iLivid.exe

iLivid Download Manager

Bandoo Media, Inc

The application iLivid.exe by Bandoo Media, Inc has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘iLivid’. While running, it connects to the Internet address ef.71.c1ad.ip4.static.sl-reverse.com on port 6969.
Publisher:
Bandoo Media Inc.  (signed by Bandoo Media, Inc)

Product:
iLivid Download Manager

Version:
5.0.1.4519

MD5:
23d1500391f55ad641de6068f2a13606

SHA-1:
9b937bf1c93eccc1474f48b784b2dcbb0376724e

SHA-256:
62ef012b3d71f93f68f67f900987e98dbd1be4fabd2e5d1985c5dda9ed5c872b

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 12:59:00 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.SearchSuite
4.0.3.14515

Reason Heuristics
PUP.Optional.BandooMedia.G
14.4.9.20

File size:
7.9 MB (8,271,360 bytes)

Product version:
5.0.1.4519

Copyright:
Copyright (C) 2014 Bandoo Media Inc. All Rights Reserved.

Original file name:
iLivid.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\ilivid\ilivid.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/19/2012 3:00:00 AM

Valid to:
11/3/2014 2:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7A5189D163723107DEFA157662A4BAE4

File PE Metadata
Compilation timestamp:
4/8/2014 11:04:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:qYg/sXb8lr59MpNmHwlCIe2PatEe1L3t/F0BJnodD9zhJ/RySezI:iQb8amQDe2itPLd/F0P09gSec

Entry address:
0x3886F0

Entry point:
E8, A5, 08, 00, 00, E9, 1C, FD, FF, FF, FF, 25, 14, 25, 83, 00, 8B, 00, 81, 38, 63, 73, 6D, E0, 74, 03, 33, C0, C3, E9, 24, 09, 00, 00, 6A, 14, 68, B8, 96, A9, 00, E8, 82, 05, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, D8, 08, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 78, 05, 00, 00, C2, 10, 00...
 
[+]

Entropy:
6.6862

Packer / compiler:
PEQuake V0.06

Code size:
4.2 MB (4,393,472 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
iLivid

Command:
"C:\users\{user}\appdata\local\ilivid\ilivid.exe" -autorun


The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to 188-27-5-28.rdsnet.ro  (188.27.5.28:26142)

TCP:
Connects to sky-78-17-195-83.bas512.cwt.btireland.net  (78.17.195.83:37146)

TCP:
Connects to broadband.time.net.my  (61.6.57.149:19103)

TCP:
Connects to 186-210-046-212.xd-dynamic.algarnetsuper.com.br  (186.210.46.212:44388)

TCP:
Connects to ten.emfme.net  (77.234.40.145:35035)

TCP:
Connects to static-83-70.blueline.mg  (197.158.83.70:46077)

TCP:
Connects to pc-84-255-160-190.cm.vtr.net  (190.160.255.84:50321)

TCP:
Connects to ns1.vospol.sk  (178.18.77.1:18794)

TCP:
Connects to dhcp.217.194.61.206.databaar.ch  (217.194.61.206:41014)

TCP:
Connects to catv-80-99-3-63.catv.broadband.hu  (80.99.3.63:15004)

TCP:
Connects to b3d39653.virtua.com.br  (179.211.150.83:54421)

TCP:
Connects to b1c1c5a0.virtua.com.br  (177.193.197.160:36353)

TCP:
Connects to abbottsburgdsl5-p132.intrstar.net  (66.207.255.132:42888)

TCP:
Connects to 89-160-150-84.du.xdsl.is  (89.160.150.84:30459)

TCP:
Connects to 67-14-248-242.hwccustomers.com  (67.14.248.242:29989)

TCP:
Connects to 31.214.184.51.user.conectabalear.com  (31.214.184.51:51704)

TCP:
Connects to 197.237.123.134.wananchi.com  (197.237.123.134:52038)

TCP:
Connects to 187-108-070-201.ip3.com.br  (187.108.70.201:55281)

TCP:
Connects to 186-210-035-111.xd-dynamic.algarnetsuper.com.br  (186.210.35.111:63784)

TCP:
Connects to 186.248.33.171.ip.orionnet.ru  (171.33.248.186:3375)

Remove iLivid.exe - Powered by Reason Core Security