Setup.exe

IMALI – N.I. MEDIA LTD

The file Setup.exe by IMALI – N.I. MEDIA has been detected as adware by 14 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from www.downanapp.com and multiple other hosts.
Publisher:
IMALI – N.I. MEDIA LTD  (signed and verified)

MD5:
f32a95448aca5d1887249c84534b0d11

SHA-1:
4bce8bf1793375e3b45bdc0efafb975c55875f29

SHA-256:
cd9a0c541a4e2a425c4b93fd392c7a1504861dc907806effc859d4847f3b5262

Scanner detections:
14 / 68

Status:
Adware

Analysis date:
4/25/2024 3:37:51 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Rootkit.72610
704

Avira AntiVirus
TR/Dldr.Agent.434064
7.11.209.28

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150210

Bitdefender
Rootkit.72610
1.0.20.310

Emsisoft Anti-Malware
Rootkit.72610
8.15.03.03.01

F-Secure
Rootkit.72610
11.2015-03-03_3

G Data
Rootkit.72610
15.3.25

IKARUS anti.virus
Trojan-Downloader.Agent
t3scan.1.8.6.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2405

McAfee
Artemis!F32A95448ACA
5600.6859

MicroWorld eScan
Rootkit.72610
16.0.0.186

Qihoo 360 Security
Win32/Trojan.eaa
1.0.0.1015

Reason Heuristics
PUP.IMALINIMEDIA
15.2.10.3

Trend Micro House Call
Suspicious_GEN.F47V0203
7.2.41

File size:
423.9 KB (434,064 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/29/2014 4:24:00 PM

Valid to:
12/30/2015 4:24:00 PM

Subject:
E=contact@imalimedia.net, CN=IMALI – N.I. MEDIA LTD, O=IMALI – N.I. MEDIA LTD, L=Ramat Gan, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215FB4642CA96492ED635B137D682A42C4

File PE Metadata
Compilation timestamp:
2/2/2015 10:42:34 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:wObE0mNgzXB4i5r3IyYzkleXaMYsNShqZj6MhQ1iQEIP+PuKZ:wOlDzXT5AkleXAASY+MDVW+PZZ

Entry address:
0x19E41

Entry point:
E8, CA, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 20, D5, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, D0, D0, 42, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81...
 
[+]

Entropy:
6.3652

Code size:
176 KB (180,224 bytes)

The file Setup.exe has been seen being distributed by the following 2 URLs.

Remove Setup.exe - Powered by Reason Core Security