setup.exe

IMALI – N.I. MEDIA LTD

The application setup.exe by IMALI – N.I. MEDIA has been detected as adware by 32 anti-malware scanners. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from www.onthesoft.com and multiple other hosts.
Publisher:
IMALI – N.I. MEDIA LTD  (signed and verified)

MD5:
9c81b80bf9ebef244648646d566d724c

SHA-1:
661b2218651ceac758819dbc365fbfc3b0621301

SHA-256:
808373ef500032e43fa62b38c5a0b806e74fd5da633d609cf3559833f969e7bd

Scanner detections:
32 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
8/9/2025 8:35:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2191985
568

Agnitum Outpost
PUA.Imali
7.1.1

AhnLab V3 Security
PUP/Win32.Imali
2015.06.24

Avira AntiVirus
ADWARE/Adware.Gen7
8.3.1.6

Arcabit
Trojan.Generic.D217271
1.0.0.425

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150716

AVG
Generic6
2016.0.3046

Baidu Antivirus
Adware.Win32.Imali
4.0.3.15716

Bitdefender
Trojan.GenericKD.2191985
1.0.20.985

Bkav FE
W32.HfsAdware
1.3.0.6597

Clam AntiVirus
Win.Trojan.Imali
0.98/21511

Comodo Security
Application.Win32.Adware.Imali.RTK
22550

Dr.Web
Trojan.Crossrider1.31135
9.0.1.0197

Emsisoft Anti-Malware
Trojan.GenericKD.2191985
8.15.07.16.11

ESET NOD32
Win32/Adware.Imali (variant)
9.11828

Fortinet FortiGate
Riskware/Imali
7/16/2015

F-Prot
W32/S-623c07dc
v6.4.7.1.166

F-Secure
Trojan.GenericKD.2191985
11.2015-16-07_5

G Data
Trojan.GenericKD.2191985
15.7.25

IKARUS anti.virus
PUA.Imali
t3scan.1.9.5.0

K7 AntiVirus
Riskware
13.205.16325

McAfee
Artemis!9C81B80BF9EB
5600.6702

MicroWorld eScan
Trojan.GenericKD.2191985
16.0.0.591

NANO AntiVirus
Trojan.Win32.Genome.dojnqf
0.30.24.2086

nProtect
Trojan.GenericKD.2191985
15.06.24.01

Panda Antivirus
Trj/Genetic.gen
15.07.16.11

Qihoo 360 Security
Win32/Trojan.0a7
1.0.0.1015

Reason Heuristics
PUP.IMALI.IMALINIMEDIA.Installer (M)
15.7.16.23

Trend Micro
TROJ_GEN.R00GC0OC315
10.465.16

Vba32 AntiVirus
TrojanDownloader.Genome
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41380

Zillya! Antivirus
Adware.Imali.Win32.2
2.0.0.2251

File size:
425.9 KB (436,112 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\45g43283\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/29/2014 10:24:00 AM

Valid to:
12/30/2015 10:24:00 AM

Subject:
E=contact@imalimedia.net, CN=IMALI – N.I. MEDIA LTD, O=IMALI – N.I. MEDIA LTD, L=Ramat Gan, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215FB4642CA96492ED635B137D682A42C4

File PE Metadata
Compilation timestamp:
2/12/2015 12:24:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:+aTN0+KgLiWpGWr3IYbbC0tB3gdZvtShqZj6MhQ1iQEIP+PubjF:+ayWLifWDa0tB3K1SY+MDVW+PwF

Entry address:
0x19E41

Entry point:
E8, CA, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 20, D5, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, D0, D0, 42, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81...
 
[+]

Entropy:
6.3607

Code size:
176 KB (180,224 bytes)

The file setup.exe has been seen being distributed by the following 4 URLs.

Remove setup.exe - Powered by Reason Core Security