sdf68cc.exe

Installer

IMALI - N.I. MEDIA TD

The application sdf68cc.exe by IMALI - N.I. MEDIA TD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
IMALI - N.I. MEDIA TD  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
404c99d3014a18e7d7e9d4322613fb24

SHA-1:
01d0da431e508918087d1ea50defcaa483a2c001

SHA-256:
5dad493b7b51c10f05c6213158d4f06d6889adaa70a20a6b95de63662021298c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 3:43:46 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.IMALI.Installer
15.5.25.20

File size:
350.4 KB (358,856 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\sdf68cc.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/13/2014 7:00:00 PM

Valid to:
8/14/2015 6:59:59 PM

Subject:
CN=IMALI - N.I. MEDIA TD, OU=online media, O=IMALI - N.I. MEDIA TD, STREET=reines 50, L=tel-aviv, S=tel-aviv, PostalCode=64587, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0093FCE354B4016AD3D34DEC6ADB0B6F35

File PE Metadata
Compilation timestamp:
12/4/2014 3:28:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:DClMuFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VyaOLu7zl:DClZZwgVxGq86oH/MKvnolgyxQzl

Entry address:
0x55B4E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7919

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
335 KB (343,040 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove sdf68cc.exe - Powered by Reason Core Security