umbrella.exe41eeb2

Iminent Protection

Iminent

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file umbrella.exe41eeb2 by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer. It is also typically executed from the user's temporary directory.
Publisher:
Iminent  (signed and verified)

Product:
Iminent Protection

Version:
3.23.4.1

MD5:
bfe4914b87487239664b2d313b608e04

SHA-1:
4b5b1289c72617f0617190c2047eb37589419283

SHA-256:
b3b4787616d796ed40ac873b94ceced5e5cd59d8e00fd55f833ba27cb56e5b08

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 10:59:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent.Bundler (M)
16.2.12.2

File size:
2.6 MB (2,715,176 bytes)

Product version:
3.23.4.1

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\umbrella.exe41eeb2

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2012 10:55:45 AM

Valid to:
3/2/2014 10:55:45 AM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EA925C07E01E1C06B597DD4B36FAA8B

File PE Metadata
Compilation timestamp:
6/5/2013 10:40:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:736Ndg+/1lHrKuc5v2JDBZjPkosIw3jbwxS/PI4xMjBOrzYoqrbJX4ESOsgSuJrR:L6fg+vHrKuC2JDBR6Iw3jbwxS/PTxMj5

Entry address:
0x184F48

Entry point:
E8, CB, 8A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 61, 83, 7D, 08, 00, 75, 13, E8, B7, 50, 00, 00, 6A, 16, 5E, 89, 30, E8, C5, 8C, 00, 00, 8B, C6, EB, 48, 83, 7D, 10, 00, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 5D, 10, 00, 00, 83, C4, 0C, EB, C7, FF, 75, 0C, 6A, 00, FF, 75, 08, E8, BB, 17, 00, 00, 83, C4, 0C, 83, 7D, 10, 00, 74, BB, 39, 75, 0C, 73, 0E, E8, 6D, 50, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, B2, 6A, 16, 58, 5E, 5D, C3, 8B...
 
[+]

Code size:
1.8 MB (1,928,192 bytes)

Remove umbrella.exe41eeb2 - Powered by Reason Core Security