bootstrapper_0-uvdhqmap_.exe

IMBooster

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application bootstrapper_0-uvdhqmap_.exe, “IMinent bootstrapper” by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Iminent  (signed and verified)

Product:
IMBooster

Description:
IMinent bootstrapper

Version:
4.17.0.0

MD5:
1fa5dcd8ff9c41ef3072240230289673

SHA-1:
4eb03311c171f79f7440b69da705bb4dbd0b427c

SHA-256:
b7a7e6b8769bf197ace4087ea243aea245b2534b17b7f8e182147c3c70262139

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 4:21:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
17.3.15.22

File size:
1.8 MB (1,929,216 bytes)

Product version:
4.17.0.0

Copyright:
(c)Iminent. All rights reserved.

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 10:31:06 AM

Valid to:
1/27/2012 10:31:03 AM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
4/29/2011 10:38:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x112339

Entry point:
E8, 2A, 7E, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, F0, AE, 58, 00, 75, 02, F3, C3, E9, B1, 7E, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 61, 83, 7D, 08, 00, 75, 13, E8, 78, 18, 00, 00, 6A, 16, 5E, 89, 30, E8, 1B, 81, 00, 00, 8B, C6, EB, 48, 83, 7D, 10, 00, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, BD, 61, 00, 00, 83, C4, 0C, EB, C7, FF, 75, 0C, 6A, 00, FF, 75, 08, E8, DB, 1E, 00, 00, 83, C4, 0C, 83, 7D, 10, 00, 74, BB, 39, 75, 0C, 73, 0E, E8, 2E, 18, 00, 00, 6A...
 
[+]

Code size:
1.2 MB (1,285,120 bytes)

Remove bootstrapper_0-uvdhqmap_.exe - Powered by Reason Core Security