sdf73b9.exe

Installer

IMALI - N.I. MEDIA TD

The application sdf73b9.exe by IMALI - N.I. MEDIA TD has been detected as adware by 3 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
IMALI - N.I. MEDIA TD  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
0f3eecdf42814569384cb6b9d7a3d8ce

SHA-1:
4d4e8c2d8e9aaeeddec029f7da963f99fdbc2659

SHA-256:
04b1e6a25065df88e78999d1ee13b04ffe64cecbcbe219061a34962cb41bb1f3

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
5/6/2024 12:25:18 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3250

ESET NOD32
MSIL/Downloader.Agent (variant)
8.10922

Reason Heuristics
PUP.Optional.Installer
15.1.16.10

File size:
350.4 KB (358,856 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\sdf73b9.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/13/2014 5:00:00 PM

Valid to:
8/14/2015 4:59:59 PM

Subject:
CN=IMALI - N.I. MEDIA TD, OU=online media, O=IMALI - N.I. MEDIA TD, STREET=reines 50, L=tel-aviv, S=tel-aviv, PostalCode=64587, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0093FCE354B4016AD3D34DEC6ADB0B6F35

File PE Metadata
Compilation timestamp:
12/23/2014 5:04:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:GzlhuFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5V53ILs7E16:Gzl0ZwgVxGq86oH/MKvnolg5amM6

Entry address:
0x55B5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7922

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
335 KB (343,040 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove sdf73b9.exe - Powered by Reason Core Security