6i7aloading.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application 6i7aloading.exe by Vittalia Internet S.L has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
f4e8f4dd93d68b649ee5ebef2b699032

SHA-1:
b5dfac96f750709266206019cf6e010a5cac9d3c

SHA-256:
5a58c8a6c9f7691117c86f44486adf6f73e00b15044f654bc4976ca10e37ede7

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 3:57:54 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3398

Comodo Security
TrojWare.Win32.Agent.IEXT
19016

Dr.Web
Trojan.Click3.9111
9.0.1.05190

ESET NOD32
Win32/Vittalia (variant)
8.10172

McAfee
CryptVittalia
5600.7054

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.L
14.8.7.21

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4782551
31208

File size:
733.6 KB (751,160 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\appdata\local\temp\6i7aloading.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
7/22/2014 8:15:00 PM

Valid to:
2/7/2015 12:02:08 AM

Subject:
CN=Vittalia Internet S.L., O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0418F16686AE11

File PE Metadata
Compilation timestamp:
7/29/2014 8:04:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:glm3YZ4+V+aDMpR2vUEV7tFxz5r829i3OmDVFOnBijPmGnlp3rnNQAXd/FPTD:glm3YZ1V+Cce87OnBOuGnlp3rnN1NPP

Entry address:
0x1CD5B

Entry point:
E8, 1C, CF, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, AB, 47, 00, E8, EF, 5A, 00, 00, E8, 00, 36, 00, 00, 0F, B7, F0, 6A, 02, E8, AF, CE, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 07, B9, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.5562

Code size:
384.5 KB (393,728 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

Remove 6i7aloading.exe - Powered by Reason Core Security