installer_daemon_tools_lite_4_40_2_0131_dutch.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_daemon_tools_lite_4_40_2_0131_dutch.exe by Vittalia Internet S.L has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
6f67692e8fb148782cb3615779484d9e

SHA-1:
259ca44cf0e75b1a45a9ceda1d9eddb7d58af8ca

SHA-256:
3449107f8e972ec70d67b5a8b994c3a02e4bb718fffa5e240b8c0d93ee1b2451

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 7:04:14 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Vittalia.AB
7.11.98.40

AVG
Startpage
2016.0.3214

Dr.Web
Adware.Downware.744
9.0.1.030

ESET NOD32
Win32/Vittalia
9.8727

IKARUS anti.virus
Trojan.Win32.StartPage
t3scan.2.0.127

McAfee
Artemis!6F67692E8FB1
5600.6870

NANO AntiVirus
Riskware.Win32.Downware.bxblfv
0.26.0.53954

Panda Antivirus
Suspicious file
15.01.30.11

Reason Heuristics
PUP.Vittalia
15.1.30.11

Sophos
Generic PUA CF
4.91

Trend Micro House Call
TROJ_GEN.R0CBB01GK13
7.2.30

VIPRE Antivirus
Vittalia Installer
20880

File size:
861.5 KB (882,160 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_daemon_tools_lite_4_40_2_0131_dutch.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/5/2012 2:00:00 AM

Valid to:
5/9/2013 1:59:59 AM

Subject:
CN=Vittalia Internet S.L., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7952CFD9EF040B59F3C140BA1DA97A60

File PE Metadata
Compilation timestamp:
12/4/2012 9:27:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:b9WC988bu6CoHVzLz82LE91wk/h48OcP48UQhUu:bB88TCo1fz82e1zhUu

Entry address:
0xE39A

Entry point:
E8, 8D, 88, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, D1, 42, 00, E8, 50, 57, 00, 00, E8, 32, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, 20, 88, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5E, 5D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
139.5 KB (142,848 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

TCP (HTTP):
Connects to download.upd4ter.com  (93.189.33.101:80)

 
http://download.upd4ter.com/installers/down.php