206140a31c6ff4882347fc2b8729e1869ec45c3d

One Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 206140a31c6ff4882347fc2b8729e1869ec45c3d by One Installer has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer.
Publisher:
One Installer LLC  (signed and verified)

MD5:
78e435e34bad087b77d11b3083c39161

SHA-1:
18c8afb8497a7a6d2bd0d9f4a6efff67c959b3ac

SHA-256:
4ae37e1d7bbfd3ffb5e196c0d8c7caae8f0df116c273b418c715b3dd6a777597

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/9/2024 6:06:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia.OneInstaller (M)
16.1.6.23

File size:
140.4 KB (143,816 bytes)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\roaming\apple computer\mobilesync\backup\66aff4381aa05c669d731d29c18df5e74508d635\206140a31c6ff4882347fc2b8729e1869ec45c3d

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/16/2013 6:37:01 AM

Valid to:
6/24/2016 12:26:08 PM

Subject:
CN=One Installer LLC, O=One Installer LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2795ED8C3E155C

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:rgXdZt9P6D3XJG3cCiUmXomgUGCSYHVQHZ9PZgMfXtUOBlDdCncOw:re34uIY7VYHW5HgOtUqZ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.7762

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove 206140a31c6ff4882347fc2b8729e1869ec45c3d - Powered by Reason Core Security