iminenttoolbarff.exe

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application iminenttoolbarff.exe by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from vz.iminent.com and multiple other hosts.
Publisher:
Iminent  (signed and verified)

MD5:
bd3d6cce4fe624974f69c21b1150483b

SHA-1:
56a5a29c3f4a3016b0842344cd0f0e9390ca02be

SHA-256:
b9f0277281c5864f760204505233c8a89e325583c01df80de404820f19a52962

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/20/2024 3:02:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Iminent.Q
14.8.8.0

File size:
1.7 MB (1,828,584 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\iminenttoolbarff.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 12:31:06 PM

Valid to:
1/27/2012 12:31:03 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
12/7/2011 6:40:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:jULIHkE7Sx5HUrl3IobNCorsSVDcALm/ueUQJu7KQjh:jwEegrNLNHcAMuKOj

Entry address:
0xB3C1

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, F2, 2D, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, B0, A1, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 1C, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 1C, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, D9, A6, FF, FF, C3, 55, 8B, EC, 83, EC, 1C, 56, 33, F6, 56, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 40, 32, 41, 00, 85, C0, 74, 21, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 44, 32, 41, 00, 8D, 45, E4...
 
[+]

Entropy:
7.9647  (probably packed)

Code size:
71 KB (72,704 bytes)

The file iminenttoolbarff.exe has been seen being distributed by the following 2 URLs.

http://vz.iminent.com/vz/fe3dc087-8c2e-4130-b85d-5fc7de0db148/.../IMinentToolbarFF.exe

Remove iminenttoolbarff.exe - Powered by Reason Core Security