tmp00000025e65cba72698abc4e

Microsoft.Expression.Interactions

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The file tmp00000025e65cba72698abc4e by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
Microsoft.Expression.Interactions

Version:
2.0.20525.0

MD5:
8a8f586af88f9a5539cd2f4c526880a8

SHA-1:
56659ab3888e8889e28f4499b500f46ce432b065

SHA-256:
981046fdb6443e40b0d2c0842c0be0c3411e44630256c3e6f1ac201368338896

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 4:23:30 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
17.1.20.5

File size:
512 KB (524,288 bytes)

Product version:
2.0.20525.0

Copyright:
Copyright (c) Microsoft Corporation. All rights reserved.

Original file name:
Microsoft.Expression.Interactions.dll

Bundler/Installer:
SIEN SuperInstall

Common path:
C:\windows\temp\tmp00000025e65cba72698abc4e

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2012 7:55:45 AM

Valid to:
3/2/2014 7:55:45 AM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EA925C07E01E1C06B597DD4B36FAA8B

File PE Metadata
Compilation timestamp:
5/25/2010 10:12:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x17A1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
87 KB (89,088 bytes)

Remove tmp00000025e65cba72698abc4e - Powered by Reason Core Security