ilividsetup-r2489-n-bi.exe

iLivid

Bandoo Media, Inc.

The application ilividsetup-r2489-n-bi.exe by Bandoo Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.sharelive.net.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc.)

Product:
iLivid

Description:
iLivid Install

Version:
5.0.2.4813

MD5:
3b842bf0c8fd1fe60ff1c5394bd078ca

SHA-1:
5a73e3d3056522279c109382f7456da4e1c6898b

SHA-256:
cdd9adaf090efad46bfb3a72c6faf891c71223b7916d7ccba41c263c36ba2710

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
11/24/2024 1:31:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo (M)
16.7.23.0

File size:
1.6 MB (1,712,640 bytes)

Product version:
5.0.2.4813

Copyright:
Copyright (c) 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ilividsetup-r2489-n-bi.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
11/27/2014 3:00:00 AM

Valid to:
2/24/2016 2:59:59 AM

Subject:
CN="Bandoo Media, Inc.", O="Bandoo Media, Inc.", L=Panama City, S=Panama, C=PA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3DECB3F6069817010107782EABF518FB

File PE Metadata
Compilation timestamp:
2/24/2012 10:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:D6C4SAmwW9AFXPYMq/m+VO2kQEFAtURxnSHmxTX++6WF8uWH5YGydyg0Tn:14e9Ubi1cXQObnNRXXlWH5idyg0Tn

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.3913

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file ilividsetup-r2489-n-bi.exe has been seen being distributed by the following URL.

Remove ilividsetup-r2489-n-bi.exe - Powered by Reason Core Security