iLividSetup-r120-n-bi.exe

iLivid

Bandoo Media, Inc.

The application iLividSetup-r120-n-bi.exe by Bandoo Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.downloadsetup.net.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc.)

Product:
iLivid

Description:
iLivid Install

Version:
5.0.0.4736

MD5:
50af2d215748930873343b2f3bba40c6

SHA-1:
cfa5a33c78d18b4f530744bb0bf85f5a03a49d18

SHA-256:
e370c0a542a320632a8ef5261bac2e2683b555f6682561106014ced914366884

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
11/24/2024 2:59:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo (M)
16.8.7.11

File size:
1.8 MB (1,918,360 bytes)

Product version:
5.0.0.4736

Copyright:
Copyright (c) 2014

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ilividsetup-r120-n-bi.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
11/27/2014 2:00:00 AM

Valid to:
2/24/2016 1:59:59 AM

Subject:
CN="Bandoo Media, Inc.", O="Bandoo Media, Inc.", L=Panama City, S=Panama, C=PA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3DECB3F6069817010107782EABF518FB

File PE Metadata
Compilation timestamp:
5/30/2013 11:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:64dBESYrgGUCuVEt03ugUv8Fb3NraKgC5mqDSqRpolP6:6CBlYsfZFjNr55mukM

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Entropy:
7.4781

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file iLividSetup-r120-n-bi.exe has been seen being distributed by the following URL.

Remove iLividSetup-r120-n-bi.exe - Powered by Reason Core Security