flvplayersetup.exe

Fanudim

Delta Platform (New Media Holdings Ltd.)

The application flvplayersetup.exe, “Fanudim Setup ” by Delta Platform (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.jdmdacconecptsafe.com and multiple other hosts.
Publisher:

Product:
Fanudim

Description:
Fanudim Setup

Version:
1.4.4.0

MD5:
ebb01e4daa0dc85377c77dac24564007

SHA-1:
076b87af53ff9c80d24fa042ad3cdfff447d1beb

SHA-256:
08c27e0a6b8fd933ef809a95863b1a76c2e5b4bc5a36d5a43a1e31d9c9a7c0cc

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
8/16/2025 6:47:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.6.2.21

File size:
931.4 KB (953,720 bytes)

Product version:
1.4

Copyright:
Web Software File

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 8:43:14 AM

Valid to:
9/10/2016 12:45:49 PM

Subject:
CN=Delta Platform (New Media Holdings Ltd.), O=Delta Platform (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215632C018A1E83562EBEAAED95E42B2D3

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:8avv+aRdb5m6p50gLbhNCk0nilCnZp8ysAHpe:nnndb/xLbhAXfZTJe

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file flvplayersetup.exe has been seen being distributed by the following 50 URLs.

http://www.jdmdacconecptsafe.com/WVl6OTRQVFpXVEhSUmQwcDNUeVV5UWlVeVJsYzBiRUpwY0dnMmJrSnllRkZ0SlRKR1ZqbG5jMkZYWlc1U1RIbFVUV1JyY0dNbE0wUW1ZejBsTWtaaVVFVnhhVkFsTWtZbE1rWnlaWEJJTm0wd1ppVXlRbE5RVFhadFVWZHVaa2xFZGtkdFNDVXlRbmxCUWxWTWNITkRjRE5hT0ZoUmVXNTVTRVpYU2tSR05XNXBTbEpMWTNFNE5teDBhWE5EWlZBNVMzUk5UVUV6VnpOQmMzZDBNbVJGY0hsVlJqQnVWMXB2YUZNNFkzbFhiVFZzU21keU5XeG1SVU5IUVc4NVVTVXlSa1JEUjJzeWNRPT0=

http://www.jdmdacapplicationsnow.com/WVl6OTRQVVI2VDNKUFYybFNSMDl6V1drbE1rSk9abEpxYWpOUlpXVlZlSEpxVVVsbVMwMDJjRmRMU2sxaFRsTlpSU1V6UkNaalBXMHdWeVV5UW1kamJVRkpWVEpITVRSSFptUnNXV2xEVjNVeGQxQnVjR3A0UTNSMkpUSkdlQ1V5UW1WT1J6Wk5ZM1I2UzFKM1FpVXlRblJZTTBodE5WbzJSVUpITnpoVVYweGtOWEY0V2pCV00ySTBiM0pMWWxnbE1rWk1SbVJKUWt0WVF6UjFZbXR6VHpaVFJIZHNkRkVsTWtabFdWQlVOMmRpU2xkeVJXcHdVazk0V1RoVlEyTlRWRGRP

http://www.newstockgift.com/WVl6OTRQVXMyT1V4Q1dtaHNRbU5QVENVeVJqTkJaMGRhWlZaUU1XZHZkakk0Yldzd1ZsVXlTVXROV1dWb1dUZzFTU1V6UkNaalBXWlRXVkpGWlUxVFIxWlNSVXBSYVZSNVpHNVRaa0ZPV205emFIVlpjemxFVEhJeE9XUWxNa0pDTkNVeVFteHVhMHBuTWxCMk5HazVWMXBIVFVGelkzRmxiR3BrUlVKc1lqUWxNa0p0Ymt0NVVVcEpRMGRSZURScWFqa3lUbTFsT0UxVlEyRXdRVklsTWtJNVNsSnpXWFE0TUZCcWNEUlFjVkJYT0RSNVpuQnhUMW8yY1RGSVlXcz0=

http://www.jdmdacnowapp.com/WVl6OTRQVEp2ZWs1YVZIQkhUelZWU2t0U1RtTlRNMGhsVkZKSlNHbFZkMlJoU0ZkQ1pVTkpRazlsUWpJeFoyY2xNMFFtWXowM1VrdENTMnB2TTJ0bVRFNDBTRWd4UnpOUFYyNWpPVFZrY0hVM1RYQTJTbU5pYUdvMU1XVklZa2hEZFRsT1VtMVhlRzVYUzFCaE4zUkNNRmN5VDJ4V05HMVVTVFkyWkVWS1ZXTWxNa0pCWlRVeUpUSkNjMVJxVERkUFVFbHhVMFpIUVZac1ZDVXlSbnBtU2tWNVluRjZSalkzYzFoQ1Z5VXlSa2h5UlV0UVNXWlNSSEF6TTJkdg==

http://www.newstockgift.com/WVl6OTRQWHA0UVZvd1MxbHZKVEpDVlZrd2MxQndRVmxWSlRKQ1JWQlliR0pPYUZKWmVWZFlNRXRhVFZVbE1rWlJiQ1V5UmtGbGN5VXpSQ1pqUFVNMlkwUnViVlYzZW5aYWVWQTRhMjlPYW5vM1lXNW1lbTQzY1dOT01GRm1TRkJpV1hSWVF5VXlSazFVV1hwUFVXZ2xNa0pzYlVKVVVGWXlVa1JOT1RWeVV6WXlhVlZrYVVGek1rZExaVWgyWjFOT2NYaGhKVEpHUld4TlMyUkxSMWhwTlhOTlFUVTJlSGhEVTIxTWEwTlZjbUowUTFZbE1rWjJTMjlOYUV4bmFVSlVNemN6YVdjPQ==

http://www.jdmdacconecptsafe.com/WVl6OTRQWGN5Y0Zsa05sWk1SV3N6VjJWdWRHRnRUSE4yT0d4bU0yZFZaWEEyUlRBbE1rSjZUbW95TVZnelVGcGpZeVV6UkNaalBVVkJiMWhpV1daalYwbDNOM0ExVDFoTVduVlZWemRIWjJ4aVNIZDZaMHRyUzNCeWJWbHJSMFIxVm5sSlJtdHJNM05DTUhKc2RpVXlSbTVaYmxCcGFuUlZSRE5TVmtZeU4wcG1XRmx2YjJsVVZFeHBOSGx0WldaNlJXTlphSG9sTWtabVdtOVlhbTF3TVdGTmJHMVdOMVprY2pKbFUyTTVlalY2V25SRk5tTk1jRmQyU1E9PQ==

http://www.jdmdacconecptsafe.com/WVl6OTRQV2xTYXlVeVFqTmlOeVV5UW1sNU0yRm5OR040TTJrMGRsUTVUWGRDZENVeVJqbFNUWG8wU0hWVVJXWlRKVEpDY2toUE5DVXpSQ1pqUFZKR00xUlJjSE5ZVVhaeVRGUkhNV1pUY1ZBbE1rSXpjWGt6UlZrM1JYSk9WVVE0YVc5Q1ZYZFFlbWxLVjA1MFJqUWxNa0pIVEVsWkpUSkdXR2hGWjNBMEpUSkNURTlCYmtGNFMzcEJXbWN3U2xGNVdpVXlSbmd4Y25WTVVWRnJObTF2SlRKQ2RUTm1kbXBNWldZemJqSjZhMloxZGlVeVFqaEJhMUEwUTNkU2FqbDVNME01ZERBbE1rSjJRMUYxY1E9PQ==

http://www.jdmdacapplicationsnow.com/WVl6OTRQV1Z3Y0VFMmVWcEtjRzF6T0dkdVFWVkZNMU5sY2twaFRsSjNhR2R2T1ZvMlVYTXdPRTlhY2t0UmMyc2xNMFFtWXoweFMyaE1lREJNZGlVeVJuSndjak0xU0d4RFlVbHRjelIyY1cxVVVEZE9KVEpDVkhsNU1HWk9jVWw0Y2tVbE1rWlFjbU5uVUhKUU9YY2xNa0pYVEV0V2VsaFJlbEl3ZGs1SlVscHJkREJNYjNkbWFWWk9NakJLY0dSNVN6azVjRWhSZDFScmFFd2xNa1pLTVRsV1dtZzVjbkZRYjNGUWJIa3hWa1Z3UmsxTmRFRkhKVEpDYTFnek9IQlFXUT09

http://www.jdmdacconecptsafe.com/WVl6OTRQWGxMWVZCMGQwcHllV28wVGxocVdXWlVlakozYnpKcGRHdGxVRU5rUVNVeVFpVXlRbVZZSlRKR1IzaHlRVk5YYTAwbE0wUW1ZejE0WlhaQlYyOXdVMU5ZSlRKR05FNWxkMmhxVldkdWFGTmhiVkZaV1VsSWVFUnFZVTl2VTBKeFIyczFkbUZWTUVGM2RsTnJhVmRIWVhNMFZYcFNlRFU1UVRjNFRsVk9VRVV6TlZZMWNEZFVkM00xYVNVeVFsUkliRUpoZDI5bWJteEdObkpyT1ZRMU5sWllTMnBqZFNVeVFtTXlRVTVMTkRVNFptRmxWVU5DVkhSelV6QlBhQT09

http://www.jdmdacapplicationsnow.com/WVl6OTRQV2RwVVRKd05GQm9RMWhaSlRKQ1pFSm5kRzV0ZVhSQllsbG5aMUYzVXpSR05HNUphamxZTUVGR1FqaFhRU1V6UkNaalBYRWxNa1pyV1dJbE1rWnhhVE42SlRKQ2QwMVlKVEpDTWxORU5IcFFSbmxtZEhweVduTlNTRWt6TWxvMFFubHBhVWxzVW1aM1VYcEtZMEZaVTNOR2NucHhhR0pwU1hGc1RHWTRNVkZwWVdSbWRsY3lWak5FVWpKdU5WVlFiVWMxUlZacE1tRkdkRTlOUTJSbFltOUVSMk1sTWtKc2JTVXlRa1JCYzAxbmQyRlNVM0ptYldoSlkybHhUbkE0

http://www.jdmdaccyclenow.com/WVl6OTRQVFZGYUhab2R6TnVKVEpHVjJKMlIwTk9NR3R3U25nMWNWbHBUbVJqUTB4MU9DVXlRbnB4UkVSVWVGSk1PRlp6SlRORUptTTlkV3h6TW5kdVFWbEdia0pNUlZoV1dYTm1NbEJRYm5oeGJtODVNRkI1UWxOdmNIaFpNREpPWldwRGFrVXhRamsxZVNVeVFtMWxZMkl4Vm1nNWNtcGhia2hvZDNSaGMxRlhkSEJ5VVdaTFVEbHBVSG93V1ZwVVZWZFRRWE5zTlhGdVMxVTVVRGw0UzFka1kxWTRablZZUlZodFRUWk9halpYUlRkYVdYb3lUbGhVVkE9PQ==

http://www.jdmdacnowapp.com/WVl6OTRQV2M1T0RaUFMxWllSMmRUTVdvbE1rSjBlV0Z4YjBoS1ptZHVRMkZtYVdKQ1RWbHZkVkJIZDJKUE9IRlpVU1V6UkNaalBXSXhSbEJCUzBOTk9FSmthMjk1YTJZeFVFMDVPR0Z6Wm5JeVNETkZkSFZ4WVZVbE1rWjBibll3VkV4U1RqZHJjRVZzTUZaUGFHOTBTVlIzVlZjeFZXOUNUa0ZXV1dZd2FUQXhNemxRZDJvMU4yaERUeVV5UW1Wb2VIUnVSbGRaVW1FNFZWbEtUM1V5VXpjMFV6bHFjRGhOZFZsS2JsQjBjMnBFYTA1bkpUSkdTWHBpY2pkbw==

http://www.jdmdaccyclenow.com/WVl6OTRQWEEyV0hocFpqRlBSbEZZY2tReFVrOTRSalU1YzFBM1RrTnRlR0ZTVlZCT01IVnFNMHMzVWpjd1oxa2xNMFFtWXoxRU4yaHBTMFZqTjJSbWIwMWFVR05rSlRKR1NGSWxNa1poYXpkdVUxTnRjamRJWlRBd1dYTkpWR1JwWTNsNFpuWk1hWE5QWTFwdlNucFFWR0ZCV2psSFpUUkRVbTVqUjBGNk9VcEhTWFp3ZWpnMmN6WjRiM2MzTUhaRU1UTlBNVTV5T1doalFXcHhlREZWTVZOSFNVeDZXQ1V5UWpoWFlrUTVibWxhZFZOTFZ6RnFNSEppTmc9PQ==

http://www.jdmdacbinariesdl.com/WVl6OTRQVGxSZWxKblZVc3dhVE5GUTFCb1NXMTJZaVV5UmpkSGFHWjBhM2R2UlRsNlNtMXlTSFF6TWpOWVpGWnVkeVV6UkNaalBWVmpUblprWkdwWlpFVktZbTV6WlZFd1QzSklKVEpDTmtOUVNXeElNbU5qYzB4eVZYaHJlVEJWTTNWM1EyUllXVUZ3WXpaV1ZtUjBjV2xGY0RoWlpuVnpNVkp5TmtKaVMzaHpZVlFsTWtaRlJWcFRlV1JpVGxGdVIwZFZZM0EyYTFkaVQycFRVMFkwUkdjNVdUQTJXRkZWYzNwTmNWbFZiRkZLTmpBM1MwNVhlbGRsVkE9PQ==

http://www.updaterepositorytown.com/WVl6OTRQWEE0V1VNeWVWTnhlazVtVUVSTVNuTXlSR3QzV1ZGelptaE5jek5XUlU5eFNrcEJXV2tsTWtKUk1EQnhheVV6UkNaalBVdHVSVFZoZWxNbE1rWlhVSFl3WkZWQ01GZExTbWsxVFRkU1VsWkRZamRrVVRoQ1pGUkpWMDlXTUZwVU0yOU1RVVo1UW1KWVNqbHliVkJTY0dOU1JVNDBhR05MVHpSMk1uQjNWRkpOY0ZsTU0zY2xNa0pLVlV0TldXUlJXa1J0TjFKbFYwTjZNV1ozZDBVNVYxZDBNMmR0Vm00bE1rSm9iekUxWmxORGJ6bDNVMFZ4VFdWWA==

http://www.jdmdacnowapp.com/WVl6OTRQVXcyT1VGWFlqZHlURTFDUjNkWVJXOTZNakozV0dsU1V6ZERaVzVwVmxrNGREUnJUMGRMYUVwR1JUUWxNMFFtWXowelpWWXlialF3UzNSWkpUSkdia2QyUlRnd1JYWjBVVlJTWTFsNlJYWmFSVlo1VVZKMmFVdzJabGg0VlROR01UUk5kblF5TW01bllXUk5ObTVZVlVGS05IQm5KVEpDZW5wRVNHVjNPVVZoWXpkWmFGSmhlRXh6ZG5SeVVtMHdZbkpGVVdwUFZVWnpkRkJFU205c2RYZHRlVUppVFc0MFRHSkNUMk0zU1dkTldtcG1ha0k9

http://www.jdmdacbinariesdl.com/WVl6OTRQVkp2VVdsV05XTnhVbTB4YjNZeFpHazRkVEpVZDIwelJEbFljbXhzVlVsU2MzUnJOWFUyY2pGREpUSkdNQ1V6UkNaalBWSm5Va1U0Y2lVeVFuaHpZbWxrZWpkSFUwcHdZWE5wWkZaMmJIZzJOa2QxYkU1dlFYaFVjMmM0UkV4eVNsWk5lV0prVGpBMGREZEliM3BLY1hoRFkycDNTMmh2YlhkelYwZzFlSE5TYTFaeFYwcEZTMUlsTWtaRlUzUTFRVlpqTlZaVVkxcFZPVmRGT0NVeVJrZDFkMHRDSlRKR1NtUnRUWE5SWVdkUVVDVXlRa04yUkhKRGNIWlpPQT09

http://www.jdmdacapplicationsnow.com/WVl6OTRQVWhoVURCU0pUSkdXVXB3VVZKWVl6TWxNa1ozU1NVeVFsZDJTbloyWTNkalVqZFJNbWRLY2twaFdqUkVaWGxhZFhjbE0wUW1ZejFGY0hOMGJqZFlSM1psVEc5WFMwUnZVMGdsTWtKdFlTVXlRazFyVmxCTFIyRkpKVEpHVkdWdVlqQnBOVk5NUzBobVREaElWWFZhYWtjNE1HVndhaVV5Um01ek5FUnphMVV5Wm05eVZWSjJKVEpDVUcxdGMzWXlSRFZUYW1wSU1WaHFkMVZITkcxRGRIa3dNazFpV0VwQ1JWWTNjVGx6Tm1kUFQzcGlXRzU1YlRSSGJGVnpTVGROTkhRPQ==

Latest 30 of 87 download URLs

Remove flvplayersetup.exe - Powered by Reason Core Security