iminentsetup{2.weial76.1}.exe

IMBooster

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application iminentsetup{2.weial76.1}.exe, “IMinent bootstrapper” by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Iminent  (signed and verified)

Product:
IMBooster

Description:
IMinent bootstrapper

Version:
5.11.2.1

MD5:
8ff1949d86ed2f1f79dc3832939a7e10

SHA-1:
8356df3316ba8579e1fac90795d0af2ac68a458a

SHA-256:
9d756acf0c75c919af0a84f22e5e6bce27bd0b75999500fddc015ca2f488f175

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/4/2024 2:45:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.13.2

File size:
804.1 KB (823,376 bytes)

Product version:
5.11.2.1

Copyright:
(c)Iminent. All rights reserved.

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2012 4:55:45 PM

Valid to:
3/2/2014 4:55:45 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EA925C07E01E1C06B597DD4B36FAA8B

File PE Metadata
Compilation timestamp:
3/13/2012 6:42:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:9vkgn83Ot3AFObzjwZcItQrw4xUwOwp+nRxz1Fme:9V8eKFm0Ovrw4Sxz

Entry address:
0x2027A0

Entry point:
60, BE, 00, 70, 55, 00, 8D, BE, 00, A0, EA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8488

Packer / compiler:
UPX 2.90LZMA

Code size:
688 KB (704,512 bytes)

Remove iminentsetup{2.weial76.1}.exe - Powered by Reason Core Security