ilividsetup-r267-n-bc.exe

iLivid

Bandoo Media, Inc

The application ilividsetup-r267-n-bc.exe by Bandoo Media, Inc has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download.cdn.sharelive.net and multiple other hosts. While running, it connects to the Internet address client-200.60.190.132.speedy.net.pe on port 80 using the HTTP protocol.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc)

Product:
iLivid

Description:
iLivid Install

Version:
5.0.0.4151

MD5:
4a7c698494825bbb02ac576bcb99eaac

SHA-1:
b21d8548e27b23c5ca4cc7f045287a5fbbf15618

SHA-256:
11fa89d4ad1d6aaf8bf5ddaabf50ca0827b238961bff5918d5ef9379fe829ade

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
4/18/2024 10:38:31 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
PUP.Installer.BandooMedia.V
13.11.25.19

Dr.Web
Adware.Bandoo.13
9.0.1.0329

ESET NOD32
Win32/Toolbar.SearchSuite (variant)
7.9166

Malwarebytes
PUP.Optional.Bandoo
v2013.11.25.07

Reason Heuristics
PUP.Optional.Installer.BandooMedia.V
14.3.1.1

File size:
1.6 MB (1,645,424 bytes)

Product version:
5.0.0.4151

Copyright:
Copyright (c) 2013

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ilividsetup-r267-n-bc.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/19/2012 2:00:00 AM

Valid to:
11/3/2014 12:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7A5189D163723107DEFA157662A4BAE4

File PE Metadata
Compilation timestamp:
5/30/2013 10:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:B8C4St5Qhkk9sZ0t23FSHZQsky045WcjFd2FAbIESqVvhBz:54eEkkU39Y04bFd26IESqRrz

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file ilividsetup-r267-n-bc.exe has been seen being distributed by the following 50 URLs.

http://download.cdn.sharelive.net/cdn/r/.../iLividSetup-r197-n-bi.exe

http://download.cdn.sharelive.net/cdn/r/.../iLividSetup-r641-n-bi.exe

http://download.cdn.sharelive.net/cdn/r/.../iLividSetup-r514-n-bi.exe

http://download.sharelive.net/cdn/r/.../iLividSetup-r934-n-bi.exe

http://pf.dlcvit.com/s/.../2/228832-673610-ilivid.exe

http://download.sharelive.net/cdn/r/.../iLividSetup-r420-n-bi.exe

http://i_mp3-es_ilivid-4-0-0-2466.fiblotaredut.com/crawled_soft/2/2/.../228832-673610-ilivid.exe

http://i_mp3-es_ilivid-4-0-0-2466.fiblotaredut.com/crawled_soft/2/2/.../228832-673610-ilivid.exe

http://i_mp3-es_ilivid-4-0-0-2466.fargutareflo.com/crawled_soft/2/2/.../228832-673610-ilivid.exe

http://download.cdn.downloadsetup.net/cdn/r/.../iLividSetup-r0-n-bi.exe

http://download.cdn.downloadsetup.net/cdn/r/.../iLividSetup-r120-n-bi.exe

http://download.cdn.sharelive.net/cdn/r/.../iLividSetup-r612-n-bc.exe

http://download.cdn.sharelive.net/cdn/r/.../iLividSetup-r1248-n-bi.exe

http://download.cdn.sharelive.net/cdn/r/.../iLividSetup-r429-n-bi.exe

Latest 30 of 164 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to client-200.60.190.132.speedy.net.pe  (200.60.190.132:80)

TCP (HTTP):
Connects to a173-223-11-145.deploy.static.akamaitechnologies.com  (173.223.11.145:80)

TCP (HTTP):
Connects to 202tdev20.codetel.net.do  (200.88.20.202:80)

TCP (HTTP):
Connects to 201tdev20.codetel.net.do  (200.88.20.201:80)

Remove ilividsetup-r267-n-bc.exe - Powered by Reason Core Security