setup.exe

IMALI - N.I. MEDIA TD

The application setup.exe by IMALI - N.I. MEDIA TD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from iqabrowser.com.
Publisher:
IMALI - N.I. MEDIA TD  (signed and verified)

MD5:
a5164466886fafec8bd375839e8f1aca

SHA-1:
fe14a98e277a85d8392658bea52236c2b56dc6a5

SHA-256:
db97e0b2b131461864854b90b02f9752acc812eff000c984d474c14f6aabfaa2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/23/2024 10:37:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.IMALI.IMALINIMEDIATD.Installer (M)
16.3.6.1

File size:
519.5 KB (531,968 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/14/2015 9:00:00 PM

Valid to:
1/19/2017 9:00:00 AM

Subject:
CN=IMALI - N.I. MEDIA TD, O=IMALI - N.I. MEDIA TD, L=tel aviv, C=IL

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08A734B220592162976C2E475224888E

File PE Metadata
Compilation timestamp:
12/15/2015 9:57:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:1Jj0xNR+JUQWS6KOhaoO9D00qF+8W0qFul7X0qFk7Mpc0qFAlLVK0qFk7O0q71L:L0xNOP6dhaoXyilDCMm8lLkCO0q71L

Entry address:
0x1A53C

Entry point:
E8, 18, 6D, 00, 00, E9, 89, FE, FF, FF, FF, 35, E8, 31, 43, 00, FF, 15, 80, 90, 42, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 55, 65, 00, 00, 6A, 01, 6A, 00, E8, 18, 24, 00, 00, 83, C4, 0C, E9, DD, 23, 00, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 64, 14, 43, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 64...
 
[+]

Code size:
159.5 KB (163,328 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security