Setup.exe

IMALI – N.I. MEDIA LTD

The file Setup.exe by IMALI – N.I. MEDIA has been detected as adware by 26 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from www.downanapp.com and multiple other hosts.
Publisher:
IMALI – N.I. MEDIA LTD  (signed and verified)

MD5:
9ae024afae2e4025b60f72c41c50d236

SHA-1:
e750935f23ee7b13ee162320e779afd11f847ae5

SHA-256:
0b6298e293135e64623f2ff3a8712a822d879f71b4d0fe5cb1e31f9df494c47c

Scanner detections:
26 / 68

Status:
Adware

Analysis date:
4/24/2024 11:46:25 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Rootkit.72610
697

AhnLab V3 Security
PUP/Win32.Imali
2015.03.09

Avira AntiVirus
TR/Dldr.Agent.436112
7.11.210.138

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150310

AVG
Generic
2016.0.3175

Bitdefender
Rootkit.72610
1.0.20.345

Comodo Security
Application.Win32.Adware.Imali.RTK
21349

Dr.Web
Program.Unwanted.228
9.0.1.069

Emsisoft Anti-Malware
Rootkit.72610
8.15.03.10.03

ESET NOD32
Win32/Adware.Imali (variant)
9.11290

Fortinet FortiGate
Riskware/Imali
3/10/2015

F-Secure
Rootkit.72610
11.2015-10-03_3

G Data
Rootkit.72610
15.3.25

IKARUS anti.virus
Trojan-Downloader.Agent
t3scan.1.8.6.0

K7 AntiVirus
Riskware
13.200.15204

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1879

McAfee
Artemis!9AE024AFAE2E
5600.6831

MicroWorld eScan
Rootkit.72610
16.0.0.207

NANO AntiVirus
Trojan.Win32.Genome.dojnqf
0.30.0.296

nProtect
Trojan.GenericKD.2191985
15.03.09.01

Qihoo 360 Security
Win32/Trojan.0a7
1.0.0.1015

Reason Heuristics
PUP.IMALI
15.3.10.3

Trend Micro House Call
TROJ_GEN.R02PC0EC615
7.2.69

Trend Micro
TROJ_GEN.R02PC0EC615
10.465.10

VIPRE Antivirus
Trojan.Win32.Generic
38260

File size:
425.9 KB (436,112 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/29/2014 9:24:00 AM

Valid to:
12/30/2015 9:24:00 AM

Subject:
E=contact@imalimedia.net, CN=IMALI – N.I. MEDIA LTD, O=IMALI – N.I. MEDIA LTD, L=Ramat Gan, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215FB4642CA96492ED635B137D682A42C4

File PE Metadata
Compilation timestamp:
2/12/2015 11:24:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:+aTN0+KgLiWpGWr3IYbbC0tB3gdZvtShqZj6MhQ1iQEIP+PubjZ:+ayWLifWDa0tB3K1SY+MDVW+PwZ

Entry address:
0x19E41

Entry point:
E8, CA, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 20, D5, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, D0, D0, 42, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81...
 
[+]

Entropy:
6.3607

Code size:
176 KB (180,224 bytes)

The file Setup.exe has been seen being distributed by the following 5 URLs.

http://www.downanapp.com/.../300?sub_id=29874248971425151758&pub_id=303&template=lp

http://www.downanapp.com/.../300?sub_id=26822895441425501870&pub_id=303&template=lp

http://www.downanapp.com/.../300?sub_id=u4f8695e3543adabf3f3381e84d&pub_id=303&template=lp5

Remove Setup.exe - Powered by Reason Core Security