Microsoft.Expression.Interactions.dll

Microsoft.Expression.Interactions

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module Microsoft.Expression.Interactions.dll by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
Microsoft.Expression.Interactions

Version:
1.0.1343.0

MD5:
ef4235383a506e6e2a6e2e99f45a457b

SHA-1:
2bb37cd3a83ac96330cf5f15e821efa06f2fa42f

SHA-256:
8145192cda3d008db5e72fa9c5167a392e5a28d03638b89c2ff405eda1db35c6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 4:06:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.15.9

File size:
70 KB (71,672 bytes)

Product version:
1.0.1343.0

Copyright:
Copyright (c) Microsoft Corporation. All rights reserved.

Original file name:
Microsoft.Expression.Interactions.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
SIEN SuperInstall

Language:
Language Neutral

Common path:
C:\Program Files\iminent\microsoft.expression.interactions.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 1:31:06 PM

Valid to:
1/27/2012 1:31:03 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
2/17/2010 1:24:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:4s+W3fjbybd/1H2aqfXC13NIahC3rd46NkAkEYiOE2:L+OCj2kAkAWid2

Entry address:
0xE05E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
52 KB (53,248 bytes)

Remove Microsoft.Expression.Interactions.dll - Powered by Reason Core Security