idman621build2.exe

Internet Download Manager

The application idman621build2.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from internet-download.joydownload.com.
Product:
Internet Download Manager

Version:
1.0.0.0

MD5:
aa62b67c93385537852dd7e7462b67fb

SHA-1:
ab4f6a659a77aa5078812f6815ef7999ba25974d

SHA-256:
df556a6143f9fd3721fa7f2fde2460ebcb4335b76257664d9aed08ff2055dd17

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 12:45:03 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160327-1

AVG
Win32/Sality
2015.0.4355

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Program.Artemis!1486BAA55414
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.1832.0

Norman
Win32.Sality.3
10.04.2016 15:29:17

File size:
484.7 KB (496,352 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\idman621build2.exe

File PE Metadata
Compilation timestamp:
5/19/2013 4:53:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:9ructFC936vmRlxc7YNX0xU1dZqCNqaF3X3c/yhI/FSPDkJh:MJJKUR0m3qNc35hYSPDkJh

Entry address:
0x331C

Entry point:
84, D8, 3D, 66, 0C, 41, 91, 68, 06, 73, D7, 00, 89, E9, 0F, B6, F9, 85, F9, 76, 03, 0F, BF, EE, 68, 30, C4, 51, 00, 68, EB, B1, EA, 00, 69, C1, 2B, C3, C4, 04, 34, 91, 8B, EB, FE, C4, 8D, 0D, 9C, BF, 53, 41, 25, 4E, 37, 92, E2, 57, FF, CB, C7, C6, F1, 69, E7, A8, 89, CD, E8, 1C, 00, 00, 00, 40, 0F, AF, F2, F3, 80, ED, C4, 14, 18, F7, C6, 1A, A3, 9C, 67, 89, D2, 84, FA, 33, EF, 85, FA, 02, CA, 88, F9, 15, B6, A5, 8F, DD, B2, 98, 2C, 47, FF, CB, 88, D2, BE, 1B, 05, 00, 00, 22, DA, 89, D8, 6B, F6, 03, 77, 03...
 
[+]

Entropy:
7.8509  (probably packed)

Code size:
24 KB (24,576 bytes)

The file idman621build2.exe has been seen being distributed by the following URL.

Remove idman621build2.exe - Powered by Reason Core Security