4C, 44, 00, 85, C0, 56, 6A, 14, 5E, 75, 07, B8, 00, 02, 00, 00, EB, 06, 3B, C6, 7D, 07, 8B, C6, A3, A0, 4C, 44, 00, 6A, 04, 50, E8, D6, 55, 00, 00, 85, C0, 59, 59, A3, 94, 3C, 44, 00, 75, 1E, 6A, 04, 56, 89, 35, A0, 4C, 44, 00, E8, BD, 55, 00, 00, 85, C0, 59, 59, A3, 94, 3C, 44, 00, 75, 05, 6A, 1A, 58, 5E, C3, 33, D2, B9, 48, EC, 43, 00, EB, 05, A1, 94, 3C, 44, 00, 89, 0C, 02...
 
[+]

Entropy:
7.9898  (probably packed)

Code size:
196 KB (200,704 bytes)

The file tixati-2.48-1.win64-install.exe has been seen being distributed by the following 4 URLs.

https://download3.tixati.com/.../tixati-2.48-1.win64-install.exe

https://download2.tixati.com/.../tixati-2.48-1.win64-install.exe

http://indir.gezginler.net/i/17546/31373534365f323031362d31312d3033/.../

https://download1.tixati.com/.../tixati-2.48-1.win64-install.exe

Scan tixati-2.48-1.win64-install.exe - Powered by Reason Core Security