ilividsetup-r420-n-bi.exe

iLivid

Bandoo Media, Inc.

The application ilividsetup-r420-n-bi.exe by Bandoo Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.ilivid.com.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc.)

Product:
iLivid

Description:
iLivid Install

Version:
5.0.0.4736

MD5:
03423e35f2cf8674cd89ea5c121733a5

SHA-1:
37b37706d4287908abe656a1a084fcafbdf0d822

SHA-256:
9806b41a47fbdbdb09a94b1228c53e0ffee0c7ee422ecf5b920db6ca384bc53d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
4/19/2024 1:33:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo (M)
16.8.5.15

File size:
1.8 MB (1,918,360 bytes)

Product version:
5.0.0.4736

Copyright:
Copyright (c) 2014

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ilividsetup-r420-n-bi.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
11/25/2014 2:00:00 AM

Valid to:
2/24/2015 1:59:59 AM

Subject:
CN="Bandoo Media, Inc.", O="Bandoo Media, Inc.", L=Panama City, S=Panama, C=PA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6339DB399F0BC52F3B85B4FA3D4AACF7

File PE Metadata
Compilation timestamp:
5/30/2013 11:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:64dBESYrgGUCuVEt03ugUv8Fb3NraKgC5mqDSqRpolPN:6CBlYsfZFjNr55mukP

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Entropy:
7.4781

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file ilividsetup-r420-n-bi.exe has been seen being distributed by the following URL.

Remove ilividsetup-r420-n-bi.exe - Powered by Reason Core Security