Setup.exe

IMALI – N.I. MEDIA LTD

The file Setup.exe by IMALI – N.I. MEDIA has been detected as adware by 12 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from www.classicvideoplayer.com and multiple other hosts.
Publisher:
IMALI – N.I. MEDIA LTD  (signed and verified)

MD5:
d46c5bdc11a48bc209b814b80942e3c3

SHA-1:
ff28a3b4b98b068131629238ab7c7286a0de5ad7

SHA-256:
ff5b1c3337aa4a01b56572751f7c64c94dcd9a84ae52a9f4665914255a0e6e14

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
6/23/2025 6:56:42 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Rootkit.72610
704

Avira AntiVirus
TR/Dldr.Agent.436112
7.11.210.46

avast!
Win32:Rootkit-gen [Rtk]
150203-1

Bitdefender
Rootkit.72610
1.0.20.310

Emsisoft Anti-Malware
Rootkit.72610
8.15.03.03.01

F-Secure
Rootkit.72610
11.2015-03-03_3

G Data
Rootkit.72610
15.3.25

IKARUS anti.virus
Trojan-Downloader.Agent
t3scan.1.8.6.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2405

MicroWorld eScan
Rootkit.72610
16.0.0.186

Qihoo 360 Security
Win32/Trojan.eaa
1.0.0.1015

Reason Heuristics
PUP.IMALINIMEDIA
15.2.13.19

File size:
425.9 KB (436,112 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/29/2014 8:24:00 AM

Valid to:
12/30/2015 8:24:00 AM

Subject:
E=contact@imalimedia.net, CN=IMALI – N.I. MEDIA LTD, O=IMALI – N.I. MEDIA LTD, L=Ramat Gan, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215FB4642CA96492ED635B137D682A42C4

File PE Metadata
Compilation timestamp:
2/12/2015 10:24:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:+aTN0+KgLiWpGWr3IYbbC0tB3gdZvtShqZj6MhQ1iQEIP+Pubjn:+ayWLifWDa0tB3K1SY+MDVW+Pwn

Entry address:
0x19E41

Entry point:
E8, CA, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 20, D5, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, D0, D0, 42, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81...
 
[+]

Entropy:
6.3607

Code size:
176 KB (180,224 bytes)

The file Setup.exe has been seen being distributed by the following 14 URLs.

http://www.classicvideoplayer.com/.../300?sub_id=000041bd3ed304726489298fa89183b8806c4&pub_id=351&template=lp8

http://www.classicvideoplayer.com/.../300?sub_id=00003fd6194a57b824d9da106e535c1abee65&pub_id=351&template=lp

http://www.latestflv.com/down/java/.../down.php?sid=497&dv1=ad490-us&kw1=ad490-us-xx&uuid=3d6caa34-8af2-4501-5fe4-dfcbf2f9832e&dv3=3d6caa34-8af2-4501-5fe4-dfcbf2f9832e

Remove Setup.exe - Powered by Reason Core Security