installer_____7_1_180_46_arabic.exe

Vittalia Internet S.L

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_____7_1_180_46_arabic.exe by Vittalia Internet S.L has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from www.almeethaq.net. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L  (signed and verified)

Version:
1.0.0.6

MD5:
50147d16c54f2976d1def3dfddaf1dde

SHA-1:
3a0b0638de468264e47f3662fc710ea882ace196

SHA-256:
a6cc8483b7a49a35fe3946628a28d05b56c255408dc29ad3deeca0da09602d3e

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 6:03:48 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Win32:Malware-gen
140617-1

AVG
Adware BundleApp_r.Y
2014.0.3986

Comodo Security
TrojWare.Win32.Agent.IEXT
18922

Dr.Web
Trojan.Click3.8928
9.0.1.05190

ESET NOD32
Win32/Vittalia.R potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.Vittalia
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.Vittalia
v2014.07.21.10

McAfee
CryptVittalia
5600.7063

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.FF
14.8.7.21

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
10470

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4150696
31208

File size:
556.4 KB (569,776 bytes)

Product version:
1.0.0.6

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
Spanish (Spain, International Sort)

Common path:
C:\users\{user}\downloads\installer_____7_1_180_46_arabic.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/9/2014 2:18:24 PM

Valid to:
8/9/2015 2:18:24 PM

Subject:
CN=Vittalia Internet S.L, O=Vittalia Internet S.L, L=Mostoles, S=Madrid, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121296DFC83F15C4B1C19CE7B920AA7D12F

File PE Metadata
Compilation timestamp:
7/11/2014 10:47:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:Zb7DerctF3BC5vZlS8lZNl9Ju81EtV/p38T9B9PV/h2:Zb7De4/R8fDrwrV/p38TBPVp2

Entry address:
0x11F3D

Entry point:
E8, 7A, CF, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, 34, 45, 00, E8, 4D, 5B, 00, 00, E8, 5E, 36, 00, 00, 0F, B7, F0, 6A, 02, E8, 0D, CF, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 61, B9, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.5221

Code size:
276 KB (282,624 bytes)

The file installer_____7_1_180_46_arabic.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

Remove installer_____7_1_180_46_arabic.exe - Powered by Reason Core Security