ilivid-download-manager.exe

iLivid

Bandoo Media, Inc.

The application ilivid-download-manager.exe by Bandoo Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.bundletagchuckle.com and multiple other hosts.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc.)

Product:
iLivid

Description:
iLivid Install

Version:
5.0.0.4705

MD5:
29d7a8279a51243a958c0eabd05e4161

SHA-1:
7f3d61ce1ecf143fe7c083a6389bcf2966f99c5a

SHA-256:
95f13528061e81ae78a92e57ce923d926f7b660c04d6360980171609d0ed4f84

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
11/23/2024 3:15:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo.BandooMedia.Installer (M)
16.2.2.16

File size:
1.8 MB (1,923,880 bytes)

Product version:
5.0.0.4705

Copyright:
Copyright (c) 2014

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ilivid-download-manager.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/9/2014 1:00:00 AM

Valid to:
2/24/2015 12:59:59 AM

Subject:
CN="Bandoo Media, Inc.", O="Bandoo Media, Inc.", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0254DA8BDA7284120701E659BC8B7D92

File PE Metadata
Compilation timestamp:
5/30/2013 9:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:ZdC4SCKd0X26c/lgGypWxgYrCz1fROlc3sJv1ovmv8zB7vP64O8RV1evegh5Qy:y408261GypJJOlMsNYdS4O8fghCy

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file ilivid-download-manager.exe has been seen being distributed by the following 10 URLs.

http://www.bundletagchuckle.com/Lov1TdjkGirndEwSo1WuzunuzKjIDMHUkkrbUURoSHPxUa8uGX8XeWaQlw8Zc8aOmRNLE7npMFRTA73MN7SBbEnj1BwNljUQ3bzs8wD1gjbX10COEMWNoScmo0tTA4o8 KC6en52sVK3pQFXJ_FVnLUj3RxoajkGEzTq1ht4csGDwSbNapjway5KbXd1bbLkr5yCGeeUoPvUhyj_DiIXNAUsWmo4wLRdbRaT3SHhqtl43V8x5ipeFLTFZcNUblCvxxHFWky24cq4gUi7OrikrvHAaeO1g83UGuSif NlCa xNwQtwyCr8o8nLpR 6mZCw_Gg tQBz3GhaAtL31pPO6Sqnvut2Wz2M2bmh xxqFzUNcU1oIPg uHCsJ7vMGu7OW0O1jn1daDTdkRtOPGx9qBq1A_oAeVpa3dzWXWpVY95yOtkiKGgVTABnBV93KQYvl AKxT8e7MI9IaXWC4wUv5F9AezZ5gCdIdZadIqepZRf6OlV8m_YJyKJItyuKnY34rNgNwe-G14AAGRgnq2tSc7ib9iAA5c0kUEH8AnObPsyv9_3EvANLed59XvRKHN42Zfv0oOKIPeEhv8gv96iQW e1YHtJ3h5Dh6veKXe2gQMIkrQDIFgGE0A-e

http://www.clearheartgift.com/MzqoYfEAzEYyE_6Td7jxI7tFpM43fY17eXKDvjS50xtdVfE7Y3iMIkbAoN7pH4ucGsFH8M6cJTwP7HLID3LJZ5riQOpkZNdC4f5lSNk3r8czUpn4Alaa_h3r5pR08T9EavURysNHDj_MmRLt4RvZvsbFeeuIkgG5KUHCrHYRfAo12XB8_GDCmHu22wRbnMxtCU2yYiBCTeTGCbA8maYXPk3_O4Nrnj8siYITLWgnsuK EJXhH8zHbPqsudBFeN 6eXV7Co2yZFJVgiZ9n6pDOuPPukn3sdeGh NLYI3zbOgpt4gjG15F5xOapwnJV_hVqirsf2mEY2AhzN2eobuoSu167tiNxoPT MHhNfeGp_7BsvLr3NVSJrM_KFk_D5lyG08NZulMzmA05qEyaqCsrokd4rLSYfSV0t_u3Yl44Zid93HUxAnGbrscC4au7T6sQVsqWTyTLmbIFVpKrZKvlnMXU0cLOv_0_AUyPw qTw4T7SxcCmlPgIoovRlDZnsF557xKBLiBgT6N4F0nhIxOhL9EOmsBKwo3PUR1Mm9kl0zsTG_7k=-G10AAGTymtmsgnaj KIHjSjYgAOXwo0G8AnObAO9MXqjbp6XcgwaPsfd2N1dCZFA7Ymqt7LHaaCLs2F7RVP_arzKoovnRzSgMlRoraQmXAM=-e

http://www.giftchuckleflash.com/654Of hjwxx5nY170vTUPSPoRxC0tJC32 gYHErCk7fFHoe6ahosUXT6YKvWBEYA3mNy2A6aM9ADwf4P3f0e48OjGMMr08VKk_XAcUdsp3I mec5WyzHJQhDGcQE4ABjWfMGUe5SyVtiFpPPTl65DhS5pGhmJgGd9kc57MdaLAUCiOYHMCOwAWiTojW1rvBISupkILV9ql0OWlxjqH_S4yOC0Z9Uom7cniPyqcA8omwHYurJVHvPo8xwTKyRjaaCXsAhHFn01L22Yw59GC8w370z7K3I3H3n Uxp3S8MEBu1FGYbqeaVq_qqpZVXf9zdyt KnRfYLekSiBUpVou1Qyy1O6OTcDyWDdfVU8QqX4FdHK62fhfFly7psfTHUrz0QXtBwaJJ5N oXqALRToMUDDDzObe2lHw LWWLK3t42a5uMfZiZ5dcJuD7JZmVPbhP5A10jN6Mzf9txQJWkh8Ti2fJdZjNDV4nhfJ23c1HMVMysyjnSHlbgwcdI4k8HXv_AcwIMTUt2KMvEVKRz6WIkDKlqLddfZTAIfCZhQcJMnUBNPrqnV KgKhxmcfkp9e_eWNhKZ4-G14AAGRwXmtrutnu9AgINuDAJU1k0AF8gjPbvvT3vS8B32hY162ei4af4mEe3qGGipB7ouZvjOvWrjDId8b3C75N paK7K3Pqg40GsUKRGJpIgg=-e

http://www.giftchuckleflash.com/nuclCHOQgnMXrvLuBSjhtt80dIFb0HH_3iOBioZ_TQ4pgAa 9HOe5q7Mi_xiYF4VQeKrIIn1sQ4HcMFT0UUI6BoLpia0PdM8caaV2R1H83 mzR0PTHyode1OQFbphDC_5IP2TeqjNeaaF_a5ohKI5AREWzIlErYe0ZH0VP5_QHUm4z4oAxf8hN1isG2_5trQTt8i94mxr7PyidS3SHLnJV8Qo7HPfZXo0pLgAkM1X8Hd9SIQWap1_vDHito4eRn_LEwgLrIf_9 8Uer4APHisf7qYwCWMCnl0c09GyVyCR2qfDM_iYS6b0ItxfkuKqKG68O pTkXtWfK3GMw5esY OqSiSntr_Z_zM0Wh 0KYmjDqhrDiX2s7WY8w53nf34XeodVK4r1r4mm8kqesqTMI_JiiL 8PjdrzN9oWAAip25pkweSvjOLeT4BfetXwYBiI_75VbLTNGQIiW2SmAAWjfsxTwk_WBDbE_daRVfTbMsHCl6ZvN jiHGOEwQzWT7cF8YN1SHWw5DATanOyxeXeYxm01xMQqrmbCAGX81P5Hu krUZJ2JNeVNf9izDtADZVAKTyHbB-G14AAGRgnq2tSezECRtw4JImMugAPsGZbV m9_taAr6h TjObisaVgbP2_ydO1AR5J5Q_ _l11tk2uBGMo pBs3xVmpNmmPdVaAXUYLGWJzCUAI=-e

Remove ilivid-download-manager.exe - Powered by Reason Core Security