iLivid.exe

iLivid Download Manager

Bandoo Media Inc

The application iLivid.exe by Bandoo Media Inc has been detected as a potentially unwanted program by 2 anti-malware scanners. The file has been seen being downloaded from download.wetransfer.com. While running, it connects to the Internet address 125.235.4.59.adsl.viettel.vn on port 80 using the HTTP protocol.
Publisher:
Bandoo Media Inc.  (signed by Bandoo Media Inc)

Product:
iLivid Download Manager

Version:
5.0.2.4762

MD5:
67272527c5acba8dbe7f64ca1313dfe4

SHA-1:
fc9f74be66a4d223caafce2dc902e7baf7bf2d03

SHA-256:
ba9f8f77ef19be77ea58d54426258bc3dd23c7644ab1613dea7943b6cc83740d

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 6:39:59 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3257

Reason Heuristics
PUP.Optional.BandooMedia.G
14.12.17.16

File size:
7.8 MB (8,146,632 bytes)

Product version:
5.0.2.4762

Copyright:
Copyright (C) 2014 Bandoo Media Inc. All Rights Reserved.

Original file name:
iLivid.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\ilivid\ilivid.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/18/2014 2:00:00 AM

Valid to:
10/5/2016 1:59:59 AM

Subject:
CN=Bandoo Media Inc, O=Bandoo Media Inc, L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1590ABE2DAF3AA2318100E59413A30DD

File PE Metadata
Compilation timestamp:
12/15/2014 2:07:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:DKKnbYH0AEAYq3JdlRdhObQ+FwYJe0hmgOxeH2ouxxXlzpaEe99sYB8T:tnbdq5SQ+FwY3hmgOxnnQ99sh

Entry address:
0x39E0AE

Entry point:
E8, 67, 08, 00, 00, E9, 1C, FD, FF, FF, 8B, 00, 81, 38, 63, 73, 6D, E0, 74, 03, 33, C0, C3, E9, EC, 08, 00, 00, 6A, 14, 68, 38, 7A, A7, 00, E8, 3A, 05, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, A0, 08, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 30, 05, 00, 00, C2, 10, 00, 6A, 0C, 68, 58, 7A, A7...
 
[+]

Entropy:
6.6140

Code size:
4.3 MB (4,484,096 bytes)

The file iLivid.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to host-190-105-61-195.telered.com.ar  (190.105.61.195:35750)

TCP:
Connects to m213-101-14-37.cust.tele2.se  (213.101.14.37:5268)

TCP (HTTP):
Connects to 125.235.4.59.adsl.viettel.vn  (125.235.4.59:80)

TCP:
Connects to softbank221081022129.bbtec.net  (221.81.22.129:7416)

TCP:
Connects to softbank218118209119.bbtec.net  (218.118.209.119:6822)

TCP:
Connects to rs5ws163.internal.pcshs.com  (204.99.5.163:3218)

TCP:
Connects to pD9571287.dip0.t-ipconnect.de  (217.87.18.135:6398)

TCP:
Connects to p58067-ipngn200301yosemiya.okinawa.ocn.ne.jp  (118.2.175.67:38322)

TCP:
Connects to p557037-ipbfp801gifu.gifu.ocn.ne.jp  (124.101.181.37:39830)

TCP:
Connects to nsg-static-162.181.75.182-airtel.com  (182.75.181.162:19177)

TCP:
Connects to i15-les02-th2-5-48-61-231.sfr.lns.abo.bbox.fr  (5.48.61.231:17624)

TCP:
Connects to ec2-54-64-44-183.ap-northeast-1.compute.amazonaws.com  (54.64.44.183:22000)

TCP:
Connects to broadband.actcorp.in  (49.207.58.135:6881)

TCP:
Connects to bb.67.c1ad.ip4.static.sl-reverse.com  (173.193.103.187:1337)

TCP:
Connects to b6.67.c1ad.ip4.static.sl-reverse.com  (173.193.103.182:6969)

TCP:
Connects to abts-tn-dynamic-254.139.174.122.airtelbroadband.in  (122.174.139.254:16522)

TCP:
Connects to abts-tn-dynamic-174.67.174.122.airtelbroadband.in  (122.174.67.174:6881)

TCP:
Connects to abts-tn-dynamic-105.249.61.171.airtelbroadband.in  (171.61.249.105:49360)

TCP:
Connects to 96-69-153-5-static.hfc.comcastbusiness.net  (96.69.153.5:40950)

TCP:
Connects to 68.dd.a86c.ip4.static.sl-reverse.com  (108.168.221.104:6969)

Remove iLivid.exe - Powered by Reason Core Security