3310.tmp

IMedia Holdings Ltd.

The file 3310.tmp by IMedia Holdings has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from a6xgwhb2wmn.systotal.com.
Publisher:
IMedia Holdings Ltd.  (signed and verified)

Description:
Update

Version:
2.09.11.0

MD5:
6ff75c034bc170633ccaac0dc52feca5

SHA-1:
5f77e0a5870878dd5e4507af0e3a9b652121ee69

SHA-256:
db8c496c78288f9d5772925d12cf7beb2018e4faa5af28ddca22a96e275c74cc

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 8:44:12 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.iMedia.IMediaHoldings.Installer (M)
15.9.13.16

File size:
2.8 MB (2,903,368 bytes)

Copyright:
© 2015

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\3310.tmp

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/18/2015 8:00:00 PM

Valid to:
12/25/2015 6:59:59 PM

Subject:
CN=IMedia Holdings Ltd., OU=IMedia Holdings Ltd., O=IMedia Holdings Ltd., STREET=63 Hoi Yuen Road Kwun Tong, L="Kwun Tong, Kowloon", S=Kowloon, PostalCode=000000, C=HK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4CCDC952B43D5F4E4C9E99C70634ACF1

File PE Metadata
Compilation timestamp:
12/25/2013 12:01:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:qbA/mvj9XipZSo0g0J0xLndCDXJtpMp/cBRkbdL30/6RoFcva5ihO://mvj9XaYoBLdotOkBRkxJ+my5iM

Entry address:
0x3219

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Entropy:
7.9989

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 3310.tmp has been seen being distributed by the following URL.

Remove 3310.tmp - Powered by Reason Core Security