installer_dragon_ball_online_1_57_21_english.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_dragon_ball_online_1_57_21_english.exe by Vittalia Internet S.L has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from domseo.com.edgesuite.net and multiple other hosts. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
596fb4e9814684895caaec8edcbc049b

SHA-1:
178e7fbdc37d81104fd6be225d6650e0fea76789

SHA-256:
4b6476a4201f823843096faabc73ce632f71eba205a10071f294b5044df5c35b

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 9:05:36 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Rootkit-gen [Rtk]
140617-1

AVG
Generic
2015.0.3392

Comodo Security
TrojWare.Win32.Agent.IEXT
19085

Dr.Web
Trojan.Click3.9242
9.0.1.05190

ESET NOD32
Win32/Vittalia.R potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.Vittalia
t3scan.1.6.1.0

McAfee
CryptVittalia
5600.7048

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.m
14.8.7.21

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4782551
31208

File size:
643.1 KB (658,512 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\downloads\installer_dragon_ball_online_1_57_21_english.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
7/31/2014 7:02:13 AM

Valid to:
2/6/2015 10:02:08 AM

Subject:
CN=Vittalia Internet S.L., O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2786630BF69FCE

File PE Metadata
Compilation timestamp:
8/4/2014 6:04:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:RPeGrQCZnplb8yrJQD0xujtKJ0bJfRBlp3rvhzR5IN2k9WSqX:RPecxnfAAlI1Jf5p3rvpvINdWSg

Entry address:
0x1809B

Entry point:
E8, 1C, CF, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 86, 46, 00, E8, EF, 5A, 00, 00, E8, 00, 36, 00, 00, 0F, B7, F0, 6A, 02, E8, AF, CE, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 07, B9, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4677

Code size:
359.5 KB (368,128 bytes)

The file installer_dragon_ball_online_1_57_21_english.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)